IoT Goes Federal under Newly Signed Law
Client Alert | 1 min read | 12.10.20
Last week, the President signed the Internet of Things (IoT) Cybersecurity Improvement Act into law, kicking off a multi-year process that will culminate in the first-ever federal requirements for IoT devices. Under the law, the National Institute of Standards & Technology (NIST) is now charged with drafting and finalizing security requirements for IoT devices, as well as guidelines for managing disclosures about those devices’ security vulnerabilities. In two short years, the federal government will then be prohibited from procuring IoT devices unless (1) the devices meet the pending NIST requirements; or (2) the devices are granted a formal waiver by an agency Chief Information Officer. In addition to creating yet another cybersecurity regime for the government contracting community, the law will create a new benchmark for consumer-facing companies to consider when assessing and complying with the growing number of states imposing their own “reasonable security” requirements for IoT devices.
Contacts

Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 3 min read | 02.13.26
In October 2024, the FTC adopted a final rule that substantially modified the HSR form, requiring new categories of information and documents. The final rule was the most significant overhaul of the HSR premerger notification requirements in decades. The new requirements imposed additional time and expense on merging parties, with the FTC estimating that the new form would likely take triple the amount of time to complete than the previous form. Numerous groups, including the U.S. Chamber of Commerce, sued to challenge the rule.
Client Alert | 12 min read | 02.13.26
What Organ Procurement Organizations Need to Know About CMS's New Proposed Rule
Client Alert | 9 min read | 02.12.26
Client Alert | 3 min read | 02.12.26


