UL Solutions has formally withdrawn as the lead administrator of the Federal Communications Commission's Cyber Trust Mark program, a flagship initiative designed to help consumers identify secure Internet of Things (IoT) devices. The departure, which followed internal security reviews and concerns about foreign influence in program management, has raised uncertainty about the future of the Biden-era voluntary cybersecurity labeling program for consumer electronics. UL Solutions stated it had completed foundational work for the initiative and expressed continued support for the FCC's goals of advancing IoT security and consumer safety.
The withdrawal leaves the FCC without a lead administrator for the Cyber Trust Mark program, and it is unclear who will take over the role. The program, launched to prioritize cybersecurity in consumer IoT products, now faces questions about its continuity and effectiveness amid the leadership change and ongoing scrutiny regarding potential ties to foreign entities. The situation underscores the challenges in establishing trusted oversight for national cybersecurity initiatives targeting the rapidly expanding IoT market.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
The FCC chose California-based nonprofit ioXt Alliance as the new lead administrator for its Cyber Trust Mark IoT cybersecurity labeling program after UL Solutions withdrew. ioXt said it would work with the FCC, UL Solutions, and industry stakeholders to advance the program.
UL Solutions formally withdrew from its role as chief administrator of the FCC's Cyber Trust Mark program, leaving the initiative without a lead entity. The FCC had not announced a replacement, creating uncertainty about the program's future.
A national security review was initiated in summer 2025 over concerns about possible foreign influence in the management of the Cyber Trust Mark program. The review raised questions about UL Solutions' role and the program's administration.
The Biden administration launched the FCC's voluntary Cyber Trust Mark program to label consumer IoT devices that meet cybersecurity standards. The initiative was intended to help consumers identify more secure smart home and connected products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.