by | Sep 2, 2026 | Blog | 0 comments

During the September 2nd meeting of the AIM Visibility Technologies Industry Group, members heard from Grace Burkard, Director of Operations at the ioXt Alliance, for an in-depth look at the U.S. Cyber Trust Mark Program and what the developing cybersecurity labeling program could mean for manufacturers, retailers, technology providers, and consumers.

The Federal Communications Commission selected ioXt Alliance as the Lead Administrator for the U.S. Cyber Trust Mark program in April 2026. The voluntary program is intended to give consumers a recognizable way to identify qualifying connected products that meet baseline cybersecurity requirements.

 

What Is the U.S. Cyber Trust Mark?

Grace explained that the U.S. Cyber Trust Mark is being developed as a voluntary cybersecurity labeling program for consumer Internet of Things products.

The program is built around cybersecurity guidance from the National Institute of Standards and Technology, including NIST IR 8425, which establishes baseline cybersecurity capabilities for consumer IoT products. Rather than serving as a “gold standard” or indicating that a product is immune from cybersecurity threats, the Trust Mark is designed to establish a recognizable baseline that manufacturers can demonstrate through independent evaluation.

Products participating in the program will undergo third-party testing and evaluation before being authorized to display the U.S. Cyber Trust Mark.

Grace noted that the initial scope is focused specifically on consumer-facing connected products. Enterprise, industrial, automotive, healthcare, and individual components such as chips and modules are currently outside the program’s primary scope.

 

Helping Consumers Understand Product Security

One of the primary objectives of the program is transparency.

Consumers purchasing connected products often have little practical information available to help them understand how a manufacturer approaches cybersecurity, software updates, product support, or secure configuration.

The U.S. Cyber Trust Mark is intended to provide a recognizable signal that a product has met defined baseline requirements while connecting the consumer with additional product-specific security information.

That additional information is where the program becomes particularly relevant to AIM.

 

The Role of the QR Code

Grace spent part of the discussion addressing the QR Code associated with the U.S. Cyber Trust Mark.

The cybersecurity label is expected to include the Trust Mark along with a scannable QR Code that connects users to more detailed cybersecurity information about the product. The labeling framework envisions multiple layers of information, with consumer-friendly information at one level and more detailed technical information available at another. This information can include items such as product security and certification information, software update practices, secure configuration guidance, the manufacturer’s support period, and other information that may change during the life of the product. Unlike a static printed statement, the QR Code provides a pathway to information that can remain current as cybersecurity conditions, software versions, and product support evolve.

 

AIM Members: Review the Technical Recommendations

Following the meeting, Grace provided AIM with a link to technical recommendations available through the FCC’s Electronic Comment Filing System.

The link takes members to a filing associated with the FCC’s Cybersecurity Labeling for Internet of Things proceeding, Docket No. 23-239. The filing contains technical recommendations developed for the U.S. Cyber Trust Mark program and provides considerably more detail than the general program overview.

Of particular interest to AIM members are the recommendations involving the label, QR code, linked product information, technical requirements, cybersecurity criteria, and implementation framework.

The labeling approach also distinguishes between information intended to be easily understood by consumers and more detailed technical information. The related ANSI/CTA-2120 labeling framework describes an on-package marking and QR code, a consumer-focused information layer, and a more technically focused information layer.  AIM members are encouraged to begin reviewing these materials now.

 

AIM TSC and Visibility Groups to Continue the Discussion

The AIM Technical Symbology Committee (TSC) will review the QR Code and data carrier aspects of the recommendations, including potential questions surrounding implementation, interoperability, symbol quality, and the relationship with other QR-based applications. The Visibility Technologies Industry Group will also continue reviewing the broader U.S. Cyber Trust Mark program and its potential impact on organizations throughout the connected-product ecosystem. Both groups plan to continue the discussion during their October meetings, and AIM members are encouraged to review the FCC materials in advance and identify questions, concerns, or recommendations that AIM should consider.  As standards, regulations, identification technologies, cybersecurity requirements, and consumer-facing product information increasingly intersect, engagement from AIM’s technical community will be critical.

 

Watch Grace Burkard’s Presentation

Members who were unable to attend the September 2nd Visibility Technologies Industry Group meeting, or who would like to revisit the discussion, can watch Grace’s complete presentation here.

AIM thanks Grace Burkard and the ioXt Alliance for joining the Visibility Technologies Industry Group and for providing members with an early opportunity to better understand the U.S. Cyber Trust Mark and the technical considerations surrounding its implementation.

AIM members interested in this issue are encouraged to review the recommendations before the October TSC and Visibility Technologies Industry Group meetings and come prepared to share feedback