Two dates this year have changed what it takes to get a connected device onto the market. On 30 April, the US Federal Communications Commission voted to propose barring every test lab in mainland China and Hong Kong from certifying electronics for the US market, even though the agency estimates that labs there test about 75 percent of US-bound devices today.
Then on 11 September, Europe’s Cyber Resilience Act started requiring manufacturers to report actively exploited security flaws within 24 hours through a new EU reporting platform. Neither change is about radio physics, yet both land on the same process that decides whether a company can sell a device at all: wireless compliance.
For IoT makers that process used to be the last box ticked before launch. It is fast becoming a decision that shapes design, suppliers and budgets from the start.
What Wireless Compliance Actually Covers
To see why, it helps to separate the layers a connected product has to pass. The first is regulatory radio approval: proof that the device transmits only in its permitted frequencies and power levels, does not interfere with other equipment, and, if worn on the body, stays within limits on radio energy absorbed by tissue. Every major market runs its own version, from the FCC in the US to CE marking in Europe.
The second layer is network certification, where a cellular device must pass industry testing, through PTCRB in North America, and often each operator’s own programme before the operator lets it on the network. The third is ecosystem certification from bodies such as the Bluetooth SIG or the LoRa Alliance, confirming the device works with others carrying the same logo. A fourth layer now sits on top: cybersecurity, which regulators increasingly treat as part of the same approval.
The Module Shortcut And Its Limits
Most IoT makers avoid the heaviest radio testing by building on a pre-certified module, a ready-made radio component that has already passed approval. In the US, that lets a product skip certifying the radio itself, as long as it follows the module’s antenna and layout rules and carries a “Contains FCC ID” label.
The shortcut has limits, though, because the finished product still needs its own emissions testing for its digital electronics, and changing the antenna or layout can undo the module’s approval. Connectivity firm Particle puts that remaining testing at $3,000 to $5,000 and eight to twelve weeks, against $40,000 or more for certifying a transmitter from scratch, and claims 80 percent of first-time cellular designs fail their first attempt.
Network certification follows the same pattern: with a certified module, PTCRB testing often narrows to the SIM, power supply and antenna, roughly halving the timeline, while US operators such as AT&T and Verizon still run their own programmes. As we explained in why Cat 1 bis won, the module market has consolidated around a few large suppliers, which makes their certification coverage a real buying criterion.
In The US, Where You Test Is Becoming Political
The biggest change concerns not what gets tested but where it happens, starting with an FCC rule, effective since September 2025, that lets the agency strip recognition from labs owned or controlled by foreign adversary governments, and it has since withdrawn or denied recognition for more than 20 Chinese labs.
This spring the FCC went much further: in April it proposed to stop recognising labs in countries that do not offer US labs reciprocal treatment, with a two-year phase-out, and on 30 April it voted to propose extending the ban to all labs in China and Hong Kong, regardless of who owns them. “Today, more than 75% of testing occurs in countries that have refused to commit to reciprocal treatment of U.S.-based labs and certification bodies,” FCC chairman Brendan Carr said.
Both measures are proposals rather than final rules, and observers expect existing approvals to stand. If the FCC adopts them, the practical impact falls on cost and speed. Compliance tracker MarkReady estimates testing runs $400 to $1,300 in Chinese labs against $3,000 to $4,000 in the US, and notes that 27 of the affected labs are Chinese branches of Western firms such as SGS, TÜV and UL.
Our read is that the price gap is not the biggest loss, since makers in Shenzhen can fail a test, fix a prototype at the factory and retest the next day. Shipping prototypes abroad turns that loop into weeks, which makes getting the design right before formal testing far more valuable.
The Security Label Changed Hands
The same concerns have reached the FCC’s voluntary security label for consumer IoT, the US Cyber Trust Mark. UL Solutions withdrew as lead administrator in January amid an FCC probe into its China ties, and in April the agency named the ioXt Alliance to replace it, so the programme is effectively restarting.
In Europe, Radio Approval Now Includes Security
Europe has taken a different route to the same destination by writing security into radio approval itself. Since 1 August 2025, internet-connected radio equipment sold in the EU has had to meet cybersecurity requirements under the Radio Equipment Directive, covering network protection, personal data and fraud prevention.
Manufacturers can show compliance using a new family of standards, EN 18031, with separate parts for connected devices, products handling personal data such as wearables and baby monitors, and devices that move money. Where a product relies on options the standards restrict, the maker must bring in a notified body, an independent assessor, rather than relying on its own declaration.
The Cyber Resilience Act builds on that base, and its reporting duties took effect on 11 September, with a 72-hour follow-up notice and a final report within 14 days of a fix, and its full product requirements apply from December 2027. We set out the steps for device makers in what the CRA means for IoT.
The UK And Other Markets Add Their Own Rules
Outside the EU the picture fragments further, starting with the UK’s product security law, which has applied since April 2024 and bans universal default passwords, requires a way to report vulnerabilities and obliges makers to state how long they will provide security updates, with fines up to £10 million or 4 percent of global revenue. Other large markets run radio approvals of their own as well, so a launch across several countries means several approval campaigns on top of the US, EU and UK rules.
What Manufacturers Should Do Now
All of this points toward treating compliance as part of product design rather than a final hurdle. The cheapest failures are the ones caught early, so makers are running informal pre-compliance scans on early prototypes, sticking closely to their module’s reference antenna design, and choosing modules partly on how many markets and operators they are already approved for.
Lab choice is now a supply-chain decision too, so a company that tests in China today should know which of its labs the rules could hit and have a second option in a reciprocal country before any US rule takes effect, rather than discovering the problem during a launch.
Security documentation now travels with the radio paperwork: how the product handles passwords and updates, how people can report vulnerabilities, and how long the maker will support it. We looked at one example of makers designing security into setup itself in Wi-Fi devices that set themselves up.
Three Rulebooks, One Product
Step back and the direction is clear, even if the details are not. The US now cares most about who does the testing, Europe about what the product must prove, and the UK about a short list of security basics. An IoT maker selling in all three markets pays for all three, and nothing in this year’s changes suggests that burden will shrink soon.
That puts a premium on planning, and makers that pick well-certified modules, keep a second lab option outside China and write their security documentation alongside the design will launch on time. Those that still treat compliance as the final box will find it has become the first bottleneck, and mutual recognition between regulators, the one change that would ease the load, is the development to watch next.