Cybersecurity Labeling for Consumers: Internet of Things (IoT) Devices and Software
The May 12, 2021, Presidential Executive Order on Improving the Nation’s Cybersecurity (14028) directs NIST to initiate two labeling programs on cybersecurity capabilities of Internet-of-Things (IoT) consumer devices and software development practices. The agency also received several other directives to enhance the security of the software supply chain.
Section 4 of the order directs NIST to take into account existing consumer product labeling programs as it considers efforts to educate the public on the cybersecurity capabilities of Internet-of-Things (IoT) devices and software development practices. NIST also is to consider ways to incentivize manufacturers and developers to participate in these programs.
By February 6, 2022, in coordination with the Federal Trade Commission (FTC) and other agencies, NIST is required to identify:
- IoT cybersecurity criteria for a consumer labeling program and
- secure software development practices or criteria for a consumer software labeling program.
NIST is relying heavily on information provided by diverse stakeholders as it carries out these directives. In October, NIST solicited public comments on draft criteria for consumer software cybersecurity and labeling. In August, the agency released for public comment a white paper suggesting a draft set of potential baseline security criteria for IoT devices. In November, NIST solicited public comments on draft criteria for consumer software cybersecurity and labeling.
NIST is identifying key elements of labeling programs in terms of minimum requirements and desirable attributes – rather than establishing its own programs; NIST will specify desired outcomes, allowing providers and customers to choose best solutions for their devices and environments. One size may not fit all, and multiple solutions might be offered by label providers.
Labeling should:
- Encourage innovation in manufacturers’ consumer oriented IoT and software security efforts, leaving room for changes in technologies and the security landscape.
- Be practical and not be burdensome to manufacturers and distributors.
- Factor in usability as a key consideration.
- Build on national and international experience.
- Allow for diversity of approaches and solutions across industries, verticals, and use cases – so long as they are deemed useful and effective for consumers.
On September 14-15, 2021, NIST hosted a virtual public workshop on these consumer education-oriented efforts. The workshop included facilitated panel discussions and presentations based on the preliminary feedback on the draft IoT criteria and the consumer software labeling position papers submitted to NIST and on preliminary feedback on potential IoT baseline security criteria. On December 2, 2021, taking public feedback into account, NIST released a further discussion paper: Consumer Cybersecurity Labeling for IoT Products: Discussion Draft on the Path Forward. This paper will be discussed at the upcoming workshop Cybersecurity Labeling for Consumer IoT and Software: Executive Order Update and Discussion - December 9, 2021.
Questions about NIST’s activities related to these efforts should be directed to
Information technology, Cybersecurity and Internet of Things (IoT) Information technology and Cybersecurity
Workshops on Cybersecurity Labeling of Consumer Products
- Cybersecurity Labeling for Consumer IoT and Software: Executive Order Update and Discussion - December 9, 2021
- Improving the Nation’s Cybersecurity: Progress and Next Steps in Carrying Out Executive Order 14028 - October 14, 2021
- Workshop and Call for Papers on Cybersecurity Labeling Programs for Consumers: Internet of Things (IoT) Devices and Software - September 14-15, 2021
IoT Product Criteria
As part of its assignment under the Presidential Executive Order on Improving the Nation’s Cybersecurity (14028) issued on May 12, 2021, NIST is responsible for a multi-faceted initiative related to cybersecurity labeling for consumers. That includes labeling for Internet of Things (IoT) products. Under the Executive Order, NIST is to publish details about the IoT labeling effort by February 6, 2022. NIST will identify key elements of IoT labeling programs in terms of minimum requirements and desirable attributes – rather than establishing its own program, it will specify desired outcomes, allowing providers and customers to choose best solutions for their products and environments. One size may not fit all, and multiple solutions might be offered by label providers.
On August 31, 2021, NIST released a white paper with draft criteria for a labeling program on cybersecurity capabilities of Internet of Things (IoT) devices. NIST sought comments on the draft criteria, which suggested a set of potential baseline security criteria for IoT devices. Comments on the draft white paper were due no later than October 18, 2021. Those comments are available here.
On December 2, 2021, taking public feedback into account, NIST released a further discussion paper: Consumer Cybersecurity Labeling for IoT Products: Discussion Draft on the Path Forward. This paper will be discussed at the upcoming workshop Cybersecurity Labeling for Consumer IoT and Software: Executive Order Update and Discussion - December 9, 2021.
Consumer Cybersecurity Labeling for IoT Products: Discussion Draft on the Path Forward
For questions, contact:
Information technology, Cybersecurity, and Internet of Things (IoT)
Consumer Software Criteria
As part of its assignment under the Presidential Executive Order on Improving the Nation’s Cybersecurity (14028) issued on May 12, 2021, NIST has released a white paper with draft criteria for consumer software cybersecurity labeling. This is one part of a multi-faceted initiative under the executive order related to cybersecurity labeling for consumers. NIST is seeking comments on the draft criteria, which suggests a set of potential baseline security criteria for consumer software.
Comments on the draft white paper are due no later than December 16, 2021. Under the Executive Order, NIST is to publish details about the consumer software labeling effort by February 6, 2022.
Comments should be submitted to:
NIST will identify key elements of labeling programs in terms of minimum requirements and desirable attributes – rather than establishing its own programs; it will specify desired outcomes, allowing providers and customers to choose best solutions for their devices and environments. One size may not fit all, and multiple solutions might be offered by label providers.
November 1, 2021 - Draft white paper with draft criteria for a labeling program on consumer software
Information technology, Cybersecurity, and Internet of Things (IoT)
Cybersecurity Labeling for Consumers: Internet of Things (IoT) Devices and Software - News & Updates
- Consumer Cybersecurity Labeling for IoT Products: Discussion Draft on the Path Forward (December 2, 2021)
- REGISTER NOW | Cybersecurity Labeling for Consumer IoT and Software: Executive Order Update and Discussion - To be held December 9, 2021 (November 23, 2021)
- NIST Seeks Comments on Draft Consumer Software Criteria for Labeling (November 1, 2021)
- NIST Seeks Comments on Draft IoT Criteria for Consumer Labeling Efforts (August 31, 2021)
- Workshop and Call for Papers on Cybersecurity Labeling Programs for Consumers: Internet of Things (IoT) Devices and Software (July 8, 2021)
Information technology, Cybersecurity, and Internet of Things (IoT)

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics