FCC Recognizes Two Accreditation Bodies for the U.S. Cyber Trust Mark Program
What Is the U.S. Cyber Trust Mark?
The U.S. Cyber Trust Mark is a voluntary cybersecurity labeling program run by the Federal Communications Commission (FCC). It covers consumer wireless Internet of Things (IoT) products, such as smart home devices. The goal is simple. It helps shoppers find connected products that meet clear security standards. Products that qualify will carry a label with a QR code. Shoppers can scan the code to read easy security details, including how long the maker plans to support the product with updates.
FCC Recognizes Two Accreditation Bodies
On 28 September 2026, the FCC’s Public Safety and Homeland Security Bureau released Public Notice DA 26-1029. In this notice, the Bureau approved two accreditation bodies for the U.S. Cyber Trust Mark program. They are the American Association for Laboratory Accreditation (A2LA) and the ANSI National Accreditation Board (ANAB). Both groups can now accredit the organizations that will run and support the program. This approval follows requests that the two groups sent to the FCC in 2025.
How the Program Fits Together
The program works like a chain, and each link has a job. The FCC sets the rules. Accreditation bodies like A2LA and ANAB check that CLAs and CyberLABs are competent. CyberLABs test the products. CLAs review the test results and approve the label. Manufacturers then place the U.S. Cyber Trust Mark on approved products. Accreditation is what keeps this chain honest, because it shows that every group involved meets the same international standards.
Who Can Be Accredited?
Cybersecurity Label Administrators (CLAs)
CLAs review manufacturer applications and decide if a product can use the label. A2LA and ANAB can accredit CLAs to ISO/IEC 17065, an international standard for bodies that certify products, processes, and services.
Cybersecurity Testing Laboratories (CyberLABs)
CyberLABs test products against the program’s security rules. A2LA and ANAB can accredit these labs to ISO/IEC 17025, a standard that covers the competence of testing and calibration laboratories.
Why These Accreditation Bodies Qualified
The Bureau found that both groups showed the right credentials and skills. Each one:
- holds ISO/IEC 17011 accreditation and passed a peer review;
- has the qualifications to accredit CLAs and CyberLABs;
- uses assessors with enough technical experience; and
- has set up procedures and policies for the program.
The recognition is not permanent. Both groups must keep meeting these criteria. They have also promised to follow new or changed assessment rules as the FCC program develops.
What This Means for the U.S. Cyber Trust Mark Rollout
This is an important step toward launch. Manufacturers cannot apply for the label until CLAs and CyberLABs are accredited and recognized. The Bureau recognizes CLAs, and the Lead Administrator recognizes CyberLABs. ioXt Alliance has been the Lead Administrator since 13 April 2026. The FCC also opened a filing window for CLA applications on 11 August 2026. The FCC has said it will announce when the program is ready to accept product applications, so companies should watch for that update.
Why Accreditation Matters for Buyers
For shoppers, a security label only works if people trust it. Accreditation helps build that trust. When a product carries the mark, buyers can feel more sure that independent, qualified groups checked it. Without strong accreditation, a label could become just another logo. That is why this recognition matters, even though it happens behind the scenes. It supports the program’s main promise: clear and reliable security information for everyday consumers.
Who Should Pay Attention?
The program is voluntary, but it may shape how buyers judge smart devices in the United States. Manufacturers of consumer wireless IoT products should learn the process early. Early preparation can save time once applications open, because testing and review take real time and effort for many companies. Testing labs and certification bodies also have a clear path now. They can plan their accreditation with A2LA or ANAB and prepare to serve as CLAs or CyberLABs. For questions, the FCC has set up a contact email: CyberTrustMark@fcc.gov.
Key Takeaways
- Check if your product is in scope: The program covers consumer wireless IoT products. Confirm this first before you spend time or budget.
- Run a gap review now: Compare your product’s security features against the FCC’s program requirements today, so you can fix weak points before testing starts.
- Prepare your update and support plan: The label shows how long a product will get security updates. Decide on a clear support period early and be ready to document it.
- Talk to labs early: Once CyberLABs are accredited, testing slots may fill up. Build relationships with likely labs and ask about timelines and costs.
- Watch for FCC announcements: Product applications are not open yet. Assign someone to track the FCC’s U.S. Cyber Trust Mark page so you do not miss the launch.
- Labs and certifiers, start now: If you plan to become a CLA or CyberLAB, contact A2LA or ANAB to learn their accreditation steps and timelines.
- Weigh the business value: The label is voluntary. Decide whether it fits your brand and your retail plans in the U.S. market.
Source of Article
Federal Communications Commission. “Public Safety and Homeland Security Bureau Recognizes Accreditation Bodies for the U.S. Cyber Trust Mark Program.” Public Notice DA 26-1029, PS Docket Nos. 24-714 and 23-239, 28 September 2026.
https://www.fcc.gov/document/fcc-recognizes-accreditation-bodies-us-cyber-trust-mark-program
Not Sure Where to Start?
Request a free initial consultation or product assessment.
Our experts are here to help.
