Cloud, APIs, Mobile Apps, and Data Services in IoT Compliance Scope (T02b)
The compliance boundary for consumer IoT products is expanding. Regulators are moving beyond device-centric security models toward whole-product definitions that encompass cloud infrastructure, mobile applications, third-party APIs, and data pipelines. Frameworks such as NISTIR 8425 and the EU Cyber Resilience Act exemplify this shift — placing services once considered internal infrastructure under evidence requirements and audit scrutiny as part of the certified product. This talk examines how product evidence boundaries are drawn, what triggers inclusion of remote services, and how organizations must adapt before enforcement timelines arrive.
