FCC investigation may throw its self-created IoT security certification program into trouble
The U.S. Federal Communications Commission (FCC) launched the U.S. Cyber Trust Mark program during the Biden administration to provide security certification for IoT devices. However, the new FCC chair under the Trump administration has initiated a China-related investigation into UL Solutions, the program's designated administrator, which may stall the program. Experts warn that a prolonged investigation will weaken the program's effectiveness and increase cybersecurity risks faced by consumers and businesses.

The U.S. government is working to establish a cybersecurity certification labeling program for internet-connected devices, but this ambitious initiative is facing a serious threat from its own sponsoring agency.
During the Biden administration, the U.S. Federal Communications Commission (FCC) launched the U.S. Cyber Trust Mark program with great fanfare. Government officials and tech industry executives said the certification process would transform the security landscape of connected devices, making it significantly harder for hackers to exploit these devices for cyberattacks. However, months after President Donald Trump took office, the FCC's new Republican chairman launched an investigation into the company the commission staff had just selected to run the program—Illinois-based testing giant UL Solutions—over its ties to China.
The FCC has revealed little about the investigation, leaving outsiders unclear on how it is progressing or even what exactly it aims to determine. This ambiguity worries some cybersecurity experts and former Biden administration officials, who believe a prolonged investigation could weaken the program and thereby extend dangerous conditions in cyberspace.
"If this drags on without trying to implement a similar program," said Paul Besozzi, a senior partner at law firm Squire Patton Boggs specializing in telecommunications matters, "the risks to consumers will only grow." — This includes the many businesses that equip their offices with connected devices.
Peace of Mind Shopping
For years, hackers have hijacked poorly secured internet-of-things devices to build botnets and launch cyberattacks that cause business disruptions and data theft. To change the incentive structure that leads manufacturers to ship flawed products, the Biden administration worked with the FCC to create a government-endorsed security label for connected devices, similar to the Environmental Protection Agency's Energy Star efficiency label.
The FCC launched the U.S. Cyber Trust Mark program at the end of the Biden administration, and the White House at the time hailed the launch as a turning point that would encourage suppliers to improve their products and encourage customers—from individuals to businesses—to prioritize security in their purchasing decisions, especially in sensitive use cases.
"The IoT security landscape for many devices is not ideal," said Matt Pearl, director of the Strategic Technologies Program at the Center for Strategic and International Studies and a former National Security Council staffer who helped launch the Cyber Trust Mark program. "The idea was to create a 'race to the top.'"
After the program's launch, companies approved by UL and other program administrators will test IoT devices such as smart appliances and surveillance cameras, evaluating their performance on features like data protection, access control, and lifecycle documentation. The proposed testing standards, still under review, include requirements such as component lists, supporting secure deletion of user data, restricting changes to security settings, and the ability to restore products to a secure default state.
Products that meet the standards will be authorized to display the program's label, indicating government recognition, designed to make secure products more attractive to business and individual buyers. A public database will include test result information for each certified product, including the period during which the manufacturer commits to providing support.
Focus on 'Bad Labs'
The Cyber Trust Mark program has been overshadowed as Trump's new FCC chairman, Brendan Carr, moves to block companies with ties to U.S. adversaries from participating in certification work for FCC programs. In May, the commission barred these so-called "bad labs" from its work. The Biden-era FCC had already blocked some untrusted companies from serving as administrators of the Cyber Trust Mark program. But Carr, who voted for the program, believed the restrictions were insufficient. In June, he confirmed a Fox News report that the FCC was investigating UL's joint ventures with Chinese state-owned enterprises and its laboratory operations in China.
Squire Patton Boggs' Besozzi explained that a joint venture alone might not be enough to trigger UL's exclusion under FCC standards, but if the commission has evidence of more serious issues, launching an investigation would not be surprising.
Pearl expressed support for the FCC's investigation, especially if it focuses on "legitimate questions" about UL's testing in China, but he added that "just because they have a joint venture" should not be grounds for disqualification.
UL declined to comment on the FCC's investigation. Kathy Fieweger, UL's chief corporate communications officer, said the company "takes cybersecurity very seriously and always operates with transparency and integrity." "We understand the program is under review," she said, "but we have not yet received any indication that circumstances have changed."
Questions Over Unusual Investigation
Other observers take a more critical view of the sudden delay in the Cyber Trust Mark program, which had enjoyed bipartisan support and undergone years of legal review and public comment periods.
"This investigation is a joke," said a former government official who spoke on condition of anonymity. The FCC chose UL "because they have extensive experience handling these types of matters," the former official added. If the commission worries that Beijing might use its Chinese employees as leverage to coerce UL, "then we have a bigger problem," the former official said, "given UL's role in health and safety testing within the U.S. consumer ecosystem."
The FCC did not respond to multiple requests for comment.
Given the industry's broad support for the labeling program, further delays could test the tech sector's patience with the FCC's investigation. The program "is a good idea," Besozzi said, "and should be pushed forward." David Simon, a partner at Skadden, Arps, Slate, Meagher & Flom LLP and co-head of the cybersecurity practice, said he is "not aware" of whether the FCC has previously launched a national security risk investigation into a company it had just approved to run one of its programs.
Momentum at Risk
Experts say the longer the FCC investigation continues, the more it will weaken the Cyber Trust Mark program. Prolonged delays could discourage IoT suppliers from submitting products for testing, severely limiting the program's effectiveness.
"I've spoken with companies that told me they are deciding whether it's worth the effort to participate in this program," Pearl said. The most critical factor for the program's success "is having a steady stream of companies submitting products," the former government official said, noting that major South Korean connected device makers, including LG and Samsung, "are ready to get started."
Make It Work, or Break It
Experts point out that the FCC has several ways to end the investigation and get the Cyber Trust Mark program back on track. One option is to have UL commit to not conducting testing for the program in its Chinese laboratories (the company did not respond to email inquiries about whether it has made such a commitment). "I think moving testing out of China would be a fairly easy mitigation measure," Pearl said.
If the joint venture is the FCC's biggest concern, "they could likely come up with some kind of mitigation," Pearl said. If company leadership believes the joint venture is less important than the reputational boost from overseeing the Cyber Trust Mark program, UL could choose to end the partnership.
The FCC could also choose to revoke its approval of UL's application to serve as the lead label administrator. That would be the most disruptive option, as it would force the commission to restart the process of selecting a lead administrator. The FCC could assign the role to other label administrators, but it is unclear whether any of them are prepared to take on program leadership.
Besozzi said it is unclear whether UL's China ties "would lead to its disqualification," but he added that given Carr's focus on excluding "bad labs," "I think you have to come up with some mechanism to mitigate these concerns."
Pressure from Europe and Industry
Although the FCC investigation has heightened anxiety about the Cyber Trust Mark's future, experts say the label was not imminent anyway. Even before the UL investigation began, the program was months away from accepting product submissions. The testing standards still need to go through a public comment period and receive FCC approval (UL submitted proposed standards in June), and parties have yet to finalize the label's design.
"We are far from people actually applying for these marks," Besozzi said. "There is still a long way to go."
The program's future may depend on how the tech industry engages with the FCC. Mandatory IoT security requirements in the European Union's new Cyber Resilience Act could increase suppliers' willingness to advertise their security in the U.S. Carr has been "in dialogue with the industry," Pearl said, and companies "are generally very supportive of the program."