prBAS ISO/IEC 27404:2026
Cybersecurity — IoT security and privacy — Cybersecurity labelling framework for consumer IoT
General information
Status:Project
Number of pages:63
Adoption method:Korice
Language:engleski
Edition:1.
Realization date:19.11.2025
Forseen date for next stage code:26.11.2025
Technical committee:BAS/TC 1, Information technology
ICS:
35.030, IT Security
35.240.95, Internet applications
35.240.95, Internet applications
Abstract
This document defines a cybersecurity labelling framework for the development and implementation of cybersecurity labelling programmes for consumer Internet of things (IoT) products. It provides requirements and guidance on the following topics:
— risks and threats associated with consumer IoT products;
— stakeholders, roles and responsibilities;
— relevant standards and guidance documents;
— conformity assessment;
— labelling issuance and maintenance;
— mutual recognition.
This document is limited to consumer IoT products, such as:
— IoT gateways, base stations and hubs to which multiple devices connect; smart cameras, televisions, and speakers;
— wearable devices;
— connected smoke detectors, door locks and window sensors;
— connected home automation and alarm systems;
— connected appliances, such as washing machines and fridges;
— smart home assistants; and
— connected children’s toys and baby monitors.
Products that are not intended for consumer use are excluded from this document. Examples of excluded devices are those that are primarily intended for manufacturing, healthcare and other industrial purposes.
This document is applicable to consumers, developers, issuing bodies of cybersecurity labels and conformity assessment bodies.
Lifecycle
...
Original document and degree of correspondence
ISO/IEC 27404:2025, identical
Work material
Only members of the technical committee have access to work material. If you are a members of this technical committee you need to login to view the documents. Login