WASHINGTON — The Biden administration and major consumer technology players on Tuesday introduced an effort to put a nationwide cybersecurity certification and labeling program in place to help consumers choose smart devices that are less vulnerable to hacking.
Officials likened the new U.S. Cyber Trust Mark initiative — to be overseen by the Federal Communications Commission, with industry participation voluntary — to the Energy Star program, which rates appliances’ energy efficiency.
“It will allow Americans to confidently identify which internet- and Bluetooth-connected devices are cybersecure,” deputy national security adviser Anne Neuberger told reporters in a pre-announcement briefing.
Amazon, Best Buy, Google, LG Electronics USA, Logitech and Samsung are among industry participants.
Devices including baby monitors, home security cameras, fitness trackers, TVs, refrigerators and smart climate control systems that meet the U.S. government’s cybersecurity requirements will bear the “Cyber Trust” label, a shield logo, as early as next year, officials said.
FCC Chair Jessica Rosenworcel said the mark will give consumers “peace of mind” and benefit manufacturers, whose products would need to adhere to criteria set by the National Institute of Standards and Technology to qualify.
The FCC was opening a rule-making process to set the standards and seek public comment. Besides carrying logos, participating devices would have QR [quick-response] code that could be scanned for updated security information.
In a statement, the Consumer Technology Association said consumers could expect to see certification-ready products at the industry’s annual January show, CES 2024, once the FCC adopts final rules. A senior Biden administration official said it was expected that products that qualify for the logo would undergo an annual re-certification.
The director of technology policy at Consumer Reports, Justin Brookman, welcomed the White House proposal but cautioned in a statement that “a long road remains” to its effective adoption.
“Our hope is that this label will ignite a healthy sense of competition in the marketplace, compelling manufacturers to safeguard both the security and privacy of consumers who use connected devices and to commit to supporting those devices for the lifetime of those products.”
The Cyber Trust initiative was first announced in October following a meeting between White House and tech industry representatives.
The proliferation of so-called smart devices has coincided with growing cybercrime in which one insecure device can often give a cyberintruder a dangerous foothold on a home network.
An April report from the cybersecurity firm Bitdefender and networking equipment company NetGear, based on their monitoring of smart homes, found that the most vulnerable devices in 2022 were, far and away, smart TVs, followed by smart plugs, routers and digital video recorders.
Providers of numerous smart home devices often don’t update and patch software fast enough to thwart newly emerging malware threats. The Cyber Mark standards are expected to make clear which devices patch vulnerable software in a timely fashion and secure their communications to preserve privacy, officials said. Also important will be informing consumers which devices are equipped to detect intrusions.