Enabling a Digital Economy that Empowers and Protects Consumers
The American public must be able to participate in a digital economy that is safe, fair, and
accessible, and produces hardware and software that are reliably secure against cyber threats.
The Administration has pursued a range of market shaping tools to empower consumers,
promote innovation, and incentivize cyber-secure competition.
In March 2024, the FCC approved the U.S. Cyber Trust Mark, a voluntary cybersecurity
certification and labeling program that will help Americans purchase smart devices that are safer
and less vulnerable to cyberattacks. Under the program, IoT devices that meet certain
cybersecurity criteria as determined by NIST, such as requiring unique and strong default
passwords or securely implementing software updates, will be eligible for certification. Already,
several leading consumer electronics manufacturers and retailers have committed to supporting
implementation of the program. In July 2023, DOE announced a labeling research effort to
address the feasibility and limitations of applying a labeling approach to OT like smart meters
and solar inverters.
The Administration has taken steps to ensure that Federal spending increases our collective
cybersecurity and resilience. DoD, the General Services Administration (GSA), and NASA have
proposed amendments to the Federal Acquisition Regulation (FAR) to standardize and improve
cybersecurity requirements for unclassified Federal information systems, including prohibiting
agencies from buying vulnerable IoT devices and requiring the use of SBOMs. Raising the
cybersecurity standards of Federally-procured technology products will incentivize cybersecurity
across the ecosystem.
Under the False Claims Act, the DOJ’s Civil Cyber-Fraud Initiative holds government
contractors accountable when they materially misrepresent the cybersecurity attributes of their
products or services. In 2023, DOJ reached settlements with two vendors who had
misrepresented that their products met cybersecurity controls tied to Federal contracts.
At the end of 2023, the Treasury Department completed its initial assessment of the need for a
Federal insurance response to catastrophic cyber events, finding that further exploration of the
appropriate form of such a response is warranted and would be undertaken in the next phase of
the assessment, in coordination with CISA and ONCD. CISA also announced the reconstitution
of the Cybersecurity Insurance and Data Analysis Working Group to create a venue for
government and industry stakeholders to exchange information and discuss the role of the
insurance industry in driving down cyber risk.
Investing in Resilient Next-Generation Technologies
Embedding security and resilience into the technological foundations of our digital ecosystem is
a cheaper and more efficient approach than attempting to bolt it on after the fact. In 2023,
American innovation and public investment, powered by the President’s Invest in America
Agenda, created opportunities for coordinated public-private efforts to optimize critical and
emerging technologies for cybersecurity as they are developed and deployed. For example, in
November 2023, DOE announced $70 million in funding through the Rural and Municipal
2024 REPORT
22
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE