Finite StateFinite State
Finite StateFinite State
Compliance & Regulations

What you need to know about the IoT Cybersecurity Improvement Act (H.R.1668)

The IoT Cybersecurity Improvement Act (H.R. 1668) is new legislation that could affect both connected device manufacturers and asset owners.

Stephanie

Stephanie

November 20, 2020

The Senate has unanimously passed IoT Cybersecurity Improvement Act (H.R.1668). Barring a presidential veto, the bill will soon become law. 

If you’ve been paying attention to IoT laws and regulations in recent months, it should come as no surprise that this bill has moved forward. IoT and connected device security has been a major priority both globally and nationally, as we’ve seen from high profile discussions around 5G and Huawei networking devices as well as recent policy pushes surrounding connected devices in our critical infrastructure. 

H.R. 1668 is a significant step in the federal government recognizing the importance of IoT security. The growing number of attacks on connected devices has made it imperative that we act. The IoT Cybersecurity Improvement Act is a significant step toward ensuring that we have the right standards in place to keep our critical systems secure. Given Finite State’s commitment to connected device security, we are grateful for the steps that Congress has taken to address this topic and are eager to help our customers and our community take action.   

What does the IoT Cybersecurity Improvement Act do?

H.R. 1668 directs the National Institute of Standards and Technology (“NIST”) to issue standards and guidelines for the federal government on “the appropriate use and management by agencies of Internet of Things devices owned or controlled by an agency and connected to information systems owned or controlled by an agency.” This includes NIST developing “minimal informational security requirements” for managing cybersecurity risks associated with these devices.  

Additionally, NIST must “consider relevant standards, guidelines, and best practices developed by the private sector, agencies, and public-private partnerships.”  Any standards and guidelines that are developed under this Act must be consistent with already-existing NIST guidelines. You can read the full text of the Act act Congress.gov.

How does the IoT Cybersecurity Improvement Act affect device manufacturers?

Since NIST has yet to actually develop these guidelines, the impact of the H.R. 1668 isn’t fully known. What we do know is this: the Act includes a procurement provision, which prohibits the head of any federal agency from “procuring or obtaining, renewing a contract to procure or obtain, or using an Internet of Things device,” if the Chief Information Officer of that agency determines during a required review for “a contract for such device that the use of such device prevents compliance with the standards and guidelines developed” by NIST.

If you want the federal government to utilize (or continue to utilize) your products, you must be able to ensure that they will not pose a significant risk. You cannot eliminate all risks from your devices, but you can monitor, manage, and mitigate factors including:

  • Vendor geopolitical, regulatory, and compliance risk
  • Supply chain risk
  • Software vulnerabilities
  • Configuration vulnerabilities
  • Device hardening measures
  • Active threats

By assessing the above, remediating any issues you find, and being able to report the results to NIST, you will undoubtedly be able to achieve compliance with the Act, whatever the specific guidelines end up being. If you don’t currently have the tooling that will allow you to uncover and analyze those factors listed above, schedule a demo with Finite State and we can show you how the Finite State Platform can analyze your device portfolio automatically and at scale. 

{{cta('186741546866')}}

There is still much work to do to improve connected device security

H.R. 1668 has the potential to improve the security of connected devices and critical infrastructure by creating a demand and incentive for higher quality devices. However, this is only one step in what must be a comprehensive system of transparency and verification in the development and deployment of connected devices.

No device can be regarded as 100% secure. The federal government, and indeed private entities as well, will have to continually assess true device risk in order to determine whether or not connected devices will pose a threat. In order to do that, they must have access and insight into software components and supply chain risks for each device, and they must be able to achieve that quickly and at scale. Here at Finite State we are committed to helping facilitate collaboration between device manufacturers, asset owners, and regulators as we continue to provide the tooling necessary to uncover the risks in connected devices.

Tags

#regulation

Related Articles

Road to Compliance: First Steps OEMs and Suppliers Should Take Today

The Road to Compliance: First Steps OEMs and Suppliers Should Take Today

Learn how to achieve Connected Vehicle Rule compliance with six actionable steps — from SBOM & HBOM generation to supplier engagement and risk evaluat...

Oct 20, 2025
Legacy Software & CVR Compliance Carveouts Explained

Legacy Software & CVR Compliance Carveouts Explained

Learn how legacy carveouts and specific authorizations can help you comply with CVR—while time-limited, they demand proactive planning now.

Oct 16, 2025
Regulations Driving IoT Security Forward

Regulations Driving IoT Security Forward

From EU CRA to FDA 524B, IoT regulations are reshaping the market. Learn what manufacturers need for compliance—SBOMs, testing, and supply chain visib...

Sep 24, 2025

Ready to Level Up Your Security Knowledge?

Join thousands of security professionals learning from the best in the industry

Start Learning TodayStart Learning Today
Finite StateFinite State

Finite State is the Product Security Automation Platform that functions as an autonomous Product Security OS: design → verify → prove, grounded in what you ship.

Platform

Platform Overview
Ground Truth Inventory
Exploitability-Based Prioritization
Design-Time Architecture Security
Automated Evidence-Backed Compliance

Solutions

Device Manufacturers
Automotive
Medical Devices
Energy & Utilities
Government
Industrial

Resources

Blog
Resource Library
Webinars & Videos
Events
Documentation

Company

About Us
CareersHIRING
Press & Media
Contact Sales
X

Privacy PolicyTerms of UseCustomer Terms and Conditions