The U.S. Cyber Trust Mark is a voluntary cybersecurity labeling initiative, backed by the U.S. Federal Communications Commission (FCC), for consumer Internet of Things (IoT) devices.
Its objective is to help consumers identify connected products that meet recognized cybersecurity expectations, while encouraging manufacturers to adopt secure-by-design and secure-by-default practices across the product lifecycle.
The U.S. Cyber Trust Certification may evolve into a market-driven reference for consumer IoT products in the United States, particularly as adoption by retailers, platforms and public stakeholders increases, while remaining voluntary in nature.
Complete our quick form
At the core of the U.S. Cyber Trust Mark lies the NIST IR 8259 series, developed by the U.S. National Institute of Standards and Technology (NIST).
NIST IR 8259 defines the foundational IoT cybersecurity baseline for manufacturers, covering technical capabilities and supporting activities across the full product lifecycle. The standard is widely recognized beyond the U.S. market as a reference for IoT cybersecurity expectations.
The NIST IR 8259 series focuses on ensuring that IoT devices are securable and addresses, among others:
These principles align with other international IoT cybersecurity frameworks, reinforcing technical convergence across markets.
NIST IR 8425 defines the consumer IoT profile of the NIST IR 8259 core baseline and is used as the technical reference for the U.S. Cyber Trust Mark.
It translates the foundational cybersecurity capabilities of NIST IR 8259 into consumer-focused outcomes, applicable to the entire IoT product, including the device, supporting software and associated services.
By aligning with NIST IR 8425, manufacturers can demonstrate how their consumer IoT products meet the technical expectations underpinning the U.S. Cyber Trust Mark.
Although the U.S. Cyber Trust Mark is U.S.-focused, its technical foundations overlap with other widely adopted frameworks, including:
This convergence enables manufacturers to adopt a single technical cybersecurity strategy adaptable to multiple regulatory and labeling schemes worldwide.
The U.S. Cyber Trust Mark requirements focuses on device-level cybersecurity, assessing how consumer IoT products implement the essential capabilities defined by NIST IR 8259, including:
These domains reflect international best practices for consumer IoT security.
Backed by the FCC and grounded in NIST IR 8259, the U.S. Cyber Trust Mark sits alongside other non-regulatory, market-driven cybersecurity schemes that are widely requested by customers and procurement channels in specific sectors.
Early alignment with NIST IR 8259 can help manufacturers:
This positions the U.S. Cyber Trust Mark within a broader global IoT market access strategy.
Applus+ Laboratories supports manufacturers in aligning their consumer IoT products with the technical foundations of the U.S. Cyber Trust Certification, through independent evaluations and gap analysis based on NIST IR 8259 and its consumer profile NIST IR 8425.
As the U.S. Cyber Trust Mark program continues to be defined and operationalized under FCC oversight, early technical alignment with NIST requirements allows manufacturers to anticipate future conformity expectations, adapt efficiently as program details mature, and position their products within the evolving U.S. cybersecurity labeling ecosystem.
Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.
They allow the operation of the website, loading media content and its security. See the cookies we store in our Cookies Policy.
They allow us to know how you interact with the website, the number of visits in the different sections and to create statistics to improve our business practices. See the cookies we store in our Cookies Policy.
Based on your behavior on the website (where you click, how long you browse, etc.) we establish parameters and a profile for you to display ads that correspond to your interests. See the cookies we store in our Cookies Policy.