Trade Law Daily is a Warren News publication.

Industry Groups Urge Voluntary IoT Security Labeling Program, Based on NIST Guidance

Trade associations led by CTA offered a set of principles on a cybersecurity labeling program for smart devices, saying it should be voluntary and based on existing National Institute of Standards and Technology guidance. That message is consistent with industry…

Sign up for a free preview to unlock the rest of this article

Timely, relevant coverage of court proceedings and agency rulings involving tariffs, classification, valuation, origin and antidumping and countervailing duties. Each day, Trade Law Daily subscribers receive a daily headline email, in-depth PDF edition and access to all relevant documents via our trade law source document library and website.

responses in initial comments on an August NPRM (see 2310100034). “While significant operational details must still be determined before a program can launch, we are encouraged by the Commission’s intention to work collaboratively with industry in a way that helps consumers make more informed buying choices while encouraging device makers to meet established cybersecurity standards,” the groups said in a filing posted Thursday in docket 23-239. The groups also said the program “must be distinct from equipment authorization processes, including no requirement to complete the certification or authorization process before qualifying for the Mark.” Achieving certification “should indicate that a product is equipped with ‘reasonable security’ for purposes of liability protection,” the filing said. Manufacturers should be allowed to “self-attest with appropriate trust mechanisms that are based on meeting” NIST’s core baseline for consumer IoT products. The FCC should also “encourage international alignment of cybersecurity labeling practices and mutual recognition agreements” and the U.S. government should launch “a robust consumer education campaign … to drive awareness and understanding of the Mark,” said the filing. It was signed by groups including the Connectivity Standards Alliance, CTIA, the Information Technology Industry Council, the National Electrical Manufacturers Association, the Security Industry Association, the Telecommunications Industry Association, the U.S. Chamber of Commerce and USTelecom.