The Question Behind the List
A founder with a prototype sensor asked me this summer a question I hear a lot in some form: "Who is actually making money with connected devices, and what does their app do?"
Not who could. Who is. So I went looking for ten use cases where I could name the company, point at a primary source, and describe what the app in the middle of it does all day.
Here's where it landed, with the date on it. On September 29, 2026 every one of the ten use cases below is tied to a named deployment: a cleared medical device, a public company's customer, a utility contract, a standards release, a government rule. Where the only evidence is a vendor's own number, I say so in the sentence.
And one date matters more than any of them. On September 11, 2026, the EU Cyber Resilience Act's reporting duties started applying to connected products, including ones already on shelves. If your device reaches Europe, that is now a live obligation, not a roadmap item. More on that in the security section.
This is a use case article, not a build guide. If you want the how, we cover protocols, architecture and cost in our IoT app development guide. Here the question is what the thing is for.
What Use Case Lists Get Wrong
Most IoT use case lists describe what a sensor could measure. The real value is in what the app does with the reading, and who acts on it.
The wrong model goes like this. Put a sensor on a thing, stream the data to the cloud, draw a dashboard, and value appears. It's the model behind most of the "smart everything" slide decks of the last decade, and it's why so many pilots ended as a dashboard nobody opened after week three.
The real model is closer to a smoke alarm. Nobody buys a smoke alarm for the data. They buy it because it does one thing, at the right moment, loudly, to the right person. The ten deployments below all have that shape. A glucose reading becomes an alert on a phone. A vibration pattern becomes a work order. A temperature excursion becomes a call before the vaccines are ruined.
Therefore, when you judge an IoT idea, don't start with the sensor. Start with the decision. Who gets told, what do they do next, and what did it cost when nobody told them? If you can't answer those three, the app will be a dashboard, and dashboards don't renew.
To be clear, the device still has to work, and firmware is hard. But in the projects I've seen, the hardware usually gets the budget and the app gets whatever is left. That ratio is often backwards.
How I Picked the Ten
Each use case had to pass three tests: a named, real deployment; a source I could fetch on September 29, 2026; and an app that people use, not just a backend.
I started from about twenty categories that recur in IoT roundups and cut anything I could only support with a market sizing report or a vendor's unnamed "leading manufacturer". Smart cities, for example, didn't make it. The deployments exist, but most public material is pilot announcements rather than something running at scale that I could cite cleanly.
These aren't ranked by market size, because I don't trust the market size numbers (see the limitations section). The order runs roughly from the most regulated to the least, which is also roughly how much the app has to get right.
- Named deployment: A company, product, utility or program you can look up, not a composite.
- Fetched source: A regulator page, company release or reputable outlet, linked in the sources list.
- Vendor claims labelled: Any result a vendor reports about its own product is attributed to the vendor in the text.
- An app in the loop: A person uses a phone or web app to see, decide or act.
The Ten Use Cases
Continuous Glucose Monitoring
the phone as a medical display
Deployment: Dexcom Stelo and Abbott FreeStyle Libre. The FDA cleared Stelo on March 5, 2024 as the first over-the-counter continuous glucose monitor, for adults who don't use insulin. The sensor sits on the upper arm and sends readings to an app on the person's phone. A year earlier, on March 6, 2023, Abbott announced FDA clearance of modified FreeStyle Libre 2 and 3 sensors for integration with automated insulin delivery systems, which adjust insulin pump dosing from the sensor's data.
What the app does: it is the display, the alarm and the data pipe. In the insulin delivery case, it sits inside a loop where a reading can change how much drug a pump delivers. That is about as high stakes as a consumer app gets.
Why it matters for builders:this is the clearest example of an IoT app being part of a regulated device. The Bluetooth connection, the alert timing and the behavior when the phone kills the app in the background are all things the manufacturer has to validate. If you're building near this space, the line between a wellness app and a device is the first thing to settle, and it's the subject of use case 10.
Fleet Telematics
trucks that report their own condition
Deployment: Samsara and Estes. In its fiscal 2026 results published March 5, 2026, Samsara said Estes expanded from video-based safety and telematics to add equipment monitoring with asset gateways and asset tags, plus connected asset maintenance. The same release names Werner Enterprises, Southern California Edison and the Metropolitan Transit Authority of Harris County, Texas among its fourth quarter wins, and reports about $1.9 billion in annual recurring revenue. All of that is Samsara describing its own business.
What the app does:two apps, really. A driver app handles logs, inspections and coaching. A web console gives dispatchers and safety managers location, camera events and maintenance alerts. The value comes from joining vehicle data with people's workflows, not from the GPS dot on a map.
Why it matters for builders: fleets are where IoT stopped being a pilot a long time ago. If you are building a vertical product for, say, landscaping crews or refrigerated delivery, you are more likely to integrate with a telematics platform's API than to build your own hardware. That makes the integration and API layer the real product.
Predictive Maintenance
catching the pump before it fails
Deployment: Siemens Senseye at Sachsenmilch Leppersdorf, a German dairy plant that processes roughly 4.6 million liters of milk a day. Siemens' published reference says the plant added vibration sensors and the SIPLUS CMS1200 condition monitoring system, fed into Senseye Predictive Maintenance, with the project completed in 2024. Siemens reports cost savings "in the lower six figures" and fewer unplanned failures. That is Siemens' own account of its own customer, and the reference does not publish the baseline or the method.
What the app does:it ranks machines by how unusual their behavior is and tells a maintenance planner which ones to look at this week. The hardest design problem isn't the model. It's trust. A planner who gets three false alarms stops opening the app.
Why it matters for builders: industrial buyers want the alert inside the system they already use, usually a maintenance or ERP tool. Expect to spend as much time on work order integration as on the monitoring itself.
Precision Agriculture
a farm run from a phone
Deployment: John Deere Operations Center. Deere's Business Impact Report 2025 lists about 1 million connected machines, nearly 500 million engaged acres, 147 million highly engaged acres and about 409,000 unique monthly active digital users. Deere defines "engaged acres" itself, so read those as Deere's own usage measures rather than audited market data. The same report sets a target of 600 million engaged acres by 2030.
What the app does: Operations Center is the place where machine data (where the planter went, how much seed went down) meets agronomic data (yield, soil, prescriptions). A grower plans in the office, the tractor executes in the field, and the results come back to the same map.
Why it matters for builders: the ratio is striking. Divide 409,000 users by 1 million machines and you get about 0.4 digital users per connected machine. Most connected machines are not managed by someone actively in the app every month. For an ag startup, that says the win may be integration into the platform farmers already use, not another app.
Smart Home Control
Matter makes the app less of a fight
Deployment: Matter, the Connectivity Standards Alliance standard. In November 2025 the CSA released Matter 1.5, adding cameras over WebRTC, a unified model for closures such as shades, gates and garage doors, soil sensors and wider energy data features.
What the app does:for a device maker, the Matter app often shrinks to setup, firmware updates and the features that go beyond the standard. Everyday control can happen in Apple Home, Google Home or Alexa. That's the trade. Less code to maintain, but less time with your customer inside your app.
Why it matters for builders:a smart home brand in 2026 has to decide early whether its app is the main interface or a companion. I'd usually pick companion plus one thing the ecosystems can't do well, such as detailed energy history or multi-home management.
Cold Chain Monitoring
vaccines that tell you they are warm
Deployment: vaccine storage in the US Vaccines for Children program. The American Academy of Pediatrics' vaccine storage guidance tells practices to use digital data loggers with buffered probes, with a primary and a backup logger for VFC vaccines, following the CDC Vaccine Storage and Handling Toolkit. Every participating clinic is, in effect, running a small IoT deployment.
What the app does: it turns a logger into a phone call at 2 a.m. when the fridge fails, and into an audit trail when the state program asks for temperature records. The alert is the product. The log is the compliance.
Why it matters for builders: food is the next big cold chain driver, but on a longer clock than many vendors imply. The FDA Food Traceability Rule now has a compliance date of July 20, 2028, after Congress directed FDA not to enforce it before then. Traceability records are not the same as temperature monitoring, but the two tend to get bought together.
Smart Meters
the utility's app in your pocket
Deployment: PSE&G in New Jersey. In July 2021 Landis+Gyr announced a 10-year agreement to supply PSE&G with 2.3 million advanced meters, network infrastructure and software on its Gridstream Connect platform, with installation planned over about four years.
What the app does: for customers, near daily usage data, outage status and bill forecasts. For the utility, remote reads and connect or disconnect, which removes truck rolls. The meter network is the IoT part. The customer app is where the utility gets its credit or its complaints.
Why it matters for builders: utilities move slowly and buy through long contracts, so the opening for most app teams is on top of the data: energy management apps, landlord tools and solar or battery apps that use meter data through utility programs.
Item and Asset Tracking
networks of other people's phones
Deployment: Apple AirTag and Amazon Sidewalk. On January 26, 2026 Apple introduced a new AirTag with a second-generation Ultra Wideband chip, which Apple says extends Precision Finding up to 50% farther. Amazon took a different route: in March 2023 it opened Sidewalk to outside developers and said the network, built from Echo and Ring devices sharing a little bandwidth over Bluetooth and 900 MHz LoRa, covered 90% of the US population. Both figures are the companies' own claims.
What the app does: the tracker is nearly dumb. The finding network is the product, and the app is the interface to it. For business asset tracking, the same pattern shows up with tags on pallets, tools and trailers.
Why it matters for builders:tracking products carry an obligation most founders miss: unwanted tracking. Any tracker that works on a crowd network has to think about stalking alerts and how a person discovers a tag they didn't consent to. Build that in from the first spec.
Smart Locks and Building Access
the phone as the key
Deployment: Level Lock Pro, sold through Apple with Matter support and Apple home keys, so a key in Apple Wallet on an iPhone or Apple Watch opens the door. The same pattern powers employee badges in Wallet for offices and campuses.
What the app does: issue keys, share them for a time window, revoke them, and show who came in when. For a property manager or a short-term rental host, the key sharing flow is the business, and the lock is the endpoint.
Why it matters for builders: wallet keys are native platform features. This is one area where I push clients toward native iOS development for the access piece, even if the rest of the product is cross-platform, because the entitlements and Wallet integration are platform specific. And the failure mode is physical: someone locked out in the rain. Design the offline and battery-dead path first.
Connected Fitness
where wellness meets the FDA
Deployment: WHOOP, and the line it ran into. On July 14, 2025 the FDA sent WHOOP a warning letter saying its Blood Pressure Insights feature was a device being marketed without clearance, because estimating blood pressure is tied to diagnosing hypertension. WHOOP publicly disputed that reading and said the feature was about wellness and performance.
What the app does:in connected fitness the wearable collects, and the app interprets: sleep, strain, recovery, trends. The interpretation is where the value is, and it's also where the regulatory risk is. Words like "detect", "diagnose" and "monitor your condition" move a product toward device territory.
Why it matters for builders:write your feature copy with the same care as your code. I'm not a regulatory lawyer, and this isn't legal advice, but I tell every health wearable client to get a regulatory opinion on the claims before launch, not after the letter.
The Ten Side by Side
Read across the table and one pattern stands out: the higher the regulatory weight, the more the app becomes part of the product's safety case.
| # | Use case | Named deployment | Radio / link | What the app does | Regulatory weight |
|---|---|---|---|---|---|
| 1 | Glucose monitoring | Dexcom Stelo; FreeStyle Libre 2 and 3 | Bluetooth LE | Shows readings, alerts, shares data | High: FDA cleared devices |
| 2 | Fleet telematics | Samsara at Estes | Cellular gateways | Location, safety video, maintenance | Medium: driver privacy, ELD rules |
| 3 | Predictive maintenance | Siemens Senseye at Sachsenmilch | Plant network, vibration sensors | Flags anomalies, raises work orders | Low to medium: plant safety |
| 4 | Precision agriculture | John Deere Operations Center | Cellular from machines | Field maps, machine data, planning | Low: data ownership terms |
| 5 | Smart home control | Matter certified devices | Thread, Wi-Fi, Bluetooth for setup | Pairing, scenes, remote control | Medium: PSTI, CRA, Cyber Trust Mark |
| 6 | Cold chain monitoring | VFC vaccine storage with data loggers | Wi-Fi or cellular loggers | Temperature alarms, audit logs | High: program rules |
| 7 | Smart meters | PSE&G with Landis+Gyr | Utility mesh network | Usage display, outage and billing data | High: utility regulators |
| 8 | Item and asset tracking | Apple AirTag; Amazon Sidewalk | UWB, Bluetooth, LoRa | Find, alert, share location | Medium: anti-stalking duties |
| 9 | Smart locks and access | Level Lock Pro with Apple home keys | Bluetooth, NFC, Thread | Keys, sharing, access logs | Medium: physical safety |
| 10 | Connected fitness | WHOOP and the FDA warning letter | Bluetooth LE | Trends, coaching, health insights | Medium to high: wellness line |
The radio column matters more than it looks. Six of the ten rely on Bluetooth for at least part of the job, usually setup or the phone link. Bluetooth is also the single biggest source of support tickets in the connected apps I've worked on, because every OS release changes something about background permissions and reconnection.
The other pattern: in half the rows, the most valuable user isn't the device owner. It's the dispatcher, the maintenance planner, the utility, the property manager. The consumer app is sometimes the smaller product.
Which of the ten pays back fastest? The ones where a single missed event is expensive and easy to count. A ruined refrigerator of vaccines, a stopped filling line, a trailer that went missing. In those, the app replaces a person walking around with a clipboard, and the arithmetic is short: cost of one event times events avoided, against the price of the software.
The slowest are the consumer ones, and that surprises people. A smart home app rarely earns money directly. It's a feature that sells the hardware and keeps returns down, so its payback shows up as fewer support calls and better reviews, which are real but hard to put in a spreadsheet. Fitness and tracking sit in between, because a subscription can ride on top of the device.
Why does this matter before you build? Because it changes what you optimize. An industrial app should be judged on how few alerts it sends that turn out to be wrong. A consumer device app should be judged on how quickly a new owner gets from the box to a working device. Those are different products even when the radio and the cloud look the same.
One more reading of the table. The regulated rows (glucose, cold chain, meters) have something in common beyond rules: someone else already defined what a good outcome looks like. The FDA, a state vaccine program, a utility commission. That makes those products slower to launch and easier to sell, because the buyer already knows what they're buying. The unregulated rows have to invent their own definition of success, which is freedom and a trap at the same time.
Security Rules in Force
As of September 29, 2026, two connected product security regimes are binding law (the UK PSTI regime and the first phase of the EU Cyber Resilience Act), and the main US label is still being set up.
| Rule or standard | Where | Status on September 29, 2026 | What it asks of an app team |
|---|---|---|---|
| Cyber Resilience Act (EU) 2024/2847 | EU market | In force since Dec 10, 2024; reporting from Sep 11, 2026; main obligations Dec 11, 2027 | 24 hour early warning, 72 hour notification, vulnerability handling, secure updates |
| UK PSTI regime | UK market | In force since Apr 29, 2024 | No default passwords, published reporting route, stated update period |
| ETSI EN 303 645 | Standard, used worldwide | Published European standard | Baseline provisions for consumer IoT |
| NIST IR 8259 series | US guidance | Final NIST guidance, voluntary | Device identity, configuration, data protection, update, customer information |
| US Cyber Trust Mark | US, voluntary label | Administrators being approved; no labelled product found | Testing against FCC criteria once applications open |
EU Cyber Resilience Act. Regulation (EU) 2024/2847 entered into force on December 10, 2024. Its first obligations landed on September 11, 2026. From that date, per the European Commission's CRA reporting page, manufacturers must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform: an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days of a fix being available (one month for severe incidents). The Commission says the platform became operational on September 11, 2026.
The detail that catches people: the reporting duty covers products already on the market, not just new ones. The main product requirements, including secure by design duties and conformity assessment, apply from December 11, 2027. The EU's Digital Omnibus proposal aims to merge incident reporting channels across NIS2, GDPR, the CRA and other laws into a single entry point. As of today it's a proposal, and I found nothing showing it moved either CRA date.
UK PSTI. The UK's product security regime has been in force since April 29, 2024. It bans universal and easily guessable default passwords, requires a published way to report security issues, and requires manufacturers to state the minimum period they will provide security updates. It's short, and it's law.
ETSI EN 303 645 and NIST IR 8259. ETSI EN 303 645 is the consumer IoT baseline standard that the UK rules draw on; its thirteen provisions cover passwords, vulnerability disclosure, updates, secure storage and secure communication. In the US, NIST's NISTIR 8259A defines a core baseline of device capabilities (identity, configuration, data protection, logical access, software update and cybersecurity state awareness). Both are voluntary on their own. Both are the practical checklist most regulators and big buyers point at.
US Cyber Trust Mark. This one needs the most care, because its status changed several times. UL Solutions was the program's lead administrator until it withdrew on December 19, 2025, after FCC Chairman Brendan Carr opened an investigation into its ties to China, including testing labs there. The FCC ran an application window in January 2026 and named the ioXt Alliance lead administrator effective April 13, 2026. On August 11, 2026 the FCC's Public Safety and Homeland Security Bureau conditionally approved label administrators and opened a new filing window.
What I could not find is any announcement that a product actually carries the mark. So the precise status is: voluntary program, created, administrators being approved, no labelled product I could confirm as of September 29, 2026. The FCC's program page is the place to re-check, though it blocks automated readers.
For app teams, the practical translation is short. No shared default credentials. Signed firmware and app updates with a rollback path. A published vulnerability disclosure page with a named owner. A stated support period. And, for anything reaching the EU, a written plan for who files the 24 hour early warning. If you want an outside view of where your product stands, that's what our security audit engagements check against.
What We Have Built
Our clearest connected device project is LIVV Audio, a Bluetooth Low Energy headphone platform, which is use case 8's cousin: a small device whose value is exposed through an app.
In the LIVV Audio build, we shipped a Swift iOS app using CoreBluetooth and a Kotlin and Java Android app, a NestJS backend and a React admin dashboard. The case study describes two paths: a local BLE path for latency-sensitive work such as playback, volume, battery level and live equalizer changes, and a cloud path for accounts, preference sync and a device registry. The phone talks to the headphones directly; the server only remembers.
That split is the lesson I'd carry into any of the ten use cases above. Anything a person expects to happen instantly, or with no signal, goes over the local link. Anything that needs history, sharing or another device goes through the backend. When teams blur that line, the app freezes in a parking garage.
The case study also lists BLE reliability as the recurring challenge, handled through extensive device testing and defensive coding. That matches everything I've seen since: the radio layer is where schedules slip. It's also why LIVV went native on both platforms, and why for BLE-heavy work I lean toward native Android development and iOS over a shared codebase. For lighter device apps, a cross-platform framework with native modules is fine; we compared the options in our ranking of hybrid app frameworks.
To be clear about scope: LIVV is consumer audio, not a medical, utility or industrial deployment. I cite it for the architecture, not as evidence that we've shipped every use case on this list. We haven't.
A Worked Example
A worked example, framed as a scenario, not a client result: a regional pediatric group deciding whether a temperature monitoring app is worth building or buying.
Consider a group with 8 clinics, each with one vaccine refrigerator. Per the AAP guidance above, each unit needs a primary and a backup digital data logger for VFC vaccines, so the group has 16 loggers already. The question isn't whether to monitor. It's whether anyone gets told in time.
Suppose the group's own records show one overnight refrigerator failure per clinic every two years. That's 8 clinics divided by 2 years, or about 4 excursions a year across the group. The cost of each one is whatever that fridge held plus staff time and rescheduled visits. I won't put a dollar figure on that, because it depends entirely on the group's inventory, and any number I printed would be invented. The group should pull its own last inventory count.
Now the arithmetic that decides it. If off-the-shelf loggers with cloud alerts already call a manager's phone, the build case is weak: buy, and spend the money on a written response plan. If the group also needs the alerts joined to its scheduling system, so affected patients are flagged for revaccination automatically, that's a single workflow integration, and it fits the $28,000 to $70,000 band below.
Divide that band by the 4 expected excursions a year and you get roughly $7,000 to $17,500 per excursion in the first year, falling after that. If one spoiled refrigerator costs the group more than that, the integration pays. If it costs less, buy the loggers and stop. That's the whole test, and it's the same one I'd run for any of the ten use cases: count the cost of one missed event, count the events, then price the software.
What Breaks First
In connected apps, the failures are rarely in the dashboard. They're in pairing, offline behavior, updates and who answers the security inbox.
| What breaks | The signal | What to do |
|---|---|---|
| Bluetooth reconnection | Support tickets about pairing after an OS update | Test on the oldest supported phones every release; keep a pairing reset flow |
| Offline behavior | Blank screens on a job site or in a basement | Cache last known state; queue commands; show data age |
| Firmware updates | Devices stuck on old versions | Signed images, staged rollout, rollback, version dashboard |
| Alert fatigue | Users muting notifications | Fewer, ranked alerts; quiet hours; escalation rules |
| Backend dependency | Devices useless during an outage | Local control path for core functions |
| Vulnerability reports | Nobody owns the inbox | Published policy, named owner, CRA timing plan |
The one I'd fix first is updates. A device that can't be patched safely is a liability under every regime in the security section. It's also the reason the CRA's 72 hour clock is scary: if a vulnerability is being exploited and your update path is manual, you'll be reporting a problem you can't fix quickly.
The second is backend dependency. When a cloud service shuts down, devices that only work through it become bricks, and customers remember. Keep a local control path for the core function, like LIVV's BLE path, even if the fancy features need the server.
Cost and Timeline
Our published bands for connected product software run from $9,000 for a discovery audit to $420,000 or more for enterprise and regulated builds. Firmware and hardware certification are separate.
| Engagement | Range | Timeline | Fits |
|---|---|---|---|
| Discovery and audit | $9k to $22k | 2 to 4 weeks | Choosing the use case, radio and rules that apply |
| Single-workflow build | $28k to $70k | 4 to 9 weeks | One device, one app, one alert path |
| Multi-workflow platform | $70k to $180k | 9 to 16 weeks | Companion app plus console plus integrations |
| Enterprise or regulated | $180k to $420k+ | 14 to 24 weeks | Health, utility or multi-site deployments |
Senior-led time is $150 to $225 an hour, retainers run $2,500 to $9,500 a month, and every build gets a 30-day post-launch warranty. Full source code and IP transfer to you, and we send a fixed-price phased proposal within 5 business days of discovery. We don't hold SOC 2, ISO 27001 or HITRUST attestations; if your buyer requires one from the vendor, factor that in.
Whether you hire an agency, a consultant or a freelancer for this matters more for IoT than for most apps, because the work crosses firmware, mobile and cloud. We laid out the trade-offs in consultant vs agency vs freelancer.
Red Flags
Walk away from an IoT proposal that can't answer, in writing, how updates are signed, what happens offline, and who handles vulnerability reports.
- No offline story: If the answer to 'what if there is no signal' is 'it shows an error', the app will fail where devices live.
- Market size in the pitch: A proposal that opens with a trillion-dollar IoT market figure is selling the category, not your product.
- Shared default credentials: Illegal for consumer products in the UK since April 2024 and against every baseline standard.
- Certification promises: Nobody can promise a US Cyber Trust Mark today; ask what standard they build to instead.
- Vendor cloud lock-in: If you don't own the cloud accounts and code, you don't own the product.
- Wellness copy that diagnoses: Feature text that says detect or diagnose without a regulatory opinion behind it.
What I Could Not Verify
Several numbers that dominate IoT articles are missing here on purpose, because I couldn't trace them to a method.
The big ones are the device counts and market sizes: tens of billions of connected devices, trillion-dollar markets, fixed percentages of pilots that fail. They circulate in different versions with different totals, usually from analyst firms whose method sits behind a paywall or from vendors quoting each other. I don't print them, and I'd be wary of a proposal that leans on them.
I also refused a few specific claims. I couldn't find a named, sourced cold chain deployment from a monitoring vendor with published results, so use case 6 rests on public health guidance rather than a vendor case study. Siemens' "lower six figures" saving at Sachsenmilch is Siemens' own statement with no baseline. Samsara's customer list and Deere's engaged acres are the companies' own measures. Amazon's 90% Sidewalk coverage figure dates from 2023 and I found no newer independent measurement.
On the Cyber Trust Mark, the FCC's own pages block automated readers, so the August 11, 2026 administrator update is cited from the FCC listing as surfaced in search and from trade press. I found no product carrying the mark, but absence from search results isn't proof. Re-check before relying on it. And the PSE&G contract is from 2021; I did not confirm how many of the 2.3 million meters are installed today.
Three Things This Week
If you're planning a connected product, three steps before you spend on anything else.
- 1. Write the decision, not the sensor: One sentence: who gets told what, and what they do next. If you can't write it, you aren't ready to build.
- 2. Count one missed event: Price a single failure (spoiled stock, a stopped line, a lockout) from your own records, and how often it happens.
- 3. Map your markets to the rules: EU means CRA reporting now; UK means PSTI now; US means NIST IR 8259 as your checklist. Put a named owner on vulnerability reports.
Then build the smallest version that closes that one loop. Everything else can wait.
Planning a Connected Device App?
Book a discovery call. We map the device, the radio, the backend and the rules that apply, and send a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Apt 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1FDA, FDA clears first over-the-counter continuous glucose monitor (Dexcom Stelo, March 5, 2024)↗
- 2Abbott press release via Nasdaq, FDA clears FreeStyle Libre 2 and 3 sensors for integration with automated insulin delivery (March 6, 2023)↗
- 3Samsara, Q4 and fiscal year 2026 results (March 5, 2026)↗
- 4Siemens, Sachsenmilch Leppersdorf reference: Senseye Predictive Maintenance↗
- 5Deere & Company, Business Impact Report 2025↗
- 6EE Journal, Matter 1.5 introduces cameras, closures and enhanced energy management (CSA announcement, November 2025)↗
- 7American Academy of Pediatrics, vaccine storage and handling (digital data loggers, CDC toolkit)↗
- 8FDA, FSMA Food Traceability Rule page (compliance date July 20, 2028)↗
- 9POWER, Landis+Gyr and PSE&G sign contract for advanced metering deployment (July 2021)↗
- 10Apple Newsroom, Apple introduces new AirTag with expanded range and improved findability (January 26, 2026)↗
- 11Light Reading, Amazon opens Sidewalk network to outside developers (March 28, 2023)↗
- 12Apple Store, Level Lock Pro (Matter) with Apple home keys support↗
- 13FDA, warning letter to WHOOP, Inc. (July 14, 2025)↗
- 14Cybersecurity Dive, FCC IoT labeling program loses lead company after China probe↗
- 15Nextgov/FCW, FCC selects ioXt Alliance to lead cyber labeling program (April 13, 2026)↗
- 16FCC, U.S. Cyber Trust Mark program page (blocks automated readers)↗
- 17FCC, PSHSB conditionally approves Cybersecurity Label Administrators and opens filing window (August 11, 2026; blocks automated readers)↗
- 18European Commission, Cyber Resilience Act reporting obligations↗
- 19Freshfields, CRA reporting obligations take effect on 11 September 2026↗
- 20GOV.UK, the UK PSTI product security regime↗
- 21NIST CSRC, NISTIR 8259A IoT Device Cybersecurity Capability Core Baseline↗
- 22CNX Software, ETSI releases EN 303 645 IoT security standard for consumer devices↗

