FCC Proposal Would Create Voluntary Cybersecurity Label for Smart Devices

Federal Communications Commission Chairwoman Jessica Rosenworcel has introduced a proposal to create a “voluntary cybersecurity labeling program” for smart devices in an effort to boost transparency and protection against cyber threats in the growing Internet of Things market.

Image is proposed logo for FCC smart device cyber trust labeling program with the words U.S. Cyber Trust MarkWith an estimated 17 billion smart devices already in use and another 25 billion projected to be online by 2030, the Internet of Things represents a significant threat surface for cyber criminals — one that is already resulting in more malware attacks in the United States. 

The threat is especially high in education, where smart devices range from speakers and smart displays to printers and vending machines: SonicWall revealed in April in its 2023 Cyber Threat Report that malware attacks targeting smart devices in K–12 schools rose 146% in 2022.

The draft proposal, called a Notice of Proposed Rulemaking, outlines the program, whichwould be established under the FCC’s authority to regulate wireless communications devices based on cybersecurity criteria developed by the National Institute of Standards and Technology, the FCC said on its website. If the proposal is approved by a vote of the full commission, it would then be posted for public comment, and “could be up and running by late 2024,” the FCC said. 

The program would provide “clear information about the security of Internet-enabled devices” and products meeting the program’s requirements would bear a new U.S. Cyber Trust Mark, according to the announcement. 

Such a labeling program “would help consumers make informed purchasing decisions, differentiate trustworthy products in the marketplace, and create incentives for manufacturers to meet higher cybersecurity standards,” the FCC said. 

The proposal would seek input on issues “including the scope of devices for sale in the U.S. that should be eligible for inclusion in the labeling program, who should oversee and manage the program, how to develop the security standards that could apply to different types of devices, how to demonstrate compliance with those security standards, how to safeguard the cybersecurity label against unauthorized use, and how to educate consumers about the program,” the agency said. 

Also unveiled by the FCC is the proposed U.S. Cyber Trust Mark logo, which would appear on packaging alongside a QR code that consumer can scan for further information; it is pending approval by the U.S. Patent and Trademark Office. 

Learn more at FCC.gov.

About the Author

Kristal Kuykendall is editor, 1105 Media Education Group. She can be reached at [email protected].


Featured

  • glowing circuit board lines and high voltage power transmission towers

    AI Ambitions Are Running Into a Network Infrastructure Trust Problem

    Network-provider trust concerns are impacting enterprise AI plans, with AI and data-driven projects the most affected initiatives among respondents reporting disruption, according to a report from telecommunications provider Arelion.

  • A glowing digital brain with neural connections and light trails

    AI Giants: It May Be Time to Slow Down

    Leaders in the artificial intelligence industry have warned for years that increasingly capable AI systems could eventually become dangerous, all the while continuing to race to build them. Now, their sentiments have changed.

  • circuit patterns

    Anthropic Intros Lower-Cost Claude Sonnet 5

    Anthropic has launched Claude Sonnet 5, positioning the model as its most autonomous mid-tier offering to date and a lower-cost alternative to its flagship Opus 4.8 system. The company said the model can plan multi-step tasks, operate tools such as browsers and terminals, and complete agentic work at a level that previously required larger and more expensive models.

  • cloud computing circuit board background

    Cloud Crime on the Rise as Attackers Exploit Trust

    CrowdStrike's latest Threat Hunting Report traces a multiyear shift from conventional intrusions toward attacks that exploit trusted identities, cloud services, AI systems, and software dependencies.