You will be provided with a reference and some statements. Please determine whether each statement is 'supported', 'unsupported', or 'unknown' with respect to the reference. Please note:
First, assess whether the reference contains any valid content. If the reference contains no valid information, such as a 'page not found' message, then all statements should be considered 'unknown'.
If the reference is valid, for a given statement: if the facts or data it contains can be found entirely or partially within the reference, it is considered 'supported' (data accepts rounding); if all facts and data in the statement cannot be found in the reference, it is considered 'unsupported'.

You should return the result in a JSON list format, where each item in the list contains the statement's index and the judgment result, for example:
[
    {
        "idx": 1,
        "result": "supported"
    },
    {
        "idx": 2,
        "result": "unsupported"
    }
]

Below are the reference and statements:
<reference>
U.S. Cyber Trust Mark | Federal Communications Commission



Skip to main content

Skip to search

An official website of the United States government

Here’s how you know

Here’s how you know

Official websites use .gov
A

.gov
website belongs to an official government
organization in the United States.

Secure .gov websites use HTTPS
A

lock
(

) or
https://
means you’ve safely connected to
the .gov website. Share sensitive information only on official,
secure websites.

Browse by

category

Browse by

bureaus & offices

About the FCC

About the FCC

About the FCC Overview

What We Do

Rulemaking Process

Leadership

FCC Initiatives

Find People

Organizational Charts

Advisory Committees

Jobs and Internships

Contracting

Strategic Plans & Budgets

Contact

FY 2027 Congressional Budget Justification

Privacy Policy

Accessibility Program

Proceedings & Actions

Proceedings & Actions

Proceedings and Actions Overview

Electronic Comment Filing System (ECFS)

Commission Documents (EDOCS)

Most Active Proceedings

Items on Circulation

Ex-Parte

Daily Digest

Mergers & Transactions

Auctions

Licensing & Databases

Licensing & Databases

Overview

About Licensing

Databases

Fees

Forms

FCC Registration System (CORES)

System Alerts & Notifications

ASR

CEFS

COALS

CORES

DIRS

EA

ECFS

EDOCS

ELS

ETFS

ETRS

GenMen

HAM

KDB

KIDVID

LMS

ICFS

NORS

PIF

PIRATE

PSIX-ESIX

TCB

ULS

URS

VPD

Reports & Research

Reports & Research

Reports and Data Overview

Reports

Data

Guides

Maps

Working Papers

For Developers

Reference Information Center (RIC)

Workload Dashboard

AI

News & Events

News & Events

News and Events Overview

Headlines

Commission Meetings

Events

Archived Events

Press Resources

FCC Blog

RSS Feeds & Email Signup

August 2026 Open Commission Meeting

For Consumers

For Consumers

Help Center Overview

Consumer Complaint Center

Disability Rights

Headlines

Social Media

Robocalls

Consumer Complaint Center

Consumer

Enforcement

Media

Public Safety

Space

Wireless

Wireline

Offices

Search

X

Search

Home

Public Safety

U.S. Cyber Trust Mark

If you have any questions or need additional information, please contact us at
CyberTrustMark@fcc.gov
Consumers rely increasingly on the convenience of wireless interconnected smart products, also known as the Internet of Things or IoT. You can link your garage door opener, your front door lock, your house alarm, and your lights so everything opens, unlocks, and turns on when you get home. Once inside, you can keep an eye on your baby from the living room, where you can shop using a voice-activated device—to name just a few examples. But with this convenience comes risk. IoT products can be susceptible to a range of security vulnerabilities.
To help address this, the FCC is creating a voluntary cybersecurity labeling program for wireless consumer IoT products. The program builds on significant public and private sector work on IoT cybersecurity. And it will rely on public-private collaboration going forward.
The FCC is in the
process
of selecting a Lead Administrator for the program the FCC’s voluntary cybersecurity labeling program for wireless consumer Internet of Things (IoT) products. Under this program, qualifying consumer smart products that meet robust cybersecurity standards will bear a label—including a new “
U.S Cyber Trust Mark
.”
This will help consumers make informed decisions about the products they bring into their homes, will differentiate trustworthy products in the marketplace, and create incentives for manufactures to meet higher cybersecurity standards.
We believe that just as the ENERGY STAR program educated the public and created incentives for manufacturers to offer more energy-efficient appliances, our cybersecurity labeling program will pave the way for more secure smart products.
The FCC is now in the process of standing up this comprehensive program.

Cyber Trust Mark Program FAQs

When was the U.S. Cyber Trust Mark program created?
In August 2023, the FCC sought public comment on how to create the Cyber Trust Mark program. In March 2024, based on public input, we
adopted rules
establishing the framework for the program.
We are now in the process of standing up this comprehensive program. As we move forward, we will make additional announcements and will seek further public input on specific implementation details.
How will the U.S. Cyber Trust Mark program work?
Here is an overview:
The
U.S. Cyber Trust Mark logo
will appear on wireless consumer IoT products that meet the program’s cybersecurity standards.
The logo will be accompanied by a QR code that consumers can scan, linking to a registry of information with easy-to-understand details about the security of the product, such as the support period for the product and whether software patches and security updates are automatic.
The voluntary program will rely on public-private collaboration, with the FCC providing oversight and approved third-party cybersecurity label administrators managing activities such as evaluating product applications, authorizing use of the label, and supporting consumer education.
Compliance testing will be handled by accredited labs
Examples of eligible products may include internet-connected home security cameras, voice-activated shopping devices, smart appliances, fitness trackers, garage door openers, and baby monitors.
While the program is voluntary, participants must follow the FCC’s program requirements.
The FCC will work with other federal agencies to develop international recognition of the FCC’s IoT Label and mutual recognition of international labels.
Which products will be included in the program?
The program applies to consumer wireless IoT products.
Examples of eligible products include internet-connected home security cameras, voice-activated shopping devices, smart appliances, fitness trackers, garage door openers, and baby monitors.
Which products will not be included in the program?
The FCC’s Cyber Trust Mark program does not include:
Medical devices regulated by the Food and Drug Administration
Motor vehicles and equipment regulated by the National Highway Traffic Safety Administration
Wired devices
Products primarily used for manufacturing, industrial control or enterprise applications
Equipment on the FCC’s
Covered List
and equipment produced by an entity on the covered list
IoT products from a company on other lists addressing national security
IoT products produced by entities banned from Federal procurement
Our program, which is based largely on criteria established by the National Institute of Standards and Technology (NIST), initially focuses on wireless consumer IoT products but may evolve over time. It does not include personal computers, smartphones, and routers. NIST is
working
to define cybersecurity requirements for consumer-grade routers.
What role will the third-party administrators play?
The Cyber Trust Mark program is owned by the Commission and will by supported by third party administrators. Their duties are spelled out in an FCC
Order
. In brief:
The
Lead Administrator
will be responsible for collaborating with stakeholders and will recommend to the Commission cybersecurity standards, testing procedures, and label design. It will also be responsible for developing a consumer education campaign.
The
Cybersecurity Label Administrators
will be responsible for day-to-day management of the program, including accepting and reviewing applications and approving or denying use of the FCC IoT Label.
And the
CyberLABs
will test products to demonstrate they meet the program's cybersecurity requirements.
The Lead Administrator, Cybersecurity Label Administrators, and CyberLABs must be accredited to international (ISO/IEC) standards.
Can entities outside of the U.S. participate in the U.S. Cyber Trust Mark program?
Manufacturers outside of the U.S. will be eligible to apply for the U.S. Cyber Trust Mark for their products as long as they are not otherwise prohibited from participating in the program. In addition, entities may apply to be a recognized CyberLAB as long as they are not otherwise prohibited from the program. Manufacturers and other entities owned or controlled by, or affiliated with, any of the following sources are prohibited from the program:
FCC Covered List
;
Department of Commerce’s Entity List
;
Department of Defense's List of Chinese Military Companies
; and Products produced by any entity owned or controlled by or affiliated with any person or entity that has been suspended or debarred from receiving federal procurements or financial awards, to include all entities and individuals published as ineligible for award on the General Service Administration’s System for Award Management.
We will establish qualification criteria for any entity outside the U.S. to be approved to act as a Cybersecurity Label Administrator once appropriate international agreements or other appropriate prerequisites are in place. We may also establish additional criteria or procedures necessary with respect to LABs located outside of the United States.
What are the next steps to launch the program?
There are many steps to standing up such a comprehensive program. Much of this is described in the FCC's
Order
, but in brief:
On August 11, 2026, we opened a filing window for Cybersecurity Label Administrator applications, which will remain open until closed by the Bureau.
We have been doing extensive stakeholder outreach to increase awareness and understanding of the new program. This should ultimately help increase participation in all aspects of program.
We are also engaging with stakeholders on the details of the program (for example, standards and label design) to promote an efficient and timely rollout of the U.S Cyber Trust Mark.
We are reviewing public input on certain implementation details for the program—for example, matters related to the structure of the registry.
The Lead Administrator has engaged with stakeholders and developed
recommendations for the FCC
on issues including standards and testing procedures, label design, and post-market surveillance.
UL Solutions withdrew as Lead Administrator, effective December 19, 2025, and we accepted applications for a Lead Administrator from January 7, 2026 through February 9, 2026.
ioXt Alliance was named as Lead Administrator, effective April 13, 2026.
There will be an announcement from the FCC when the program is ready to accept applications for products to bear the label.
Meanwhile, we are reviewing the public input in response to the Further Notice of Proposed Rulemaking regarding additional potential disclosures related to national security.
There will be some intermediary steps as well, and we will be communicating new developments as we move forward.
How will a manufacturer apply to use the U.S. Cyber Trust Mark?
Once the U.S. Cyber Trust Mark is launched:
The applicant (e.g., manufacturer) must have its product tested by an accredited and FCC- recognized CyberLAB to ensure it meets the program’s cybersecurity requirements.
The applicant would then submit an application with supporting documents to a Cybersecurity Label Administrator.
The Cybersecurity Label Administrator will review the application and determine whether the IoT product meets the program requirements.
The Cybersecurity Label Administrator will then either approve or deny the application.
When can a manufacturer apply to use the U.S. Cyber Trust Mark?
The FCC will make an announcement when the program is ready to accept applications for products to bear the label. The FCC's
Order
outlines the specific steps that manufacturers will have to take to apply to use the mark.
There are a number of steps that need to occur before manufacturers can apply:
At the end of this stakeholder engagement period (or sooner), the Lead Administrator will recommend to the FCC’s Public Safety and Homeland Security Bureau the standards and testing procedures for at least one class of consumer IoT product. The Bureau will release a public notice seeking public comment on the Lead Administrator’s recommendation.
After the public comment period is over, the Bureau will review the record and release an order adopting the applicable standards and testing procedures and establishing the scope of the FCC’s program.
The FCC’s scope will be used by FCC-recognized Accrediting Bodies to accredit CLAs to ISO/IEC 17065 and the Commission’s program scope and to accredit CyberLABs to ISO/IEC 17025 and the Commission’s program scope.
Only after CLAs are accredited and recognized by the Bureau and CyberLABs are accredited and recognized by the Lead Administrator, will they be ready to receive and process manufacturer applications to use the U.S. Cyber Trust Mark.
What will happen when consumers scan the QR code that accompanies the U.S. Cyber Trust Mark?
Once the U.S. Cyber Trust Mark label is on products, it will be accompanied by a QR code that you can scan with your wireless phone to read easy-to-understand, security-related information about that particular product. This information will include:
How to change the default password
How to configure the device securely
Whether updates/patches are automatic and if not, how consumers can access them
The product's minimum support period end date or a statement that the device is not supported by the manufacturer and the consumer should not rely on the manufacturer to release security updates

Key Documents
August 11, 2026 - Public Notice
FCC Announces Cybersecurity Label Administrators & Filing Window
April 13, 2026 - Public Notice
FCC Selects New Lead Administrator for U.S. Cyber Trust Mark Program
January 29, 2026 - Order
FCC Announces Extension for USCTM Administrator Applications
January 26, 2026 - Public Notice
FCC Opens US Cyber Trust Mark Cyber Label Administrator Filing Window
January 6, 2026 - Public Notice
FCC Announces Lead Administrator Filing Window
June 13, 2025 - Lead Administrator Recommendations
Lead Administrator Recommendations on Technical Standards and Testing Procedures, Label Design, and Post-Market Surveillance
May 6, 2025 - Order
Order Granting USCTM Lead Administrator Extension of Time
March 4, 2025 - Order
Order Granting USCTM Lead Administrator Extension of Time
January 10, 2025 - Public Notice
FCC Reminds Accreditation Bodies to Seek PSHSB Recognition
January 8, 2025 - Notice from Lead Administrator
Lead Administrator's Call for Stakeholders in 90-Day Stakeholder Engagement Process
December 11, 2024 - Public Notice
FCC Announces 10 Administrators of IoT Labeling Program
December 4, 2024 - Public Notice
FCC Selects Lead Administrator for U.S. CyberTrust Mark Program
October 3, 2024 - Public Notice
FCC Guidance on Confidential IoT Labeling Administrator Applications
September 26, 2024 - Order
FCC Announces Extension for IoT Labeling Administrator Applications

September 10, 2024 - Public Notice
FCC Announces Application Process for Administrators of Internet of Things Cybersecurity Labeling Program
August 9, 2024 - Public Notice
FCC Announces IoT Labeling Rules Effective September 9, 2024
July 30, 2024 - Public Notice
Announcing the Effective Date of Certain IoT Labeling Rules
July 18, 2024 - Public Notice
FCC Announces Comment and Reply Dates for the IoT Labeling Program
June 27, 2024 - Public Notice
FCC Requests Comments on Implementation of the IoT Labeling Program
March 15, 2024 - Erratum
Erratum, FCC Adopts Rules for IoT Labeling Cyber Trust Mark Program
March 14, 2024 - R & O, FNPRM and Press Release
FCC Adopts Rules for Cyber Trust Mark Program

August 10, 2023 - NPRM & Fact Sheet
FCC Proposes Cybersecurity Labeling Program for Smart Devices
July 18, 2023 - Press Release
Chairwoman Rosenworcel Announces Cybersecurity Labeling Program for Smart Devices

Bureau/Office:

Public Safety and Homeland Security

Tags
:

Public Safety

Cyber Trust Mark

IoT Labeling

Updated:

Tuesday, August 11, 2026

Text

Federal Communications Commission

45 L Street NE

Washington, DC 20554

Link

Phone: 1-888-225-5322

ASL Video Call: 1-844-432-2275

Fax: 1-866-418-0232

Contact Us

Visiting FCC Facilities

Link

Website Policies & Notices

Privacy Policy

FOIA

No Fear Act Data

Open Government Directive

Plain Writing Act

RSS Feeds & Email Updates

Accessibility

Vulnerability Disclosure Policy

USA.gov

Text

CATEGORIES

Link

About the FCC

Proceedings & Actions

Licensing & Databases

Reports & Research

News & Events

For Consumers

Text

BUREAUS & OFFICES

Link

Consumer

Enforcement

Inspector General

Media

Public Safety

Space

Wireless

Wireline

Offices

Twitter

LinkedIn

Facebook

Youtube

Instagram

Federal Communications Commission
</reference>

<statements>
1. In the United States, the Federal Communications Commission (FCC) has operationalized the U.S. Cyber Trust Mark program, establishing a recognized consumer-facing cybersecurity labeling system
2. The framework requires rigorous physical testing of wireless IoT products, validation of secure default settings, data protection at rest and in transit, and documented patch support policies accessible through dynamic QR codes on packaging
3. U.S. Cyber Trust Mark: Consumer security verification via dynamic registry tracking
</statements>

Begin the assessment now. Output only the JSON list, without any conversational text or explanations.