Three shifts now mark smart-home security. First, the FCC's US Cyber Trust Mark — the voluntary labeling program that began accepting certified devices in January 2025 — puts a shield logo on products meeting documented baseline security standards. Second, Matter's continued security requirements — device attestation and secure onboarding are mandatory in the specification every certified device passes. Third, Europe's product-security laws — the UK's PSTI regime (in force since April 2024) banning default passwords and Europe's Cyber Resilience Act (with main obligations phasing toward 2027) — set firmware-update duties global manufacturers build to worldwide. The shopper-facing result: labels and policies that finally let you compare security like battery life.
What is the Cyber Trust Mark?
The FCC's program, documented on its consumer pages, certifies connected devices against NIST-aligned baseline criteria: no universal default passwords, secure update commitments, data protection, and incident reporting. The shield logo on packaging (with a QR code to each product's documented specifics) rolled out on first certified products in 2025. Participation is voluntary — absence doesn't prove insecurity — but presence documents a floor, which is more than the category offered before.
What did the UK and EU rules change?
- UK PSTI (April 2024): bans default passwords, requires a public vulnerability policy and support-period disclosure — manufacturers must state how long the gadget gets security updates, in writing, at sale.
- EU Cyber Resilience Act: adopted in 2024 with obligations phasing in through 2027, requiring security-by-design, update support across the product's expected life, and CE-marking integration for connected products.
Because makers design product lines globally, these duties reach US shelves as de facto standards: stated support periods and no-default-passwords increasingly appear in documentation everywhere.
What should you check when buying a smart device in 2026?
- The Cyber Trust Mark — a documented floor where present.
- A stated security-update commitment — years, in writing. The support-period disclosure the UK mandates is the single most useful line in any spec sheet.
- Matter certification where relevant — it carries documented device-attestation requirements.
- The maker's track record — how it handled past vulnerabilities is public record for the major brands.
What's the overlooked detail?
Support length beats feature lists. A camera with gorgeous resolution and 18 months of firmware support becomes a liability on month 19; a plainer device with five documented years stays defensible. The industry's own answer — the labels above — exists precisely because nobody could see this number before; in 2026, you can.
FAQ
For more context, read USB-C Everything: The EU Charging Rule Is Now Fully in Force.
For more context, read prime day 2026 deals strategy.
For more context, read Samsung Galaxy S26: What Changed and What It Costs.

