The U.S. Cyber Trust Mark Program, an Energy Star-style certification designed to enhance smart home security, is facing an uncertain future just months after its launch. UL Solutions, the program’s lead administrator, has announced its withdrawal, following an FCC investigation into ties with China. This development leaves the initiative in limbo, with no clear path forward for certifying smart home devices against cybersecurity threats.
What is the Cyber Trust Mark Program?
Announced in 2023 under the Biden administration, the Cyber Trust Mark Program aimed to establish a voluntary cybersecurity certification for Internet of Things (IoT) devices, including smart home gadgets like cameras, thermostats, and door locks. Certified products would display a shield icon on their packaging, similar to the Energy Star label, signaling compliance with baseline security standards. The program officially launched at CES 2025, but no products have yet received the certification mark.
UL Solutions Steps Down
UL Solutions, a global safety science company, served as the program’s lead administrator, responsible for testing and certifying devices. However, the company announced it is stepping down from this role, citing the FCC’s ongoing investigation into its operations. The FCC launched the probe in 2025, examining UL Solutions’ ties to China and potential conflicts of interest. This investigation has cast doubt on the program’s credibility and operational viability.
FCC’s Broader Crackdown on Cybersecurity
The Cyber Trust Mark Program is not the only casualty of the FCC’s recent actions. In 2025, the Commission rolled back cybersecurity regulations for telecom companies that were implemented after the 2024 Salt Storm hack. Additionally, FCC Chair Brendan Carr has intensified scrutiny of testing labs, decertifying so-called “corrupt labs” based in China. These moves signal a broader shift in U.S. cybersecurity policy, prioritizing geopolitical concerns over industry-wide certification schemes.
Impact on Smart Home Security
The potential collapse of the Cyber Trust Mark Program leaves consumers and manufacturers without a unified cybersecurity standard for smart home devices. Without certification, consumers may struggle to identify secure products, increasing risks of data breaches and device hijacking. Manufacturers lose a clear benchmark for compliance, potentially slowing innovation in secure IoT design. The program’s failure also undermines efforts to create a global cybersecurity framework, as the U.S. had hoped to set an example for other nations.
What’s Next for Smart Home Security?
With the Cyber Trust Mark Program in limbo, the future of smart home security certification remains uncertain. The FCC has not responded to requests for comment on the program’s fate. Industry experts suggest that alternative certification bodies, such as the Internet Security Alliance or the Consumer Technology Association, could step in to fill the void. Meanwhile, manufacturers may rely on existing standards like the IoT Security Foundation’s guidelines or the European Union’s EN 303 645 standard.
For consumers, the immediate impact is limited, as no products have yet carried the Cyber Trust Mark. However, the program’s demise could delay broader adoption of security best practices in the smart home market. As of April 2026, the FCC has not announced any plans to revive the program or launch a replacement. The cybersecurity community continues to monitor the situation, advocating for stronger, bipartisan support for IoT security initiatives.


