Regulations / United States
Regulations by jurisdiction
United States: what binds a connected product
The US has no horizontal IoT security law. What exists is sector-specific (FDA for medical devices), voluntary (the Cyber Trust Mark), or enforcement after the fact by the FTC under consumer-protection law.
| Framework | Applies when | Who demands it | In force | Penalties |
|---|---|---|---|---|
| US Cyber Trust Mark | Consumer wireless IoT sold in the US, by choice | Retail shelf positioning; no legal duty | Programme launched Jan 2025 | None; misuse of the mark is an FCC matter |
| FDA premarket cybersecurity | Cyber devices submitted for FDA clearance or approval in the US | Regulatory approval | Statutory since 29 Mar 2023 | Refusal to accept the submission |
US Cyber Trust Mark
FCC labelling programme modelled on Energy Star; testing against NIST IR 8425 criteria by accredited labs.
FDA premarket cybersecurity
Section 524B of the FD&C Act: a cybersecurity plan, SBOM, and post-market vulnerability process in every submission; 2023 and 2025 guidance.
Check your own product
The IoT security scorecard and the requirements generator resolve these frameworks for your product archetype and markets. Educational reference, not legal advice.
← All jurisdictions