IoT security regulations businesses must follow are no longer optional checkboxes—they shape procurement, product design, vendor contracts, and incident response across nearly every industry that runs connected devices. Skip them and you risk blocked sales, federal contract losses, state enforcement actions, or supply-chain cutoffs.
Here’s the quick reality check:
- Federal rules already lock down IoT used by government agencies and critical infrastructure.
- California’s SB-327 sets a practical floor for almost every connected device sold in the country’s biggest market.
- The FCC’s U.S. Cyber Trust Mark is turning voluntary labels into de-facto market requirements.
- Global rules (especially the EU Cyber Resilience Act) hit U.S. manufacturers the moment they sell abroad.
If you need the bigger picture on securing connected devices end-to-end, start with the full IoT security for connected devices 2026 guide. Everything below focuses strictly on the regulations themselves.
Core Federal IoT Security Regulations Businesses Must Follow
The Internet of Things Cybersecurity Improvement Act of 2020 still anchors federal policy. It requires NIST to publish and update standards for any IoT device federal agencies buy or connect to their systems. Agencies cannot procure devices that fail those standards.
NIST has kept the pressure on. In 2026 it released the initial public draft of SP 800-213 Revision 1 (IoT Product Cybersecurity Guidelines) and opened a call for comments on the companion SP 800-213A requirement catalog. Manufacturers and integrators selling to the government now face clearer expectations around identity, secure updates, vulnerability handling, and configuration management.
CISA’s Cybersecurity Performance Goals 2.0, released December 2025, pulled IT, IoT, and OT into one set of six functions: Govern, Identify, Protect, Detect, Respond, Recover. Critical-infrastructure operators treat these as the new baseline even when they are not strictly mandatory.
The FCC’s Covered List keeps expanding. In 2026 it added certain foreign-produced advanced robotic devices and power inverters. Devices on the list cannot receive new equipment authorizations, which effectively blocks importation and marketing of new models. Existing authorized gear can usually stay in service, but the direction is clear: national-security risk now sits inside ordinary procurement decisions.
U.S. Cyber Trust Mark and Labeling Pressure
IoT security regulations businesses must follow The FCC’s voluntary cybersecurity labeling program for wireless consumer IoT products—the U.S. Cyber Trust Mark—gained a new Lead Administrator (ioXt Alliance) in April 2026. The program is still ramping, yet federal procurement rules already point toward requiring the mark for many consumer-grade devices sold to government by early 2027. Retailers and enterprise buyers are following the same signal. In practice, “voluntary” is becoming the price of shelf space and contracts.
State-Level Rules That Reach Almost Everyone: California SB-327
California’s Security of Connected Devices law (SB-327) took effect in 2020 and still sets the practical standard for the U.S. market. Any connected device sold or offered for sale in California must ship with “reasonable” security features appropriate to its function and the data it handles. The statute specifically bans shared default passwords; each unit needs a unique preprogrammed password or a forced user-set credential on first use.
Enforcement sits with the Attorney General and local prosecutors—no private right of action. That has not stopped the floor from rising. In 2026 the accepted meaning of “reasonable” now routinely includes unique device identity, protected credential storage, a working vulnerability disclosure channel, and basic update practices. Devices that collect personal data also collide with CCPA rules that tightened opt-out notices for connected products.
If your product reaches California consumers (and almost every national product does), SB-327 is the regulation you design for first.
Sector-Specific and Emerging Requirements
Healthcare devices face FDA premarket and post-market cybersecurity guidance that already demands software bills of materials. HIPAA-covered entities must protect ePHI that travels through or sits on those devices.
Water and wastewater systems above 3,300 population remain under America’s Water Infrastructure Act risk-and-resilience assessment and emergency-response-plan obligations. Deadlines rolled through 2026; enforcement continues.
Manufacturers selling into the European Union now confront the Cyber Resilience Act. Vulnerability and incident reporting obligations began September 11, 2026. Full security-by-design and support-period rules land in December 2027. Many U.S. companies are simply designing once to the stricter EU bar rather than maintaining two product lines.

Step-by-Step Action Plan for Beginners
- Inventory every connected device and the data it touches. Map which ones sit on federal networks, critical infrastructure, California sales channels, or EU markets.
- Check each device against the current NIST SP 800-213 family and SB-327 password rules. Flag anything still using shared defaults or lacking unique identity.
- Review vendor contracts for update commitments, vulnerability disclosure support, and end-of-support dates. Push for Cyber Trust Mark certification where it applies.
- Stand up or update a coordinated vulnerability disclosure process. Document how you will meet the 24-hour early-warning clock if you sell into the EU.
- Align internal policies with CISA CPG 2.0 functions even if you are not critical infrastructure. The language is now the common reference for auditors and insurers.
- Schedule a quarterly review of the FCC Covered List and NIST updates. Rules move faster than most procurement cycles.
In my experience, the companies that treat this as a one-time checklist fall behind within six months. Build the review into your normal risk process.
Common Mistakes & How to Fix Them
IoT security regulations businesses must follow Treating SB-327 as “just unique passwords.” Reasonable security now expects more. Fix: add unique device identity, secure storage, and a public disclosure channel.
Ignoring the Cyber Trust Mark because it is still labeled voluntary. Retail and federal buyers already treat it as table stakes. Fix: start the certification conversation with your primary product lines now.
Assuming EU CRA only hits European subsidiaries. Any product placed on the EU market triggers the rules. Fix: map your distribution channels and decide whether global design is cheaper than dual compliance.
Letting end-of-support devices linger on the network. CISA has already issued binding directives to federal agencies on unsupported edge devices; the same logic is spreading. Fix: inventory support dates and budget for replacement or isolation.
Relying solely on the manufacturer’s word. Ask for evidence—SBOMs, test reports, update histories. What usually happens is the first breach exposes the gap.
Quick Reference: Key IoT Security Regulations Businesses Must Follow in 2026
| Regulation / Framework | Who It Hits | Core Requirement | Status as of 2026 |
|---|---|---|---|
| IoT Cybersecurity Improvement Act + NIST SP 800-213 | Federal agencies & their vendors | Minimum cybersecurity capabilities for procured IoT | Active; Rev. 1 draft circulating |
| California SB-327 | Any connected device sold in CA | Reasonable security features; unique passwords | Enforceable; interpretation tightening |
| U.S. Cyber Trust Mark (FCC) | Wireless consumer IoT; federal procurement pressure | Labeled baseline security + QR registry | Program live; Lead Admin appointed |
| CISA CPG 2.0 | Critical infrastructure (voluntary but influential) | Unified IT/IoT/OT functions | Released Dec 2025 |
| EU Cyber Resilience Act | Products with digital elements sold in EU | Security-by-design; 24-hr vulnerability reporting | Reporting started Sept 11, 2026 |
For deeper context on the actual threats these rules try to stop, see the companion piece on the biggest IoT security risks for businesses.
Key Takeaways
- Federal procurement and critical infrastructure already operate under NIST and CISA frameworks that treat IoT as a first-class risk.
- California SB-327 remains the de-facto national floor for consumer and commercial connected devices.
- The U.S. Cyber Trust Mark is shifting from optional to expected by buyers and government.
- EU CRA reporting obligations already apply to any U.S. company placing products on the European market.
- Inventory, unique credentials, update commitments, and vulnerability processes form the practical minimum.
- Sector rules (FDA, water systems, etc.) stack on top of the horizontal requirements.
- Review cycles matter more than one-time compliance projects.
Stay ahead of the next NIST or FCC update and you keep both market access and operational resilience. The next practical step is a full device inventory mapped against the table above—then close the highest-risk gaps first.
FAQs
What happens if my business ignores IoT security regulations businesses must follow?
You can lose federal contracts, face California enforcement, get blocked from major retailers, or be shut out of the EU market. Insurance and liability exposure also rise.
Do IoT security regulations businesses must follow apply only to manufacturers?
No. Operators, integrators, and any organization that deploys connected devices into regulated environments share the compliance burden through procurement and network-security rules.
How often should we re-check IoT security regulations businesses must follow?
At least quarterly against NIST, FCC Covered List, and CISA updates, plus immediately when entering a new market or sector.




