You will be provided with a reference and some statements. Please determine whether each statement is 'supported', 'unsupported', or 'unknown' with respect to the reference. Please note:
First, assess whether the reference contains any valid content. If the reference contains no valid information, such as a 'page not found' message, then all statements should be considered 'unknown'.
If the reference is valid, for a given statement: if the facts or data it contains can be found entirely or partially within the reference, it is considered 'supported' (data accepts rounding); if all facts and data in the statement cannot be found in the reference, it is considered 'unsupported'.

You should return the result in a JSON list format, where each item in the list contains the statement's index and the judgment result, for example:
[
    {
        "idx": 1,
        "result": "supported"
    },
    {
        "idx": 2,
        "result": "unsupported"
    }
]

Below are the reference and statements:
<reference>
FCC Cyber Trust Mark and Cybersecurity Testing | Applus+ Keystone

FCC Cybersecurity testing for IoT devices. Certification requirements, cybersecurity standards, and U.S. Cyber Trust Mark eligibility. Request a quote now!

Markets
Standards
About
European Union
United States
FCC Cyber Trust Testing Overview
EU Cyber Resilience Act (CRA)
EN 18031 Radio Equipment Directive (RED)
FCC Testing of Device Types
FCC Testing of Product Categories
FCC Testing of Equipment Ecosystems
ETSI EN 303-645
IEC 62443
FDA 510(k)
Cybersecurity Testing Overview
Request A Quote
IoT Penetration, EMC, and Wireless Combined
×
Test Types
Commercial Testing
Military Testing
Country-Specific Testing
Industries
EMC Test Types
Wireless Certification Testing
–
New!
EMC/EMI Compliance Testing
Lightning & Surge Testing
Shielding Effectiveness
Electrostatic Discharge Testing (ESD)
EMC Pre-Compliance Testing
On-Site and In-Situ Testing
What is EMC/EMI Testing?
EMP Compliance Testing
Common Sources of EMI
EMI in the Workplace
Research & Development
Commercial Test Standards
All Commercial EMC Testing
AIM 7351731 EMC Testing
ANSI EMC Testing
ASTM EMC Testing
CE Mark Certification
CISPR EMC Testing
CNS-13438 ITE Testing
E-Mark for Motor Vehicles
EN EMC Testing
FCC EMC Testing
ICES EMC Testing
IEC EMC Testing
IEEE 299 EMC Testing
NRTL EMC Testing
SAE/US CAR-2-6 Automotive
ANSI Wireless Testing
–
New!
CFR Wireless Testing
–
New!
IEEE Wireless Testing
–
New!
TIA Wireless Testing
–
New!
Military EMC Testing
All Military EMC Standards
Boeing EMC Testing
MIL-STD-188-125-1 HEMP
MIL-STD-285 Electromagnetic Shielding
MIL-STD-461 Overview
MIL-STD-464 Airborne, Sea, & Ground
MIL-STD-907B Shielding Effectiveness
MIL-STD-1377 Cable Shielding and Filters
MIL-STD-750 Immersion Testing
MIL-STD-1399 Shipboard User Equipment
MIL-G-83528 Shielding of Gasket Material
MPD-7011F Wire Harness Testing
RTCA DO-160 EMC Testing
Country-Specific Standards
Australia EMC Testing
Canada EMC Testing
Japanese EMC Testing Standards
South Korea EMC Testing
New Zealand EMC Testing
Vietnam EMC Testing
Canadian Wireless Testing
–
New!
European Wireless Testing
–
New!
New Zealand Wireless Testing
–
New!
Singapore Wireless Testing
–
New!
Taiwanese Wireless Testing
–
New!
Industries
Autonomous Vehicles
Agricultural Machinery
Electronics
Manufacturing
Medical
Military & Aerospace
Nuclear
Railway
Transportation
UAV
×
Test Types
Commercial Testing
Military Testing
Industries
Environmental Test Types
Acceleration
Altitude
Arizona Dust
Climatics
Corrosion
Drop
Dynamics
Fungus Resistance
Halt / Hass

– New!!
Humidity
Icing & Freezing Rain
Immersion
Ingress Protection
Loose Cargo Bounce
Reliability
Salt-Fog Testing
Sand & Dust
Shock
Solar Radiation
Temperature
Temperature Validation
Temperature Over Vibration
Thermal Shock
Vibration Testing
Wind & Rain
Commercial Test Standards
All Commercial Environmental Standards
AAR S9401 Electronic Railway Equipment
ANSI C136.31 Roadway & Lighting
AREMA Railway Equipment
ASTM Environmental Testing
EIA-364E Electrical Connectors/Sockets
EN Environmental Standards
IEC Environmental Standards
IEEE C37.30 High-Voltage of Air Switches
ISO Environmental Standards
JIS D 0203 Automotive Ingress Protection
SAE Environmental Standards
TAPPI Environmental Standards
UL 1703 Photovoltaic Modules & Panels
Military Testing
Military Environmental Standards
ATPD 2352 Transparent Armor
Boeing D6-81926 Vibration
DEF STAN 81-41 Part 3 Packaging
DEF STAN 00-035 Part 3 Environmental
ITOP 1-2-601 Vibration
RTCA D0-160 Airborne Equipment
MIL-STD Environmental Testing
MIL-STD-108
Electronic
Enclosures
MIL-STD-167 Shipboard Equipment
MIL-STD-202 Electronic Component Parts
MIL-STD-331 Weapon System Fuses
MIL-STD-750 Semiconductor Devices
MIL-STD-810 Environmental Conditions
MIL-STD-883 Testing of Microcircuits
MIL-STD-1344 Electrical Connectors
Industry Testing
Autonomous Vehicles
Electronics
Manufacturing
Medical
Military & Aerospace
Railway
Transportation
×
Test Types
Test Standards
Industries
About
Package Testing Types
Accelerated Aging
Altitude
Bridge Impact
Bubble Leak
Burst Strength
Cold Chain
Conditioning
Compression
Drop
Flexible Package
Forklift Handling
Inclined Impact
Impact
Pallet
Parcel
Rotational Corner Drop
Rotational Edge Drop
Rotational Flat Drop
Seal Strength
Sterile Barrier System
Temperature Validation
Tip-Over
Vertical Compression
Vibration
Package Testing Standards
Amazon
ASTM
E-Commerce
General Motors
IEC
ISO
ISTA
NMFC
NSF Vaccine Storage
TAPPI
Industry Testing
Consumer Products Package Integrity Testing
E-Commerce Package Integrity and Distribution Testing
Frozen Food Package Integrity Testing: Cold Chain and Temperature Validation
Industrial Products Packaging Testing
Medical Device Package Certification Testing
Personal Care & Beauty Products Packaging Testing
Pharmaceutical Packaging Integrity Testing
About Package Testing
Package Testing Overview
Package Testing Standards
FAQ
ISTA Planner Tool

– New!!!
How to Submit a Sample
Accelerated Aging Time Calculator
Accreditations
Package Testing Brochures
What Are Damaged Shipments Costing You?
×
Overview
Commercial Testing
Military Testing
Test Types
NEMA Enclosure Testing
Ingress Protection Overview
Ingress Protection IP Code Testing
IP Code Test Planner
– NEW
IP Code Chart: Ingress Protection Ratings
Causes of Water-Based IP Test Failures
Enclosure Ingress Protection Ratings
Popular IP Code Standards
Request an IP Code Quote
IP Commercial Test Standards
IP Code Testing Standards
ASTM D951 Water Resistance by Spray
EN 60945 Navigation & Radio Equipment
IEC 60068-2-68 Sand & Dust
IEC 60529 Electronic Enclosures
IEC 60598 Luminaire
ISO 20653 Vehicles Against Foreign Objects
JIS-D-0203 Moisture & Spray of Automotive Parts
IP Military Test Standards
MIL-STD-202 Method 104 Immersion
MIL-STD-750 Method 1011 Immersion
MIL-STD 883 Method 1002 Immersion
RTCA DO-160 Waterproofness
IP Test Types
IPX1 & IPX2 Dripping Water
IPX3 & IPX4 Spraying/Splashing Water
IPX5 & IPX6 Water Jets
IPX7 & IPX8 Water Immersion
IPX9 High Temp & Pressure Water Jets
IP69K Ingress Protection
IP1X – IP4X Solids
IP5X & IP6X Dust
NEMA Enclosure Testing
NEMA Enclosure Testing
NEMA 250 Type 1 Enclosures
NEMA 250 Type 2 Enclosures
NEMA 250 Type 3 Enclosures
NEMA 250 Type 3R Enclosures
NEMA 250 Type 3RX Enclosures
NEMA 250 Type 3S Enclosures
NEMA 250 Type 3SX Enclosures
NEMA 250 Type 3X Enclosures
NEMA 250 Type 4 Enclosures
NEMA 250 Type 4X Enclosures
NEMA 250 Type 5 Enclosures
NEMA 250 Type 6 Enclosures
NEMA 250 Type 6P Enclosures
NEMA 250 Type 12 Enclosures
NEMA 250 Type 12K Enclosures
NEMA 250 Type 13 Enclosures
×
Our Company
A+ Resources
Connect with Us
Our Company
Accreditation
Applus+ Laboratories
Company Overview
Facility & Equipment
Ethics & Compliance
Testimonials
Resources
Articles & White Papers
Brochures
Directions
FAQ
Payment Portal
Tools & Calculators

– New!!
Visitor’s Guide
Videos
Connect with Us
Customer Survey
Contact Us
Employment
Report Revisions
Request a Quote
×
Overview
Test Standards
Industries
Safety Testing Overview
Safety Certification Testing
Pre-Certification Compliance
Medical Consulting
Mitigation
Safety Consulting
Global Market Access
Request a Safety Quote
Safety Test Standards
IEC 61010
IEC 60601
CB Scheme
IEC 62368
IEC 60204
ISO 14971
IEC 60601-2-60
Industry Testing
Consumer Electronics
Industrial Equipment
Hazardous Locations
Scientific and Laboratory Equipment
Medical Devices
Household Appliances
Lighting Products
IT and Security
Batteries and Power Supply
ENERGY STAR®
×

Request a Quote

Search for:

Cybersecurity
EMC/EMI
Environmental
Package
IP Code
About

FCC Cyber Trust Regulatory Compliance Testing
The FCC created it for consumer Internet of Things (IoT) devices like smart cameras, thermostats, locks, lights, wearables, baby monitors, and similar connected products.
The
FCC U.S. Cyber Trust Mark
will become
mandatory on January 4, 2027
, but
only for vendors supplying consumer Internet of Things (IoT) products to the U.S. federal government
. For the general consumer marketplace and retail stores, the labeling program remains entirely voluntary.
Summary of the FCC Cyber Trust Testing Standard
The FCC Cyber Trust Mark program is designed to create a more consistent way to evaluate connected consumer products. Instead of each company defining cybersecurity in its own way, the program gives manufacturers a shared set of expectations to work toward before a product can be labeled.
This makes the standard useful because many smart products depend on more than just hardware. A connected device may rely on accounts, apps, remote servers, and update systems to operate safely. The Cyber Trust process helps make sure those supporting pieces are considered as part of the overall cybersecurity picture.
A manufacturer can apply to use the U.S. Cyber Trust Mark on an eligible connected product. To earn the mark, the product must meet FCC-approved cybersecurity requirements that are meant to show the device has been reviewed for baseline security protections. If you think you can benefit from this category of compliance testing,
contact us
today!
The label is binary, meaning the product either qualifies or it does not. It is not a 1-to-5-star rating, a grade, or a ranking against other products.
The label includes two main parts:
The Cyber Trust Mark logo —
This gives shoppers a quick visual signal that the product has gone through the FCC Cyber Trust Mark process.
A QR code —
The QR code links shoppers to a registry with plain-language cybersecurity information about that specific product. This helps users look beyond the logo and review details about the product’s security support, setup, and certification information.
Scope of the Cybersecurity Areas Reviewed
The FCC based the program on NIST IR 8425, a NIST baseline for consumer IoT cybersecurity. The product should be designed so it can be identified, configured securely, protect data, control access, receive secure updates, detect cybersecurity issues, and give users useful security information.
Examples include:
Avoiding insecure default credentials.
The device should support secure software updates.
Access should be limited to authorized users/services.
Data should be protected at rest and in transit.
The company should have a way to receive and share security info.
Users should receive instructions from the manufacturer for secure setup and usage.
What the QR code is supposed to tell you
The QR registry is meant to answer practical questions like:
Who made the product?
Who certified it?
What lab tested it?
Can you change the default password?
How do you set it up securely?
Are software/security updates automatic?
How long will the manufacturer support the product with security fixes?
Does the manufacturer maintain a software bill of materials (SBOM) or hardware bill of materials (HBOM)?
This QR code support period is important because the FCC specifically wants buyers to see how long the maker promises to identify critical vulnerabilities and issue updates. For example, a smart camera that stops getting patches can become risky even if it worked fine when a user bought it.
What kinds of products are covered in the FCC standard?
The program initially focuses on wireless consumer IoT products. “Consumer” means normal home/consumer use, not industrial or enterprise gear. The FCC gives examples of “smart” products including:
thermostats
lights
locks
cameras
watches
fitness trackers
Additionally, the FCC Cyber Trust standard excludes some categories, including FDA regulated medical devices and motor vehicles/motor vehicle equipment, because those are already handled by other regulators. Products tied to certain national security risk lists are also excluded from using the label.
How Can A Company Receive The FCC Mark?
The compliance program goes as follows:
Check that the product is eligible.
Get the product tested by an accredited/recognized lab.
Get a conformity/compliance report.
Submit an application to an FCC-recognized Cybersecurity Label Administrator.
If approved, the company can put the FCC IoT Label/Cyber Trust Mark on the product.
The FCC oversees the program, but third-party administrators and labs such as Applus+ Keystone do much of the day-to-day reviewing and testing.
Program status:
The FCC has selected
ioXt Alliance
as Lead Administrator to help finalize implementation, including technical standards, testing procedures, and label design.
Is FCC Cyber Trust Testing Mandatory?
For regular consumer sales, it is voluntary. A company does not have to participate, but if it uses the mark, it has to follow the program rules.
For federal government buying, there is a major twist: a June 2025 Executive Order directed FAR Council agencies to work toward requiring federal vendors of consumer IoT products to carry the U.S. Cyber Trust Mark by January 4, 2027, where appropriate and lawful.
What it does
not
mean
The mark does not mean “unhackable.” It means the product met a baseline program standard at the time of authorization and has certain support/disclosure obligations.
It also does not replace best practices. You still want to update devices, change default passwords, use strong Wi-Fi security, remove unused devices, and avoid sketchy apps.
Why Does FCC Cybersecurity Testing Matter?
For Consumers
FCC Cyber Trust testing makes it easier to compare connected devices using cybersecurity criteria, not just price, features, or brand recognition. This gives buyers more visibility into whether a product has been reviewed against a recognized security standard.
For Manufacturers
The U.S. Cyber Trust Mark can help show that cybersecurity was considered as part of the product’s design and support process. As connected device security becomes more important, the mark may help products stand out to retailers, business buyers, and government purchasers looking for added confidence.
Marketing and Compliance Teams,
Lastly, marketing teams use testing to support stronger product messaging, but the language still needs to stay accurate. Instead of making broad claims like “hack proof” or “fully secure,” a safer approach is to say the product is “certified to meet FCC U.S. Cyber Trust Mark program requirements.”
Expert Cyber Security Testing for IoT manufacturers
Applus+ Keystone is ready to support your FCC cybersecurity testing and compliance needs. As an ISO/IEC 17025 accredited laboratory with extensive experience in wireless, EMC, and regulatory testing, we are expanding our capabilities to help manufacturers evaluate connected devices against evolving FCC cybersecurity requirements. Our team provides comprehensive testing support to help identify vulnerabilities, verify compliance, and prepare products for market.
Whether you are pursuing the FCC Cyber Trust Mark, validating the cybersecurity of IoT devices, or preparing connected products for regulatory approval, our experts deliver accurate, reliable results backed by decades of testing experience. From product development through certification, we help manufacturers navigate changing cybersecurity requirements with confidence.
Contact Applus+ Keystone
today to discuss your FCC cybersecurity testing needs and learn how our expanded cybersecurity testing capabilities can support your next project.
Additional FCC Cyber Trust Testing and Related Standards
Cyber Security Testing of Product Types
Cyber Security Testing of Product Categories
Cyber Security Testing of Product ecosystems
IoT Penetration Testing, Electromagnetic Compatibility, and Wireless Testing

Request a Quote!

Request A Cybersecurity Testing Quote
Additional Electronic Testing
FCC Cyber Trust Mark
– New!!
European Wireless Testing
Country Specific Wireless Testing
Commercial Wireless Testing
CE Mark

/

FCC Certification
Pre-Certification
Lightning & Surge
Electrostatic Discharge (ESD)
Electromagnetic Pulse (EMP)
Other Common Testing Types
EMC/EMI
Halt/Hass
– New!
IP Code
Global Market Access
Package Integrity
Cold Chain

Pennsylvania Lab
131 N. Columbus Innerbelt
New Castle, PA 16101
(724) 657-9940

PEnnsylvania Package Testing Lab
203 Commerce Avenue
New Castle, PA 16101
(724) 657-9940

Michigan Lab
32201 North Avis Drive
Madison Heights, MI 48071
(248) 588-9770

North Carolina Lab
2320 Presidential Drive
Suite 101
Durham, NC 27703
(919) 296-0098

Request a Quote
Directions
Customer Survey
Contact Us
Sitemap
Payment Portal
Visitor’s Guide
Follow
Follow
© Applus+ Keystone
Policies & Terms
</reference>

<statements>
1. Compliance is already required to access public institutional procurement pipelines
</statements>

Begin the assessment now. Output only the JSON list, without any conversational text or explanations.