Skip to main content
Switch Language
  • Article

UL Solutions Guide to the U.S. Cyber Trust Mark

A cybersecurity labeling program for smart devices designed to give consumers the information needed to make decisions about security when purchasing products to bring into their homes.

a person whose hand is touching a virtual Screen Padlock Icon

What is the U.S. Cyber Trust Mark?

In 2023, the U.S. Government revealed plans to introduce the U.S. Cyber Trust Mark1 to American consumers. Overseen by the Federal Communications Commission (FCC), the Cyber Trust Mark will be a cybersecurity certification and labeling program for consumer Internet of Things (IoT) products.

This label will promote the adoption of cybersecurity standards for consumer products, in order to provide consumers with a safer and more secure user experience.

What requirements need to be fulfilled to obtain U.S. Cyber Trust Mark certification?

The specific criteria for the program are still under development. However, according to official notices from the FCC, the program will adopt the criteria outlined by the National Institute of Standards and Technology (NIST). These criteria focus on cybersecurity controls which should be implemented for security of the entire lifecycle of an IoT product and its associated services. This approach will take into consideration risks and use cases, which is crucial in the diverse and rapidly expanding IoT market.

The NIST IoT cybersecurity criteria cover various technical and nontechnical areas, including asset identification, product configuration, data protection, interface access control, software updates, cybersecurity state awareness, documentation, information and query reception, information dissemination and product education and awareness.

Creating standards, protocols for conformance and certification guidelines is a complex matter. Various industry stakeholders are contributing their expertise and experience to develop these in a way that enables efficiency and prompt, widespread adoption. Based on these stakeholder recommendations, the FCC will make the official determination on the program’s requirements. UL Solutions, serving in the role of Lead Administrator for the program, will lead this stakeholder effort.

What types of devices will be eligible for the Mark?

Various consumer smart products are anticipated to qualify for the Trust Mark, including, but not limited to:

  • Internet-connected home security cameras
  • Smart kitchen appliances
  • Smart speakers
  • Smartwatches and fitness trackers
  • Smart televisions
  • GPS trackers
  • Smart light bulbs
  • Robot vacuum cleaners

When will the U.S. Cyber Trust Mark begin?

The U.S. Cyber Trust Mark scheme is expected to commence in 2025. To familiarize consumers with the new label, the FCC, in collaboration with program stakeholders, will undertake consumer education efforts. Additionally, major retailers in the United States are urged to prioritize products that bear the Cyber Trust Mark1.

What is UL Solutions Role in the U.S. Cyber Trust Mark Program? 

UL Solutions will be serving as the Lead Administrator for the program. In that role, UL Solutions will work with stakeholders to make recommendations to the FCC on a number of important program details, like applicable technical standards and testing procedures, post-market surveillance requirements, the product registry, and a consumer education campaign. UL Solutions will also approve testing labs for the program that meet the criteria established by the FCC. UL Solutions plans to apply to become a testing laboratory once the requirements and applications are released.

In addition, UL Solutions will be a Cyber Label Administrator (CLA), authorizing the use of the label for those products that meet the program standards and authorizing labels for those products that meet the program standards.

How can UL Solutions help you prepare?

To jumpstart your journey towards obtaining the U.S. Cyber Trust Mark, UL Solutions is providing assessment, advisory and gap analysis services based on NIST IR 8259, which serves as the foundational guidance for expected requirements of the new U.S. Cyber Trust Mark framework described in NIST IR 8425.

The final FCC program assessment requirements may vary from those in NIST IR 8425. However, we anticipate these variations will be minor. It is worth noting that a NIST IR 8259 assessment will solely focus on the device itself. The inclusion of cloud services and phone applications in the U.S. Cyber Trust Mark is expected to be included as part of the U.S. Cyber Trust Mark.

Contact us to learn how we can help you prepare today.

  1. U.S. Cyber Trust Mark. (n.d.). Federal Communications Commission. Retrieved December 5, 2024 from https://www.fcc.gov/CyberTrustMark

  2. Certification MARK – U.S. cybersecurity labeling program for smart devices. (2023, September). Federal Communications Commission. Retrieved Nov. 14, 2023, from https://www.fcc.gov/cybersecurity-certification-mark

X

Get connected with our sales team

Thanks for your interest in UL's products and services. Let's collect some information so we can connect you with the right person.

Please wait…