[Home](/)/[Resources](/resources)/US IoT Cybersecurity Improvement Act

USCybersecurityRegulation guide

# US IoT Cybersecurity Improvement Act of 2020

The IoT Cybersecurity Improvement Act of 2020 (Public Law 116-207) requires NIST to develop and publish security standards and guidelines for IoT devices used by federal agencies. While the Act directly governs federal procurement, its NIST guidelines (SP 800-213 and SP 800-213A) are rapidly becoming the de facto standard referenced in commercial IoT procurement — particularly in critical infrastructure supply chains.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Fus-iot-cybersecurity-act)

At a glance

Legislation

Public Law 116-207

Enacted

December 2020

Technical baseline

NIST SP 800-213A

Consumer label

FCC Cyber Trust Mark (2024)

Direct scope

Federal agencies and contractors

## Scope and applicability

### Direct Federal Applicability

The Act directly governs federal agencies purchasing IoT devices and contractors supplying IoT to federal agencies. Agencies must follow NIST standards and guidelines when procuring IoT devices. Contractors must ensure their products meet the capabilities defined in NIST SP 800-213A to be eligible for federal procurement.

### De Facto Commercial Applicability

Critical infrastructure operators using NIST frameworks and commercial enterprises referencing NIST SP 800-213 in procurement are increasingly treating the baseline as a de facto requirement. Supply chain pressure from federal prime contractors is pushing SP 800-213A compliance into commercial IoT product requirements even without a direct regulatory mandate.

### Excluded Devices

General purpose computing devices (laptops, desktops, smartphones) and national security systems are excluded from the Act's scope. The focus is on purpose-built IoT devices — sensors, controllers, gateways, and embedded systems that connect to federal networks or process federal data.

## NIST SP 800-213A IoT device cybersecurity capability core baseline

The six capability areas in SP 800-213A define the minimum cybersecurity features an IoT device must support to be suitable for federal procurement. Each area addresses a distinct aspect of device security throughout its operational lifecycle.

01

Device identification — the device must have a unique logical identifier and must be able to report its manufacturer, model, and serial number to authorized users and systems.

02

Device configuration — the device must support the ability to change its configuration to a secure state, disable features not required for operation, and restore factory default settings.

03

Data protection — the device must protect data it stores and transmits using appropriate cryptographic mechanisms, with secure key management and protection of sensitive configuration data.

04

Logical access to interfaces — the device must support authentication and authorization for each network and local interface, role-based access control, and account lockout after repeated failed access attempts.

05

Software update — the device must support the ability to update its software and firmware, verify the authenticity and integrity of updates before applying them, and communicate the update schedule to operators.

06

Cybersecurity state awareness — the device must support event logging, provide monitoring capability for security-relevant events, and have the ability to report anomalies to external systems.

## Federal procurement compliance process

### Agency Procurement Requirements

Federal agencies must identify IoT devices in their procurement plans, assess whether those devices meet the NIST SP 800-213 baseline, and document their assessment. Agencies that cannot find compliant products may seek a waiver from OMB, but waivers are expected to be rare and time-limited.

### Contractor IoT Capability Statements

Contractors supplying IoT devices to federal agencies are expected to provide documentation of how their devices meet each element of the SP 800-213A baseline. This is typically provided in the form of a device cybersecurity capability statement — a structured declaration against each baseline element.

### FISMA Implications for IoT in Federal Networks

IoT devices connected to federal networks fall under the Federal Information Security Modernization Act (FISMA). Agencies must include IoT devices in their system security plans and ensure they are managed within an authorized information system boundary. Unmanaged IoT devices on federal networks are a FISMA compliance risk.

### FedRAMP for Cloud-Connected IoT Platforms

When an IoT device management platform, data aggregation service, or cloud backend is used to manage federal IoT deployments, that cloud service may need FedRAMP authorization. Vendors offering cloud-connected IoT platforms to the federal market should assess whether their cloud components require FedRAMP authorization at the appropriate impact level.

## Commercial implications and Cyber Trust Mark

### FCC Cyber Trust Mark Program

Launched in 2024, the FCC Cyber Trust Mark is a voluntary labelling scheme for consumer IoT products. Products that meet the cybersecurity requirements — based on NIST SP 800-213A — can display the US Cyber Trust Mark label and link to a product security registry via a QR code. The program is administered through accredited testing laboratories.

### Relationship to IoT Cybersecurity Improvement Act

The FCC Cyber Trust Mark directly implements the consumer-facing equivalent of the federal procurement standards established by the IoT Cybersecurity Improvement Act. Both programs use NIST SP 800-213A as the technical baseline, creating a unified framework that spans federal procurement and commercial consumer products.

### Market Differentiation for Certified Products

Products displaying the Cyber Trust Mark signal to buyers — both consumer and commercial — that the device meets an independently verified cybersecurity baseline. As awareness grows, the mark is expected to become a meaningful differentiator in competitive IoT product categories, particularly for smart home, wearable, and connected appliance segments.

## Frequently asked questions

### Does the IoT Cybersecurity Improvement Act apply to commercial (non-federal) IoT products?

The Act directly applies only to federal agency procurement and their contractors. However, NIST SP 800-213A, which the Act mandated NIST to develop, is widely referenced in commercial procurement requirements — particularly by critical infrastructure operators, healthcare organizations, and enterprises with federal supply chain obligations. The FCC Cyber Trust Mark, which is based on the same NIST baseline, extends the practical reach of these requirements into the consumer market on a voluntary basis.

### What is the FCC Cyber Trust Mark and how does it relate to NIST SP 800-213A?

The FCC Cyber Trust Mark is a voluntary consumer IoT labelling program launched in 2024. Products are tested against requirements derived from NIST SP 800-213A — the same device cybersecurity capability baseline that governs federal procurement. Certified products display the mark and link to a public security registry via QR code. While currently voluntary, the program creates a de facto market standard that manufacturers targeting consumer or government-adjacent markets should engage with proactively.

### Do firmware update capabilities need to be demonstrated or just designed in?

NIST SP 800-213A requires that devices support the ability to update software and firmware — this is a functional capability requirement, not merely a design intent. For federal procurement, agencies and contractors are expected to verify that the capability exists and works as described. For the FCC Cyber Trust Mark, accredited test laboratories assess whether update mechanisms meet the baseline requirements, including authenticity verification of updates. Documentation alone is insufficient — the capability must be testable.

### How does the IoT Cybersecurity Act interact with CISA's known exploited vulnerabilities catalogue?

CISA's Known Exploited Vulnerabilities (KEV) catalogue identifies vulnerabilities being actively exploited in the wild. Federal agencies are required under CISA Binding Operational Directive 22-01 to remediate KEV vulnerabilities on federal networks. IoT devices running software with KEV-listed vulnerabilities that cannot be patched present a significant compliance risk under both the IoT Cybersecurity Improvement Act and BOD 22-01. The software update capability in SP 800-213A is specifically intended to ensure devices can receive patches to address vulnerabilities like those in the KEV catalogue.

**Disclaimer:** This page is an educational resource only and does not constitute legal or regulatory advice. NIST publications and FCC programme requirements are updated periodically. Consult current NIST documents and qualified legal counsel for product-specific compliance decisions.

🇺🇸 US roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap[

Want an expert to take your product through 🇺🇸 US compliance for you?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

See compliance services](/services)

Learn this properly

In-depth course that teaches the full process, not just this one answer.

[Start the course — $149](/courses/12-fcc-cyber-trust-mark-iot-security)[Prefer to read? Get the book — $24.99](/books/12-fcc-cyber-trust-mark-iot-security)

Related guides

*   [US NIST IoT CybersecurityGuide to NIST SP 800-213 and SP 800-213A — the six IoT device cybersecurity capability baseline areas, non-technical documentat…](/guides/us-nist-iot-cybersecurity)
*   [EU Cyber Resilience ActEU Cyber Resilience Act for hardware: default-secure requirements, vulnerability disclosure, 24-hour incident notification, and the four Annex I product classes.](/guides/eu-cyber-resilience-act)
*   [Section 889 Banned ComponentsComplete guide to Section 889 NDAA compliance — the five prohibited manufacturers, Part A and Part B prohibitions, component-le…](/guides/section-889-banned-components)
*   [US Supply Chain SecurityComplete guide to US supply chain security.](/guides/us-supply-chain-security)