India connected devices IoT security regulation

The FCC Is Scaling Its Voluntary IoT Trust Mark Through Competing Labs — India's Device Rules Still Lack One Consumer Signal

FCC adds two more accredited labs to the Cyber Trust Mark program; India's own IoT security regime remains split across three agencies with no equivalent consumer mark.

Two Models for Securing Connected Devices People of Internet Research · India 2 New FCC label administrators IIA Lab Services and Element Mater… 0–3 India IoTSCS assurance levels MeitY's STQC runs a voluntary, gra… Nov 2025 India's baseline IoT code, updated DoT's TEC released version 2.0 of … peopleofinternet.com
Two Models for Securing Connected Devi… People of Internet Research · India 2 New FCC label administrators 0–3 India IoTSCS assurance levels Nov 2025 India's baseline IoT code, updated peopleofinternet.com

Key Takeaways

A wider bench of assessors, not a wider mandate

On August 11, 2026, the FCC's Public Safety and Homeland Security Bureau conditionally approved IIA Lab Services, LLC and Element Materials Technology Portland – Evergreen, Inc. as Cybersecurity Label Administrators (CLAs) for the U.S. Cyber Trust Mark program, and simultaneously reopened an open-ended filing window for additional CLA applicants (FCC Public Notice DA-26-18A1). The program itself is not new — it launched in January 2025 as a voluntary label that consumer device makers can apply to routers, smart cameras, and other connected products that meet baseline security requirements, with UL Solutions initially serving as Lead Administrator before being succeeded by ioXt Alliance. What changed this month is capacity: rather than tightening a single mandatory gate, the FCC is licensing more independent, accredited testing labs to compete for manufacturers' business under one label (Benton Institute summary).

The Bureau paired that expansion with a supply-chain screen: any CLA that becomes owned, controlled, or affiliated with an entity on the FCC's Covered List — which already reaches foreign router makers, several Chinese-based testing facilities, and U.S. firms with alleged ties to Chinese telecom equipment — automatically forfeits its authority (SDxCentral). That is a genuine national-security guardrail layered onto an otherwise market-driven design: multiple accredited private labs compete to certify devices against one publicly recognizable mark, and the government's role is limited to vetting the labs and policing who is allowed to run them.

India's parallel but fragmented path

India has been building toward the same goal — assurance that the smart cameras, routers, and sensors flooding its market meet a security floor — but through a noticeably more scattered architecture. The Department of Telecommunications' Telecommunication Engineering Centre issued the Code of Practice for Securing Consumer IoT (TEC 31318:2021, updated to Release 2.0 in November 2025), a baseline standard broadly aligned with the European ETSI EN 303 645 framework and covering secure defaults, credential management, and vulnerability disclosure (TEC Code of Practice). Separately, MeitY's Standardisation Testing and Quality Certification Directorate runs the IoT System Certification Scheme (IoTSCS), an opt-in scheme that grades devices across assurance levels 0 through 3 depending on the sensitivity of what they touch — from basic sensors to systems handling medical or financial data (STQC IoTSCS). A third track, the Mandatory Testing and Certification of Telecommunication Equipment regime, does compel pre-market testing — but only for devices that connect to telecom networks (gateways, smart meters, certain cameras), not for the broader universe of Wi-Fi and Bluetooth consumer IoT. The result, as one Indian cybersecurity outlet summarized it, is that "there is no single overarching law making all IoT security measures universally mandatory" — enforcement is fragmented across DoT, MeitY, and CERT-In, and there is no consumer-facing mark analogous to the U.S. Cyber Trust Mark that a shopper could actually look for on a box (The420.in).

The case for going further than a voluntary label

There is a real argument for tightening this rather than merely branding it. India's consumer electronics market is price-sensitive and dominated by low-margin imports where security features are the first line item cut; a purely voluntary mark, unless retailers or e-commerce platforms are required to surface it, risks becoming a label that manufacturers who already build securely adopt while the cheapest, least-secure devices — the ones most likely to be conscripted into botnets — never bother. Insecure consumer IoT has already proven itself a national-security liability, not just a consumer-protection one: unpatched devices are the raw material for the DDoS botnets that European regulators and NIST have both flagged as the primary threat vector this class of rule exists to blunt. A government mandate, the argument goes, forces the floor upward across the entire market at once rather than waiting for reputational pressure that price-sensitive buyers may never apply.

Why capacity-building beats mandate-stacking

But India's problem right now is not an absence of legal hooks — it is that it already has three overlapping certification pathways (TEC's code of practice, STQC's IoTSCS, and MTCTE) layered on top of existing BIS and WPC approvals, with no single mark tying them together for consumers. Adding a fourth mandatory layer would raise compliance costs and time-to-market precisely for the small and mid-sized manufacturers the PLI scheme for electronics is trying to cultivate, without doing anything to unify the signal a buyer actually sees. The FCC's move this month is the more exportable lesson: rather than deepen the mandate, widen the number of accredited, competing labs that can certify against one existing voluntary baseline, and pair that expansion with a narrow, targeted security screen on who is allowed to run those labs. India already has the standard (TEC 31318) and the grading scheme (IoTSCS); what it lacks is the single public mark and a multi-administrator testing bench to scale it affordably. Extending mandatory MTCTE-style certification to non-telecom consumer devices — as India has already done narrowly for CCTV under its 2024 Essential Requirements — should stay the exception reserved for genuinely high-risk categories, not the template for the rest of the connected-device market.

A single, well-recognized voluntary mark, backed by several accredited test labs instead of one bureaucratic gate, would do more to lift India's IoT security floor than another overlapping mandatory approval layer.

Sources & Citations

  1. FCC Public Notice DA-26-18A1 (CLA approvals & filing window)
  2. SDxCentral — FCC conditionally approves two more Cyber Trust Mark CLAs
  3. SDxCentral — FCC Cyber Trust Mark push & Covered List screen
  4. STQC (MeitY) — IoT System Certification Scheme
  5. TEC (DoT) — Code of Practice for Securing Consumer IoT, Release 2.0
  6. The420.in — India's fragmented IoT security guidelines