The U.S. Cyber Trust Mark explained
Updated
The Cyber Trust Mark is a voluntary FCC label for smart devices. Its rollout has changed hands, so here is what we can confirm, what to check on fcc.gov, and the security criteria to compare yourself.
As an Amazon Associate we earn from qualifying purchases. Links to Amazon on this page are affiliate links: buying through them costs you nothing extra.
What the Cyber Trust Mark is meant to be
The FCC adopted the program on March 14, 2024 (Report and Order FCC 24-26). It is a voluntary labeling program for wireless consumer Internet of Things products. Examples named by the FCC include home security cameras, voice-activated shopping devices, internet-connected appliances, fitness trackers, garage door openers and baby monitors.
The design is straightforward. A manufacturer chooses to apply. An accredited lab tests the product against the program’s requirements. A third-party label administrator reviews the application and authorizes use of the logo. The FCC oversees the whole system. The logo is meant to appear with a QR code that opens plain-language details, such as how long the product will receive support and whether software patches and security updates install automatically.
Where the program stands
This is the part that changes, so read it with the date in mind. On April 13, 2026, the FCC’s Public Safety and Homeland Security Bureau selected the ioXt Alliance as the new Lead Administrator. The notice says the previous administrator’s initial recommendations are under staff review and will be released for public comment, and that ioXt will lead consumer outreach and stakeholder engagement and recommend additional cybersecurity standards, testing procedures and label design. News coverage reports the earlier administrator, UL Solutions, withdrew in December 2025.
The FCC announcement says it looks forward to “finalize implementation of the program.” Neither the notice nor the announcement says whether any product is certified or carries the label. We could not verify any labeled products, and we do not know the program’s status after April 2026. Check fcc.gov (search “U.S. Cyber Trust Mark”) for the current status and any list of certified products before you rely on the logo.
What the label would measure: NIST IR 8425
NIST’s consumer IoT page lists IR 8425 alongside the White House’s July 18, 2023 announcement of the labeling effort. The FCC’s final technical requirements may differ, so check fcc.gov for the exact criteria. NIST IR 8425, published September 19, 2022, describes six product capabilities that make a useful buying checklist even without a logo:
| NIST capability | What to ask about the device |
|---|---|
| Asset identification | Can the product and its components be identified and tracked, for example by model and firmware version? |
| Product configuration | Can you change settings, restore secure defaults, and does it block changes from unauthorized people? |
| Data protection | Is stored and transmitted data protected, and can you delete your data? |
| Interface access control | Are network and local interfaces limited to authorized users, with no shared default password? |
| Software update | Does it receive verified updates, and does the maker keep them coming? |
| Cybersecurity state awareness | Does it record security-relevant events that could help detect a problem? |
NIST also lists information a maker should publicly share: the terms of support, including update frequency and how updates are applied, the end of the support term, needed maintenance, new vulnerabilities and any required customer action, and breach details. NIST does not set a minimum support period; it says developers should state the length and scope of support so customers can decide.
A buyer’s security checklist that works without the logo
- Support period. Look for a stated number of years of security updates, not just “compatible with future updates.” If the maker does not say, treat that as a cost.
- Update method. Prefer automatic over-the-air updates you can see in the app, with a version number and release notes.
- No default password. The device should force a unique password at setup. The FTC says to change any default username and password.
- Two-factor authentication for the account that controls the device, especially cameras, locks and garage doors.
- Encryption. For cameras, the FTC advises choosing a device with built-in encryption for account information, livestreams and recordings.
- Data controls. Look for a setting to delete recordings and your account, and a privacy policy that names what is collected.
- Vulnerability reporting. A security contact or published advisories show the maker expects to fix problems.
- Local options. A device that still works on your home network if the cloud service ends is safer to own than one that stops working.
What the mark would not tell you
- It is voluntary, so a device without the logo is not necessarily unsafe; it may simply be outside the program.
- It would show a point-in-time assessment. A device still needs updates and a strong account password afterward.
- It is not a privacy rating. A device can be secure and still collect more data than you want. See smart speaker privacy settings and indoor camera privacy.
- It covers the product and does not replace your home setup: router password, updates and a separate network for smart devices (how to set one up).
Using the mark if it does appear
If a product on the shelf shows the logo, scan the QR code. Read the support period and update method, then verify the listing on the FCC or lead administrator’s site rather than trusting the packaging alone. Keep the checklist above as your fallback.
Shop by need
Buying a camera or baby monitor
What to look for: stated years of security updates, forced unique password, two-factor authentication, encrypted streaming, option to turn off remote viewing
Typical price: $25–$250
See options on AmazonChoosing a smart lock or garage controller
What to look for: published support period, firmware updates through the app, account lockout and two-factor authentication, physical key or code backup
Typical price: $90–$300
See options on AmazonAdding sensors and plugs
What to look for: local control with Matter or Zigbee, no mandatory cloud account, maker publishes update policy
Typical price: $10–$40
See options on AmazonFrequently asked questions
Is the U.S. Cyber Trust Mark required?
No. It is a voluntary program. Manufacturers choose whether to apply, and products without the logo are not banned.
Are there products with the Cyber Trust Mark yet?
We could not confirm any. The FCC’s April 2026 announcements about the new lead administrator do not say whether products are certified. Check fcc.gov for the current list.
Who runs the Cyber Trust Mark program?
The FCC oversees it. On April 13, 2026, the FCC named the ioXt Alliance as Lead Administrator, replacing the earlier administrator.
What is NIST IR 8425?
It is NIST’s baseline of cybersecurity capabilities for consumer IoT products: asset identification, product configuration, data protection, interface access control, software update and cybersecurity state awareness.
Sources
- Federal Communications Commission — “US Cyber Trust Mark” program will help consumers choose safer smart devices (Report and Order FCC 24-26)
- Federal Communications Commission — Public Notice DA 26-354: Lead Administrator for the U.S. Cyber Trust Mark Program (April 13, 2026)
- Federal Communications Commission — Announcement selecting ioXt Alliance as Lead Administrator (April 13, 2026)
- Cybersecurity Dive — FCC signals continued commitment to Cyber Trust Mark program (April 14, 2026)
- NIST — IR 8425, Profile of the IoT Core Baseline for Consumer Products
- NIST — Consumer IoT cybersecurity
- Federal Trade Commission — Securing your internet-connected devices at home
- Federal Trade Commission — Using IP cameras safely