The U.S. Cyber Trust Mark is a voluntary cybersecurity labeling initiative, backed by the U.S. Federal Communications Commission (FCC), for consumer Internet of Things (IoT) devices.

Its objective is to help consumers identify connected products that meet recognized cybersecurity expectations, while encouraging manufacturers to adopt secure-by-design and secure-by-default practices across the product lifecycle.

The U.S. Cyber Trust Certification may evolve into a market-driven reference for consumer IoT products in the United States, particularly as adoption by retailers, platforms and public stakeholders increases, while remaining voluntary in nature.
 

Your strategic partner in testing and certification

Complete our quick form

GET A QUOTE

Built on NIST IoT cybersecurity standards

At the core of the U.S. Cyber Trust Mark lies the NIST IR 8259 series, developed by the U.S. National Institute of Standards and Technology (NIST).

NIST IR 8259 defines the foundational IoT cybersecurity baseline for manufacturers, covering technical capabilities and supporting activities across the full product lifecycle. The standard is widely recognized beyond the U.S. market as a reference for IoT cybersecurity expectations.

NIST IR 8259 as the Foundational IoT Cybersecurity Baseline

The NIST IR 8259 series focuses on ensuring that IoT devices are securable and addresses, among others:

  • Device identity and logical access control
  • Secure configuration and default settings
  • Secure software and firmware updates
  • Protection of data and critical assets
  • Vulnerability handling and coordinated disclosure
  • Cybersecurity support throughout the product lifecycle

These principles align with other international IoT cybersecurity frameworks, reinforcing technical convergence across markets.

Adopting the NIST IR 8425 Consumer IoT Profile for the U.S. Cyber Trust Mark

NIST IR 8425 defines the consumer IoT profile of the NIST IR 8259 core baseline and is used as the technical reference for the U.S. Cyber Trust Mark.

It translates the foundational cybersecurity capabilities of NIST IR 8259 into consumer-focused outcomes, applicable to the entire IoT product, including the device, supporting software and associated services.

By aligning with NIST IR 8425, manufacturers can demonstrate how their consumer IoT products meet the technical expectations underpinning the U.S. Cyber Trust Mark.

Relationship with international IoT cybersecurity frameworks

Although the U.S. Cyber Trust Mark is U.S.-focused, its technical foundations overlap with other widely adopted frameworks, including:

This convergence enables manufacturers to adopt a single technical cybersecurity strategy adaptable to multiple regulatory and labeling schemes worldwide. 

Key U.S. Cyber Trust Mark requirements: what the program evaluates

The U.S. Cyber Trust Mark requirements focuses on device-level cybersecurity, assessing how consumer IoT products implement the essential capabilities defined by NIST IR 8259, including:

  • Data and asset protection (e.g., cryptographic keys and sensitive data).
  • Interface and access security (network, APIs and physical interfaces).
  • Secure update mechanisms (integrity and authenticity).
  • Secure boot and lifecycle security.
  • Vulnerability handling and disclosure practices.

These domains reflect international best practices for consumer IoT security.

Global market context

Backed by the FCC and grounded in NIST IR 8259, the U.S. Cyber Trust Mark sits alongside other non-regulatory, market-driven cybersecurity schemes that are widely requested by customers and procurement channels in specific sectors.

Early alignment with NIST IR 8259 can help manufacturers:

  • Prepare for U.S. consumer IoT market expectations
  • Reuse cybersecurity evidence across regions
  • Align U.S. expectations with EU and international frameworks

This positions the U.S. Cyber Trust Mark within a broader global IoT market access strategy.

U.S. Cyber Trust Certification alignment and readiness

Applus+ Laboratories supports manufacturers in aligning their consumer IoT products with the technical foundations of the U.S. Cyber Trust Certification, through independent evaluations and gap analysis based on NIST IR 8259 and its consumer profile NIST IR 8425.

As the U.S. Cyber Trust Mark program continues to be defined and operationalized under FCC oversight, early technical alignment with NIST requirements allows manufacturers to anticipate future conformity expectations, adapt efficiently as program details mature, and position their products within the evolving U.S. cybersecurity labeling ecosystem.

GET A QUOTE

RELATED SERVICES TO U.S. Cyber Trust Mark: from NIST alignment to certification readiness

Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.

Cookie settings panel