FCC Workshop: IoT Product Cybersecurity Insights
The recent FCC Workshop provided extensive information on cybersecurity testing and certification for IoT products. Drawing from the workshop content, BTL has conducted further research and consolidated the findings. These insights offer a comprehensive view of global requirements for cybersecurity in IoT products.
| Country | Statute | Name | Applicable Subject (Product/Scope) | State | Labelin requirements | Effective Date |
| India | ITSARs : 3GPP TS 33.117(Version 14)/MTCTE | India Telecom Security | • All kinds of telecommunications products • Wi-Fi CPEs, IP routers, 5G session management functions (SMF, OLTs, ONTs/PON) must be MTCTE certified | compulsion | \ | \ |
| Singapore | Common Standard (CC) and Common Method (CEM) | Cyber Security in Singapore | • Wi-Fi routers • Consumer IoT devices (e.g., IP cameras) • All smart devices (smart door locks, smart lights, smart printers, etc.) | \ | CLS(IoT)Label
| 2023/07/01 |
Japan (IPA) | Cyber STAR(JC-STAR) | Japan Cyber STAR (JC-STAR) Voluntary Program | • Direct or indirect connection to Internet devices (consumer and industrial products) via IP • Covered devices: routers, IP cameras, hubs, smart home devices, PLCs, sensors, controllers, etc. | Voluntary | ![]() | 2025/03 (Japanese version)
2026 STAR-2, STAR-3, STAR-4 launched |
| Korea | ITU-T X.1352 Label | Korea Internet of Things Cyber Security (KISA). | Security assessment of Internet of Things (IoT) devices | Voluntary | ![]() | \ |
| Finland | EN 303 645 | Transport and communication in Finland (Traficom) | Mainly covered: • Smart home devices, smart cameras, smart lamps, etc., to ensure that products have basic network security protection | Voluntary(RED-DA & CRA) | CE marking | \ |
| Brazil | Act 9281 | ANATEL (National Telecommunications Service of Brazil) | At present, market surveillance is mainly focused on IPTV devices: • ANATEL is committed to reducing and possibly discontinuing the operation of IPTV equipment. • ANATEL has a dedicated laboratory that monitors IPTV servers, identifies their locations, and attempts to block their functionality. | \ | \ | \ |
| Saudi Arabia | IoT Cybersecurity Guide (CGIoT-1:2024) | Saudi Arabia's National Cyber Security Agency (NCA) | There is no need for a certificate or Declaration of Conformity (DoC), but instead a code of conduct is provided to guide the security of IoT products | \ | \ | \ |
| China | GB 42250:2022 | CCRC Cyber Security Office | What covers: Technical requirements for cybersecurity-specific products. Covers 33 product categories, including: • All wireless and networking products (e.g., routers, switches, firewalls, etc.). • The automotive industry has recently added the GB 44495 standard to standardize vehicle information security. | \ | \ | \ |
| Australia | Australian Cyber Security Act 2024 (IoT Home Devices) | Australian Information Security Assessment Program (AISEP). | Manufacturer's Obligations • Declaration of Conformity • Regulatory Agencies Commodity Testing • Foreign Manufacturer Obligations • Support Period | compulsion | \ | Effective Date: 2025 Date of Compliance: 2026/03/06 The first three principles of the ETSI EN 303 645 standard |
United Kingdom | Consumer IoT Cybersecurity Regulation (PSTI) | Consumer IoT Cybersecurity Regulation (PSTI) | An initial security baseline is intended for manufacturers to ensure that the product has basic security protections. Safety requirements 2 and 3 Expansion applies: • Cybersecurity technology that cannot be installed on a physical device. • Equipment provided by the manufacturer of the product. | Voluntary | CE marking | 2025/08/01 according to EN 303 645 part |
| EU RED | RED 3.3(d)、3.3(e)、3.3(f) | Notified Body EU-TEC Certification | Applicability of the standard: • If the product is within the scope of application, the applicable terms of EN 18031-x (if the harmonised standard route is chosen) will be determined. • Products are evaluated against the standard and, if necessary, EU-TEC certification from a Notified Body. | Voluntary | CE marking | 2025/08/01 |
| EU CRA | CRA (Cyber Resilience Act) reporting obligations | ENISA (European Network and Information Security Agency). | Report Object: • The manufacturer submits a report to ENISA (European Network and Information Security Agency). • Use the Single Reporting Platform (SRA) established by ENISA (see Article 16 of the CRA for details). Time frame for reporting: • Initial Notice: Submitted within 24 hours of becoming aware of the incident. • Initial assessment: impact and mitigation measures within 72 hours. • Final Report: Submit a full incident report within one month of the initial assessment, including impact, root cause, and remediation options. Covers a wide range of goods, including: • Photo editing, word processing software. • Digital products such as smart speakers, hard drives, and gaming devices. • Products with network security needs, such as VPNs, password managers, routers, switches, etc. | \ | CE marking | 2026/09/11 |
BTL is currently building relevant Cybersecurity testing capabilities. If you are interested, please contact us for further information.
Relevant information
EU Releases Exemption Guidelines on Removability and Replaceability of Portable and LMT Batteries — Multiple Product Categories Relief Granted
On July 14, 2026, the European Commission published the "Commission Guidelines to Facilitate the Harmonised Application of Provisions on the Removability and Replaceability of Portable and Light Means of Transport (LMT) Batteries" (Commission Notice C(2026) 5032 final). These guidelines aim to provide a uniform interpretative framework for the implementation of Article 11 of the EU Battery Regulat
6G Developments: Past, Present and Future
The formulation of 6G standards has entered a more concrete phase. At the 3GPP RAN Plenary Meeting held in Singapore in June 2026, the industry made progress in multiple key research areas and finalized the timeline for Release 21, which is regarded as the first standard version expected to formally define 6G.
Overview of EN IEC 61000-4-29:2026
The key focus of the 2026 edition is to address new DC power distribution environments, especially higher-voltage DC systems. It also clarifies test generator capability, duration tolerance, current limitation during short interruptions, inrush current verification, result evaluation, and test report requirements. For products using 24 Vdc, 48 Vdc, 380 Vdc, 400 Vdc, 800 Vdc, or other DC input pow


