Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

NIST on Track to Release Draft Security Criteria for Consumer IoT Products

By Sheila Millar & Anushka R. Stein on September 16, 2021
Email this postTweet this postLike this postShare this post on LinkedIn

On August 31, 2021, the National Institute of Standards and Technology (NIST) released its draft white paper, DRAFT Baseline Security Criteria for Consumer IoT Devices. The draft white paper is in response to Executive Order (EO) 14028, “Improving the Nation’s Cybersecurity,” which requires NIST, in collaboration with other agencies, to educate the public on Internet-of-Things (IoT) security. The draft white paper proposes baseline security criteria for consumer IoT products as part of a cybersecurity labeling program and builds on NIST’s Secure Software Development Framework (SSDF) and other NIST documents. NIST is not establishing its own labeling program but instead seeks to identify minimum requirements for programs, which it must do by February 6, 2022.

NIST’s summary sets out the timelines and objectives, along with some general principles. Labeling should:

  • Encourage innovation in manufacturers’ IoT security efforts, leaving room for changes in technologies and the security landscape.
  • Be practical and not be burdensome to manufacturers and distributors.
  • Factor in usability as a key consideration.
  • Build on national and international experience.
  • Allow for diversity of approaches and solutions across industries, verticals, and use cases – so long as they are deemed useful and effective for consumers.

The proposed labeling criteria set out in the draft white paper builds off of NISTIR 8259A, IoT Device Cybersecurity Capability Core Baseline and NISTIR 8259B, IoT Non-Technical Supporting Capability Core Baseline. NISTIR 8259B itself is new guidance released last month, and is intended to help manufacturers identify the non-technical capabilities they need to support device and system cybersecurity controls and to communicate with customers and third parties effectively. NISTIR 8259B is one of four documents recently released by NIST to help manufacturers and federal agencies manage cybersecurity, which include IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements (SP 800-213), Creating a Profile Using the IoT Core Baseline and Non-Technical Baseline (NISTIR 8259C), and Profile Using the IoT Core Baseline and Non-Technical Baseline for the Federal Government (NISTIR 8259D).

NIST hosted an informative workshop on the proposed labeling criteria and related issues as previously announced on September 14–15. The workshop featured a variety of stakeholders, including representatives from federal agencies with experience in labeling programs, such as the Environmental Protection Agency (EPA), Federal Trade Commission (FTC) and Consumer Product Safety Commission (CPSC), as well as international experts. The workshop included discussions on how to define a “consumer,” what should be in scope for a labeling program, limits of a labeling program, and achieving global harmonization, among many other topics. Recurring themes included assuring that a cybersecurity label avoids conveying a false sense of security and the need to keep labels simple.

Comments on the draft white paper are due October 17, 2021, and can be submitted to labeling-eo@nist.gov. NIST has already received feedback on important details, which were discussed during the workshop. With the growth of IoT devices, an IoT labeling scheme will likely have significant impact on many industry sectors, so interested stakeholders may wish to consider submitting comments.

Photo of Sheila Millar Sheila Millar

Sheila A. Millar is a partner at Keller and Heckman LLP, where she represents businesses and trade associations on a variety of public policy and regulatory issues, including privacy, data security, cybersecurity and advertising matters, as well as product safety issues. She has…

Sheila A. Millar is a partner at Keller and Heckman LLP, where she represents businesses and trade associations on a variety of public policy and regulatory issues, including privacy, data security, cybersecurity and advertising matters, as well as product safety issues. She has been involved in a variety of audit and compliance projects, including, among other issues, privacy and data security audits, and is experienced in providing crisis management legal support to a variety of national and international companies and associations.

Ms. Millar is a frequent speaker on regulatory and public policy matters, and has authored many articles. Ms. Millar is one of the vice chairs of the International Chamber of Commerce (ICC) Marketing and Advertising Commission, and chair of its Working Group on Sustainability, where she spearheaded the development of the ICC Framework Guides on Environmental Marketing Claims.

Ms. Millar is AV® PreeminentTM Rated by Martindale-Hubbell and for the eigth consecutive year was selected by her peers for inclusion in The Best Lawyers in America® 2018 for her work in practicing Advertising Law. She has also received the distinguished honor of Advertising Law “Lawyer of the Year” 2014 in Washington, DC by Best Lawyers®, and was awarded Advertising and Marketing Lawyer of the Year USA by Finance Monthly for their Finance Monthly Global Awards 2017.

Read more about Sheila MillarEmailSheila's Linkedin Profile
Show more Show less
Photo of Anushka R. Stein Anushka R. Stein
Read more about Anushka R. SteinEmailAnushka R.'s Linkedin Profile
  • Posted in:
    Technology and AI
  • Blog:
    Consumer Protection Connection
  • Organization:
    Keller Heckman
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo