Preparing for the CRA?Here’s what we’re building |
Cybersecurity requirements are expanding across global markets, and the companies that design, build, and distribute connected products are feeling it. New regulations are raising the bar on everything from product-level security to supply chain transparency to how vulnerabilities get reported and managed. The scope and complexity are real and growing.
The IoT M2M Council, the largest global trade association dedicated to the IoT and M2M sector, is launching a new initiative to help manufacturers, suppliers, distributors, and ecosystem partners work through this together. Our role has always been to bring the industry together around the challenges that matter most. Right now, cybersecurity compliance is one of those challenges.
We publish a monthly IoT Security & Public Policy newsletter covering these developments. If you want to stay current as this evolves, subscribe here.
Over the coming months, IMC will introduce initiatives to help manufacturers and suppliers:
- Streamline IoT device cybersecurity compliance across global jurisdictions
- Reduce the internal burden of evolving cybersecurity regulations
- Improve management of compliance documentation and supply chain visibility
- Track and maintain product-level cybersecurity compliance as requirements evolve
- Support Software Bill of Materials (SBOM) management
- Support vulnerability monitoring and ongoing compliance workflows
Tools and Resources
- CRA Playbook for Manufacturers — A chapter-by-chapter practical guide to CRA compliance, covering secure-by-design, vulnerability management, SBOM, conformity assessment, technical documentation, and more.
Download the first six chapters today!
Coming Soon:
- CRA Readiness Calculator — A self-assessment tool to help manufacturers of products with digital elements (PDE) gauge their readiness for the EU Cyber Resilience Act.
- Industry Index — A reference tool for tracking cybersecurity regulations, frameworks, across global markets.
Initial Focus Areas
Listed are the regulations and frameworks we are tracking most closely on behalf of our members, organized by region:
Europe
- EU Cyber Resilience Act (CRA) New EU-wide requirements for manufacturers of products with digital elements. Phased enforcement begins September 2026; full compliance required by December 2027.
- NIS2 Directive Expanded EU cybersecurity obligations and incident reporting requirements for essential and important entities.
- UK PSTI Act Minimum security standards for consumer connectable products sold in the UK. In effect since April 2024.
North America
- FCC Cybersecurity Labeling (U.S. Cyber Trust Mark) Voluntary labeling program for IoT products meeting FCC-endorsed security criteria.
Asia-Pacific
- JC-STAR (Japan) Japan’s cybersecurity certification framework for connected devices entering the Japanese market.
- Singapore Cybersecurity Labelling Scheme (CLS) Tiered cybersecurity rating for consumer IoT products, mandatory for certain product categories sold in Singapore.
- South Korea Connected Device Certification Cybersecurity certification requirements for connected devices, particularly those used in critical infrastructure.
Industry Leadership
IMC Cybersecurity Committee —The Committee brings together cybersecurity experts, IoT manufacturers and suppliers, compliance professionals, open-source ecosystem contributors, and product security leaders to guide IMC’s cybersecurity initiatives.
Learn more about the IMC Cybersecurity Committee
Industry Collaboration
IMC-GCF Joint Task Force on IoT Security
In collaboration with the Global Certification Forum, IMC is leading a Joint Task Force focused on evaluating a more holistic approach to IoT security certification across devices, networks, and cloud platforms.
Learn More About the IMC-GCF Joint Task Force
The Industry-Wide Approach
These are not challenges any single company should have to solve alone. That is exactly why trade associations exist. IMC is bringing together the people who understand this space to help the industry move forward together, with shared frameworks, practical tools, and a collaborative approach to what is genuinely a shared problem.
Stay Informed
IoT Security & Public Policy Monthly Newsletter
IMC publishes a monthly newsletter covering global cybersecurity regulation, compliance developments, IoT security policy, and emerging industry initiatives impacting the connected device ecosystem. Coverage is organized into four content categories:
- Regulation — CRA, NIS2, UK PSTI, ENISA guidance, CE marking, FCC, JC-STAR, Singapore CLS, South Korea, and other regulatory activity affecting IoT manufacturers and suppliers.
- Security — SBOM management, vulnerability handling, coordinated disclosure, product security, and emerging threats to connected devices.
- Standards & Certification — Conformity assessment, EU and international standards, and certification frameworks relevant to manufacturers placing products on global markets.
- Industry & Policy — Digital sovereignty initiatives, public procurement requirements for connected technologies, and cross-border policy developments affecting the IoT ecosystem.
Read recent coverage at the IoT Security & Public Policy content channel.
Other IMC Resources:
- Join the IMC Adopters and become a member today!
- Find out more about becoming an IMC Sustaining Member!
The IoT M2M Council is the largest global trade association dedicated to advancing the IoT and M2M industry and supporting a trusted, connected future.










