Information Center
Information Center
Knowledge Center
2025-04-29

FCC Workshop: IoT Product Cybersecurity Insights

Share:

The recent FCC Workshop provided extensive information on cybersecurity testing and certification for IoT products. Drawing from the workshop content, BTL has conducted further research and consolidated the findings. These insights offer a comprehensive view of global requirements for cybersecurity in IoT products.


CountryStatuteName

Applicable Subject

(Product/Scope)

State

Labelin

 requirements

Effective Date
IndiaITSARs : 3GPP TS 33.117(Version 14)/MTCTEIndia Telecom Security

• All kinds of telecommunications products

• Wi-Fi CPEs, IP routers, 5G session management functions (SMF, OLTs, ONTs/PON) must be MTCTE certified

compulsion\\
SingaporeCommon Standard (CC) and Common Method (CEM)Cyber Security in Singapore

• Wi-Fi routers

• Consumer IoT devices (e.g., IP cameras)

• All smart devices (smart door locks, smart lights, smart printers, etc.)

\

CLS(IoT)Label

1745908185869371.png

2023/07/01

Japan

(IPA)

Cyber STAR(JC-STAR)Japan Cyber STAR (JC-STAR) Voluntary Program

• Direct or indirect connection to Internet devices (consumer and industrial products) via IP

• Covered devices: routers, IP cameras, hubs, smart home devices, PLCs, sensors, controllers, etc.


Voluntary1745908245632825.png

2025/03 (Japanese version)

 

2026 STAR-2, STAR-3, STAR-4 launched


KoreaITU-T X.1352 LabelKorea Internet of Things Cyber Security (KISA).

Security assessment of Internet of Things (IoT) devices

Voluntary1745908298135240.png\
FinlandEN 303 645 Transport and communication in Finland (Traficom)

Mainly covered: 

• Smart home devices, smart cameras, smart lamps, etc., to ensure that products have basic network security protection

Voluntary(RED-DA & CRA)CE marking\
BrazilAct 9281ANATEL (National Telecommunications Service of Brazil)

At present, market surveillance is mainly focused on IPTV devices:

• ANATEL is committed to reducing and possibly discontinuing the operation of IPTV equipment.

• ANATEL has a dedicated laboratory that monitors IPTV servers, identifies their locations, and attempts to block their functionality.


\\\
Saudi Arabia

IoT Cybersecurity Guide (CGIoT-1:2024)

Saudi Arabia's National Cyber Security Agency (NCA)

There is no need for a certificate or Declaration of Conformity (DoC), but instead a code of conduct is provided to guide the security of IoT products

\\\
ChinaGB 42250:2022CCRC Cyber Security Office

What covers: Technical requirements for cybersecurity-specific products.

Covers 33 product categories, including:

• All wireless and networking products (e.g., routers, switches, firewalls, etc.).

• The automotive industry has recently added the GB 44495 standard to standardize vehicle information security.

\\\
Australia

Australian Cyber Security Act 2024 (IoT Home Devices)

Australian Information Security Assessment Program (AISEP).

Manufacturer's Obligations

• Declaration of Conformity

• Regulatory Agencies Commodity Testing

• Foreign Manufacturer Obligations

• Support Period

compulsion

\

Effective Date: 2025

 

Date of Compliance: 2026/03/06 The first three principles of the ETSI EN 303 645 standard


United

Kingdom

Consumer IoT Cybersecurity Regulation (PSTI)


Consumer IoT Cybersecurity Regulation (PSTI)

An initial security baseline is intended for manufacturers to ensure that the product has basic security protections.

Safety requirements 2 and 3 Expansion applies:

• Cybersecurity technology that cannot be installed on a physical device.

• Equipment provided by the manufacturer of the product.

VoluntaryCE marking

2025/08/01 according to EN 303 645 part      

EU RED

RED

 3.3(d)3.3(e)3.3(f)


Notified Body EU-TEC Certification

Applicability of the standard:

• If the product is within the scope of application, the applicable terms of EN 18031-x (if the harmonised standard route is chosen) will be determined.

• Products are evaluated against the standard and, if necessary, EU-TEC certification from a Notified Body.

VoluntaryCE marking

2025/08/01

EU CRA

CRA (Cyber Resilience Act) reporting obligations

ENISA (European Network and Information Security Agency).

Report Object:

• The manufacturer submits a report to ENISA (European Network and Information Security Agency).

• Use the Single Reporting Platform (SRA) established by ENISA (see Article 16 of the CRA for details).

Time frame for reporting:

• Initial Notice: Submitted within 24 hours of becoming aware of the incident.

• Initial assessment: impact and mitigation measures within 72 hours.

• Final Report: Submit a full incident report within one month of the initial assessment, including impact, root cause, and remediation options.

Covers a wide range of goods, including:

• Photo editing, word processing software. 

• Digital products such as smart speakers, hard drives, and gaming devices. 

• Products with network security needs, such as VPNs, password managers, routers, switches, etc.

\

CE marking

2026/09/11


BTL is currently building relevant Cybersecurity testing capabilities. If you are interested, please contact us for further information.


Relevant information

EU Releases Exemption Guidelines on Removability and Replaceability of Portable and LMT Batteries — Multiple Product Categories Relief Granted
2026-08-04

EU Releases Exemption Guidelines on Removability and Replaceability of Portable and LMT Batteries — Multiple Product Categories Relief Granted

On July 14, 2026, the European Commission published the "Commission Guidelines to Facilitate the Harmonised Application of Provisions on the Removability and Replaceability of Portable and Light Means of Transport (LMT) Batteries" (Commission Notice C(2026) 5032 final). These guidelines aim to provide a uniform interpretative framework for the implementation of Article 11 of the EU Battery Regulat

6G Developments: Past, Present and Future
2026-07-28

6G Developments: Past, Present and Future

The formulation of 6G standards has entered a more concrete phase. At the 3GPP RAN Plenary Meeting held in Singapore in June 2026, the industry made progress in multiple key research areas and finalized the timeline for Release 21, which is regarded as the first standard version expected to formally define 6G.

Overview of EN IEC 61000-4-29:2026
2026-07-03

Overview of EN IEC 61000-4-29:2026

The key focus of the 2026 edition is to address new DC power distribution environments, especially higher-voltage DC systems. It also clarifies test generator capability, duration tolerance, current limitation during short interruptions, inrush current verification, result evaluation, and test report requirements. For products using 24 Vdc, 48 Vdc, 380 Vdc, 400 Vdc, 800 Vdc, or other DC input pow

Privacy Preference Center

We use cookies to allow our website to function properly, personalize content and advertisements, provide social media features, and analyze traffic. We also share information about your use of our website with our social media, advertising, and analytics partners.

View Privacy Policy

Manage consent settings

Necessary Cookies

Uniformly activate

The operation of the website relies on these cookies, and you cannot disable them in the system. These cookies are typically set based on your actions (i.e., service requests), such as setting privacy preferences, logging in, or filling out forms. You can configure your browser to block or prompt you about these cookies, but this may cause certain website functionalities to not work.

Select Language