"We can't Change it Overnight": Understanding Industry Perspectives on IoT Product Security Compliance and Certification
Prianka Mandal, Adwait Nadkarni
Abstract
Regulators and standards bodies have recently proposed several security compliance initiatives for IoT products. These emerging standards and regulations seek to bring security assurance to IoT products by way of compliance certification. However, even certified IoT products exhibit common vulnerabilities, which suggests the presence of latent challenges in the certification ecosystem. This paper performs the first qualitative, interview-based study (n=17) with IoT practitioners to understand industry perspectives and experiences of IoT product security certification, in order to uncover the latent factors and challenges obstructing effective IoT product certification. Our reflexive thematic analysis of the interview transcripts leads to 16 key findings that uncover critical factors affecting compliance enforcement in practice. We distill these findings and our observations into 4 major themes which represent critical gaps that must be addressed for product certification to be viable for IoT.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- "We can't Allow IoT Vendors to Pass off all Such Liability to the Consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product SecurityPrianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin et al.S&P 2025
- Security in the Air: Understanding IoT Vendor Practices and the Economics of Over-the-Air UpdatesHuancheng Hu, Christian DoerrUSENIX Security 2026
Builds on14
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim et al.S&P 2016 · 325 citations
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
- Ask the Experts: What Should Be on an IoT Privacy and Security Label?Pardis Emami Naeini, Yuvraj Agarwal, Lorrie Faith Cranor, Hanan HibshiS&P 2020 · 195 citations
- A Stitch in Time: Supporting Android Developers in WritingSecure CodeDuc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes et al.CCS 2017 · 125 citations
- Understanding Challenges for Developers to Create Accurate Privacy Nutrition LabelsTianshi Li, Kayla Reiman, Yuvraj Agarwal, Lorrie Faith Cranor et al.CHI 2022 · 56 citations
Related papers
- "Belt and suspenders" or "just red tape"?: Investigating Early Artifacts and User Perceptions of IoT App Security CertificationPrianka Mandal, Amit Seal Ami, Victor Olaiya, Sayyed Hadi Razmjo et al.USENIX Security 2024 · 4 citations
- Patchy Performance? Uncovering the Vulnerability Management Practices of IoT-Centric VendorsSandra Rivera Pérez, Michel van Eeten, Carlos Hernandez GañánS&P 2024 · 3 citations
- IoT Bugs and Development ChallengesAmir Makhshari, Ali MesbahICSE 2021 · 76 citations
- On the Contents and Utility of IoT Cybersecurity GuidelinesJesse Chen, Dharun Anandayuvaraj, James C. Davis, Sazzadur RahamanFSE 2024 · 1 citation
- P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesZe Jin, Luyi Xing, Yiwei Fang, Yan Jia et al.CCS 2022 · 19 citations
