
After years of intense debate and worsening hacker threats, regulation is coming to the IoT. Three of the world’s largest markets have rolled out distinct methods to securing the landscape, an important measure with connected endpoints in homes and offices set to double by 2030.
Europe’s Cyber Resilience Act and The United Kingdom’s Product Security and Telecommunications Infrastructure Act mandate strict production requirements. Meanwhile, The United States’ Cyber Trust Mark takes a self-regulation, consumer-focused approach. At the same time, the rest of the world is watching closely, with some emerging markets like India already gravitating toward an EU-style approach.
The stakes are high for both manufacturers and users. Multiple compliance frameworks mean navigating a complex web of requirements that impact everything from production costs to time-to-market. However, consumer privacy and security deserve added scrutiny with more devices carrying microphones and cameras. So, as these regulations mature, which model will become the de facto global standard?
It has taken a while to get here. Plagued by default passwords and poor patching, industry insiders like myself have long called for production minimums to weed out cheap devices. Then, spurred by the remote boom of the pandemic, always-on hackers targeted always-on devices, many of which are present in our most personal and professional spaces. Today, IoT underpins critical infrastructure and sensitive applications, and policymakers recognize the long-term threat of low-security devices.
Europe, as per usual, was the first to act. The trade bloc suggested its suite of device regulations in 2022 and passed them last December. They are undoubtedly comprehensive—obligating manufacturers to protect their internet-connected products from unauthorized access throughout their life cycle. This demands products without known exploitable vulnerabilities, thereby requiring design, development and production that always ensures an appropriate security level.
The U.K. quickly followed with similar producer demands. Its act, proposed a few months after Europe and passed last April, requires minimum security update periods (rather than lifetime like in Europe) and mandatory security issue reporting back to consumers. Generic passwords, thankfully, were also in the crosshairs with a ruling that devices must either have a randomized password or generate a unique one during initialization—an important step that prevents hackers from quickly accessing devices, infecting local networks and creating botnets.
The United States took a different path. Rather than mandates, they are betting on market forces to solve the security issue. Former President Joe Biden announced a program similar to Energy Star—The Cyber Trust Mark—where voluntary certification shows consumers which devices pass the cybersecurity grade and which do not. The hope is that consumer choice will impact bottom lines and incentivize better security.
When leaders move, the market listens. With three of the largest connected device consumers spearheading security in different ways, expect other countries to plot their next move. Looking at early advances, most prefer European top-down production mandates over American bottom-up consumer encouragement.
India is leading the way. First proposed in 2023, The Code of Practice for Securing Consumer IoT Devices mirrors EU standards and requires similar security-by-design principles. Australia, while currently operating under a voluntary code, is considering mandatory standards that align closely with U.K. principles.
But it is not a clean sweep. Singapore’s Cybersecurity Labelling Scheme opts for a voluntary approach more aligned with the U.S. This option can be appealing depending on the country’s legislative appetite since it is easier to implement. But it is evident in these early days that emerging markets are taking cues from Brussels more than Washington.
For a hint of where things are going, it is worth looking at how different markets tackled a similar technology problem and regulatory solution in data privacy. Once again, Europe led the way in 2016 with the General Data Protection Regulation (GDPR). On the other hand, The United States decided against federal thresholds.
The result? Major tech companies applied GDPR globally and countries from Brazil to India modeled their privacy laws after the framework.
Europe’s reputation for leading security and privacy regulation makes it the natural template for emerging markets. So, do not be surprised to see local versions of the Cyber Resilience Act. As devices handle increasingly critical societal functions, countries will likely favor legislation that guarantees stronger safeguards rather than optional baselines.
Whatever happens next, companies need to get their act together now. At a minimum, consumer certifications are on the way, and this still demands upping device and platform security. In Europe, there is a grace period with the act’s main obligations applying from December 2027. This gives companies two years and change to get up to speed which, as I have previously written, is not a lot of time to redesign and troubleshoot.
If device makers want to retain access to this market, and likely others to come, they must make the security investment today and ensure their global competitiveness tomorrow.
Preparing for CRA and Open-Source Silicon Security
Why Secure by Design Is Essential for Cybersecurity
Memory Safety Will Be Key to Tackle Fundamental Cyber Security
You must Register or Login to post a comment.
This site uses Akismet to reduce spam. Learn how your comment data is processed.
Advertisement

More Stories
How One Alum Helped Build a Community of Internet Leaders
The Tribal Broadband Bootcamps Celebrate Their Five-Year Anniversary
Adaptability and Resilience: Q&A with New Board Chair Brian Haberman