IoT cyber security regulations in the USA

What the IoT cyber security regulations of the USA require, whether they are in force and mandatory, and whether ETSI EN 303 645 is enough to comply.

Last updated

3 regulations recorded for the USA in the panorama of IoT cyber security regulations, which compares every country that regulates the cyber security of connected products.

Cybersecurity Improvement Act

H.R. 1668 - IoT Cybersecurity Improvement Act of 2020

Congress · 12 April 2020 · last reviewed ETSI EN 303 645 can be used

QuestionAnswer
Is the regulation in force? Yes
Scope All IoT devices and systems
Who must follow the regulation? Federal agencies owning or controlling IoT devices and systems
Mandatory or Voluntary? Mandatory
Is there a label or a certification? No
Does the regulation mandate baseline security requirements? Yes
Are there additional requirements to the baseline security? Yes
Does the regulation contains assurance levels? No
Is compliance with ETSI EN 303 645 a requirement? No
Can ETSI EN 303 645 be used to comply with the regulation? Partially
Are other standards or guidance referenced? (cf. regulation) No

Read the regulation

California: SB-327 (California)

Senate Bill No. 327 - Information privacy: connected devices

California State Senate · 28 September 2018 · last reviewed ETSI EN 303 645 can be used

QuestionAnswer
Is the regulation in force? Yes
Scope Consumer IoT
Who must follow the regulation? IoT manufacturers
Mandatory or Voluntary? Mandatory
Is there a label or a certification? No
Does the regulation mandate baseline security requirements? Yes
Are there additional requirements to the baseline security? No
Does the regulation contains assurance levels? No
Is compliance with ETSI EN 303 645 a requirement? No
Can ETSI EN 303 645 be used to comply with the regulation? Yes
Are other standards or guidance referenced? (cf. regulation) No

Read the regulation

Oregon: HB 2395 (Oregon)

House Bill 2395

Oregon House of Representatives · 16 April 2019 · last reviewed ETSI EN 303 645 can be used

QuestionAnswer
Is the regulation in force? Yes
Scope Consumer IoT
Who must follow the regulation? IoT manufacturers
Mandatory or Voluntary? Mandatory
Is there a label or a certification? No
Does the regulation mandate baseline security requirements? Yes
Are there additional requirements to the baseline security? No
Does the regulation contains assurance levels? No
Is compliance with ETSI EN 303 645 a requirement? No
Can ETSI EN 303 645 be used to comply with the regulation? Yes
Are other standards or guidance referenced? (cf. regulation) No

Read the regulation

Every other country

Licence: Free to use for non-commercial purposes. Any use must credit cetome and link to cetome.com/panorama. The data is also open on GitHub.

Next step

Put this research to work

Our research shows where the rules stand. To build secure-by-default products, we help you define a product security strategy and put it into practice across your organisation.