
The growth of Connected Devices and the Internet of Things has brought with it an increased awareness of the importance of cyber security. Businesses and organisations have become used to protecting their IT infrastructure from malicious hackers, but connected devices are also vulnerable and present an equally viable platform from which to launch a wider cyber security attack. By their nature, these devices can be more difficult to protect, and in the consumer market there is a much lower awareness of the potential threats.
Attempts to address this fall broadly into three categories:
Standards and Guidelines. Based on research and best practice, these define requirements and controls to ensure security, in physical devices and in development processes.
Certification Schemes. These offer a way for manufacturers or suppliers of devices and products to demonstrate that their products meet a certain level of security, often with reference to one or more standards or sets of guidelines.
Often the critical factor that persuades manufacturers to act, and get their products tested for security vulnerabilities. Legislation tends to mandate high level security measures but may identify certain Certification Schemes that can be used as evidence.
There is no shortage of standards and guidelines in this space. Most established standards bodies, and many commercial organisations, have released cyber security standards aimed at consumer IoT products over the last few years.
Relevant standards
Perhaps the most widely used and referenced of these is ETSI EN 303 645. First released in 2020, EN 303 645 is used as the baseline set of requirements in certification schemes globally. New standards in specific vertical applications, such as smart energy, often reference EN 303 645 to cover cyber security requirements. EN 303 645 regularly gets cited as a relevant standard in some legislation covering consumer IoT devices.
In the United States in 2020, the National Institute of Standards and Technology published NISTIR 8259A. Positioned as a Cybersecurity Capability Core Baseline' for IoT devices, and initially aimed at providing guidance for organisations developing, acquiring, or deploying IoT products, NISTIR 8259A has become widely referenced by in certification schemes and government-led cyber security work within the US, including consumer IoT.
Other standards covering connected devices include the Consumer Technology Association's CTA-2088, the IoT Security Foundation's IoT Security Assurance Framework, and the UL-2900 series from UL Solutions which also has specific coverage for medical devices.
Certification schemes
With a few exceptions, standards organisations have generally avoided offering certification schemes directly linked to their published standards. Instead, these schemes have generally come from the Test, Inspection and Certification (TIC) sector.
Resillion offers a Secure Connected Device assurance scheme, allowing IoT device manufacturers to get their products independently tested and certified against a range of standards, including those listed above. Similar schemes are available from other technology testing companies.
The IASME Foundation is active in the UK market, offering the IASME IoT Cyber Scheme alongside wider cyber security schemes such as Cyber Essentials and Cyber Essentials Plus.
Another industry body developing a certification scheme is the Connectivity Standards Alliance (CSA), the organisation behind Zigbee and the more recent Matter standards for device connectivity. With CSA members including many of the largest manufacturers of smart home equipment and connected devices such as Apple, Google and Amazon, the CSA scheme has the potential to be widely adopted, especially by manufacturers within the CSA and Matter ecosystem.
Certification success
The most successful labelling or certification schemes are always those that are backed by legislation or government incentives, or which can be used as evidence of conformance with regulatory requirements. Surprisingly, considering the potential risks posed, such government intervention has been a long time coming and is still relatively uncommon.
Among the leading administrations to introduce legislation were Singapore, with the Cybersecurity Labelling Scheme (CLS), and the states of Oregon and California, all in 2020. The Singapore CLS references the ETSI EN 303 645 standard and has different assurance levels which start with manufacturer self-declaration and go on to levels that require independent testing. In the absence of specific certification, legislation such as that in Oregon and California tends to specify certain basic requirements like no common default passwords, a means of reporting discovered vulnerabilities, and a process for updating firmware to address them.
In Europe, the Cyber Resilience Act will drive legislation in member states, eventually requiring that IoT devices meet certain cyber security requirements before they can be sold in European markets. For wireless devices, the EU Radio Equipment Directive (RED) has specific requirements around cyber security which will come into force in mid-2025 (postponed from 2024).
More recently, in 2023, the US Government via the FCC has announced the development of a US Cyber Trust Mark'. This will be a voluntary labelling scheme for consumer IoT devices and aims to give consumers informed choice when purchasing connected devices, and confidence that their devices and personal information will be secure.
In the United Kingdom, the Product Security and Telecommunications Infrastructure Act 2022 (PSTI) was an important piece of legislation. This Act aims to protect buyers and users of IoT products, by giving the Secretary of State the power to require by law that such products meet certain cyber security requirements.
The definition
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
02/05/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
01/05/2026
January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...
01/04/2026
January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION
Douyin Users Can Now Create And Share Videos With Stun...
11/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/02/2026
Graduate Spotlight: Gabrielle Rodriguez The educator, who grew up in the Philippines, shares how shes bringing what she learned at Berklee back home.
Februar...
11/02/2026
The intergalactic children's show starring Adam King will premiere on 14 February on RT 2, RT KIDSjr and RT Player
The Late Late Toy Show star Adam King...
10/02/2026
From San Fran to Santa Clara down to Los Angeles, ESPN celebrates the Big Game w...
10/02/2026
A team of broadcast engineers and experts dispersed across Northern Italy help broadcasters and still photographers keep shooting
OBS has put new imaging techn...
10/02/2026
If you can have the best pictures and the best sound quality for these global ev...
10/02/2026
Disney+ will add vertical video within its app this year after ESPN introduced V...
10/02/2026
GameChanger today unveiled the most comprehensive product update in its 15-year history, marking a major step forward in how families, athletes, coaches, fans, ...
10/02/2026
With a new film adaptation of Wuthering Heights arriving just in time for Valent...
10/02/2026
Today, we announced our fourth quarter 2025 earnings, marking a strong finish to the year with exceptional user growth and continued momentum across the busines...
10/02/2026
I dag redovisar vi v rt resultat f r fj rde kvartalet 2025, vilket markerar ett starkt avslut p ret med robust anv ndartillv xt och fortsatt momentum i hela v...
10/02/2026
World-first opt-out function now fully integrated on SBS On Demand
10 February, 2026
Media releases
SBS has announced a suite of audience-first enhancement...
10/02/2026
Jennifer Hanley, Vice President, International, L3Harris, signed a Memorandum of...
10/02/2026
eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({ content_source:......
10/02/2026
NEW YORK February 10, 2026 Nielsen's Gracenote, the global leader in entertainment metadata, today announced the continuation of its partnership with Go...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
Clear dialogue has long been one of the biggest pain points in post-production. From complex mixes to unpredictable playback environments, intelligibility somet...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
10 Feb 2026
VEON's Kyivstar Expands Digital Healthcare Services in Ukraine ...
10/02/2026
The new TV campaign is set to air on Sky from 10th February - 6th April inviting...
10/02/2026
Red Seat Ventures Acquires Leading Podcast Subscription Platform Supercast Los Angeles, CA, February 10, 2026 - Red Seat Ventures, a division of Fox Corporati...
10/02/2026
Arvato Systems Celebrates a Decade of Innovation and Customer Success in the Dig...
09/02/2026
A look inside the tech, tools, and team that make the Super Bowl into true eye c...
09/02/2026
Software-defined IP backbone and centralized signal-control hub redefine champio...
09/02/2026
Broadcasters continue to raise the bar when it comes to producing an eye-catchin...
09/02/2026
Game coverage will feature nearly 100 cameras, a deep well of replay channels, a...
09/02/2026
Sony's imaging tech is the literal lens through which the spectacle and exc...
09/02/2026
The technologies, including AI, allow fans at home to see the athletes, feel' the speed, and sense the skill
With four years from one Winter Games to the ...
09/02/2026
Sportradar AG announces a multi-year agreement with NBC Sports Regional Sports N...
09/02/2026
New York Festivals Advertising Awards proudly unveils a dynamic new Sports Category Group, expanding its 2026 competition to recognize the powerful role sports ...
09/02/2026
Devlin Design Group, Filmwerks, LTN pitched in on the four-day effort
The site ...
09/02/2026
Despite the game taking place right in the middle of NBC Sports' busiest month ever, its production and operations teams pulled off a massive Super Bowl LX ...
09/02/2026
SBS Media Sustainability Challenge returns for 2026
9 February, 2026
Media releases
The challenge offers brands and agencies $500,000 in advertising invent...
09/02/2026
The National Film and Video Foundation (NFVF), an agency of the Department of Sport, Arts, and Culture and custodian of the SAFTAs, is calling on all South Afri...
09/02/2026
The National Film and Video Foundation (NFVF), an agency of the Department of Sp...
09/02/2026
The National Film and Video Foundation (NFVF) is pleased to announce that the call for training provider submissions is open. This funding aims to award grants ...
09/02/2026
Two multi-role L3Harris products - the Red Wolf launched effects vehicle and Sk...
09/02/2026
The L3Harris Key Management System is the first solution on the open market - and available to NATO customers today - that allows countries to create their own ...