Skip to main contentSkip to footer

    Top Rated & Verified

    Top Clutch App Development Company Black Owned United StatesTop Clutch Java Developers France 2026Top Clutch Service Line Blind Company Black Owned 2026Top Clutch App Development Company Minority Owned 2026Top Clutch Web Developers Black Owned 2026Top Clutch App Development Company Black Owned 2026Top Clutch Flutter Developers France 2026Top Clutch Health & Wellness App Developers France 2026Top Clutch Swift Company France 2026Top Clutch Machine Learning Company France 2026Top Clutch Chatbot Company France 2026Top Clutch Artificial Intelligence Company France 2026Top Clutch App Development Company Minority Owned Los Angeles
    Back to Blog
    IoT
    September 29, 2026
    26 min read

    Top 10 IoT App Use Cases in 2026,With Real Deployments

    Every IoT list promises billions of devices. This one names ten real deployments, cites each one, labels vendor claims as vendor claims, and tells you which security rules started applying this month.

    A phone showing connected device controls beside a smart meter, a delivery truck and a glucose sensor
    1M
    Connected John Deere machines, with nearly 500M engaged acres (Deere's own figures)
    Deere & Company, Business Impact Report 2025
    2.3M
    Smart meters PSE&G contracted from Landis+Gyr for New Jersey
    Landis+Gyr press release, July 16, 2021 (via POWER)
    Sep 11, 2026
    Date EU Cyber Resilience Act incident and vulnerability reporting began
    European Commission, CRA reporting obligations page
    90%
    Share of the US population Amazon says its Sidewalk network covers
    Light Reading, March 28, 2023 (Amazon's claim)

    Key Takeaways

    • Ten IoT app use cases, each tied to a named deployment with a source: CGM apps (Dexcom, Abbott), fleet telematics (Samsara and Estes), predictive maintenance (Siemens at Sachsenmilch), agriculture (John Deere), Matter smart homes, vaccine cold chain, smart meters (PSE&G), item tracking (AirTag, Sidewalk), smart locks and fitness wearables.
    • The device is rarely the hard part. The app and backend that turn a reading into a decision, and keep working offline, are where most of the build effort goes.
    • EU Cyber Resilience Act reporting obligations started on September 11, 2026 for products already on the market. The main requirements follow on December 11, 2027.
    • The US Cyber Trust Mark is still getting its administrators in place after UL Solutions withdrew in December 2025. I found no product carrying the label as of September 29, 2026.
    • Vendor results in this article are the vendors' own claims and are labelled that way. I refused several popular IoT market statistics because I could not trace them to a method.

    The Question Behind the List

    A founder with a prototype sensor asked me this summer a question I hear a lot in some form: "Who is actually making money with connected devices, and what does their app do?"

    Not who could. Who is. So I went looking for ten use cases where I could name the company, point at a primary source, and describe what the app in the middle of it does all day.

    Here's where it landed, with the date on it. On September 29, 2026 every one of the ten use cases below is tied to a named deployment: a cleared medical device, a public company's customer, a utility contract, a standards release, a government rule. Where the only evidence is a vendor's own number, I say so in the sentence.

    And one date matters more than any of them. On September 11, 2026, the EU Cyber Resilience Act's reporting duties started applying to connected products, including ones already on shelves. If your device reaches Europe, that is now a live obligation, not a roadmap item. More on that in the security section.

    This is a use case article, not a build guide. If you want the how, we cover protocols, architecture and cost in our IoT app development guide. Here the question is what the thing is for.

    What Use Case Lists Get Wrong

    Most IoT use case lists describe what a sensor could measure. The real value is in what the app does with the reading, and who acts on it.

    The wrong model goes like this. Put a sensor on a thing, stream the data to the cloud, draw a dashboard, and value appears. It's the model behind most of the "smart everything" slide decks of the last decade, and it's why so many pilots ended as a dashboard nobody opened after week three.

    The real model is closer to a smoke alarm. Nobody buys a smoke alarm for the data. They buy it because it does one thing, at the right moment, loudly, to the right person. The ten deployments below all have that shape. A glucose reading becomes an alert on a phone. A vibration pattern becomes a work order. A temperature excursion becomes a call before the vaccines are ruined.

    Therefore, when you judge an IoT idea, don't start with the sensor. Start with the decision. Who gets told, what do they do next, and what did it cost when nobody told them? If you can't answer those three, the app will be a dashboard, and dashboards don't renew.

    To be clear, the device still has to work, and firmware is hard. But in the projects I've seen, the hardware usually gets the budget and the app gets whatever is left. That ratio is often backwards.

    How I Picked the Ten

    Each use case had to pass three tests: a named, real deployment; a source I could fetch on September 29, 2026; and an app that people use, not just a backend.

    I started from about twenty categories that recur in IoT roundups and cut anything I could only support with a market sizing report or a vendor's unnamed "leading manufacturer". Smart cities, for example, didn't make it. The deployments exist, but most public material is pilot announcements rather than something running at scale that I could cite cleanly.

    These aren't ranked by market size, because I don't trust the market size numbers (see the limitations section). The order runs roughly from the most regulated to the least, which is also roughly how much the app has to get right.

    • Named deployment: A company, product, utility or program you can look up, not a composite.
    • Fetched source: A regulator page, company release or reputable outlet, linked in the sources list.
    • Vendor claims labelled: Any result a vendor reports about its own product is attributed to the vendor in the text.
    • An app in the loop: A person uses a phone or web app to see, decide or act.

    The Ten Use Cases

    1

    Continuous Glucose Monitoring

    the phone as a medical display

    Deployment: Dexcom Stelo and Abbott FreeStyle Libre. The FDA cleared Stelo on March 5, 2024 as the first over-the-counter continuous glucose monitor, for adults who don't use insulin. The sensor sits on the upper arm and sends readings to an app on the person's phone. A year earlier, on March 6, 2023, Abbott announced FDA clearance of modified FreeStyle Libre 2 and 3 sensors for integration with automated insulin delivery systems, which adjust insulin pump dosing from the sensor's data.

    What the app does: it is the display, the alarm and the data pipe. In the insulin delivery case, it sits inside a loop where a reading can change how much drug a pump delivers. That is about as high stakes as a consumer app gets.

    Why it matters for builders:this is the clearest example of an IoT app being part of a regulated device. The Bluetooth connection, the alert timing and the behavior when the phone kills the app in the background are all things the manufacturer has to validate. If you're building near this space, the line between a wellness app and a device is the first thing to settle, and it's the subject of use case 10.

    2

    Fleet Telematics

    trucks that report their own condition

    Deployment: Samsara and Estes. In its fiscal 2026 results published March 5, 2026, Samsara said Estes expanded from video-based safety and telematics to add equipment monitoring with asset gateways and asset tags, plus connected asset maintenance. The same release names Werner Enterprises, Southern California Edison and the Metropolitan Transit Authority of Harris County, Texas among its fourth quarter wins, and reports about $1.9 billion in annual recurring revenue. All of that is Samsara describing its own business.

    What the app does:two apps, really. A driver app handles logs, inspections and coaching. A web console gives dispatchers and safety managers location, camera events and maintenance alerts. The value comes from joining vehicle data with people's workflows, not from the GPS dot on a map.

    Why it matters for builders: fleets are where IoT stopped being a pilot a long time ago. If you are building a vertical product for, say, landscaping crews or refrigerated delivery, you are more likely to integrate with a telematics platform's API than to build your own hardware. That makes the integration and API layer the real product.

    3

    Predictive Maintenance

    catching the pump before it fails

    Deployment: Siemens Senseye at Sachsenmilch Leppersdorf, a German dairy plant that processes roughly 4.6 million liters of milk a day. Siemens' published reference says the plant added vibration sensors and the SIPLUS CMS1200 condition monitoring system, fed into Senseye Predictive Maintenance, with the project completed in 2024. Siemens reports cost savings "in the lower six figures" and fewer unplanned failures. That is Siemens' own account of its own customer, and the reference does not publish the baseline or the method.

    What the app does:it ranks machines by how unusual their behavior is and tells a maintenance planner which ones to look at this week. The hardest design problem isn't the model. It's trust. A planner who gets three false alarms stops opening the app.

    Why it matters for builders: industrial buyers want the alert inside the system they already use, usually a maintenance or ERP tool. Expect to spend as much time on work order integration as on the monitoring itself.

    4

    Precision Agriculture

    a farm run from a phone

    Deployment: John Deere Operations Center. Deere's Business Impact Report 2025 lists about 1 million connected machines, nearly 500 million engaged acres, 147 million highly engaged acres and about 409,000 unique monthly active digital users. Deere defines "engaged acres" itself, so read those as Deere's own usage measures rather than audited market data. The same report sets a target of 600 million engaged acres by 2030.

    What the app does: Operations Center is the place where machine data (where the planter went, how much seed went down) meets agronomic data (yield, soil, prescriptions). A grower plans in the office, the tractor executes in the field, and the results come back to the same map.

    Why it matters for builders: the ratio is striking. Divide 409,000 users by 1 million machines and you get about 0.4 digital users per connected machine. Most connected machines are not managed by someone actively in the app every month. For an ag startup, that says the win may be integration into the platform farmers already use, not another app.

    5

    Smart Home Control

    Matter makes the app less of a fight

    Deployment: Matter, the Connectivity Standards Alliance standard. In November 2025 the CSA released Matter 1.5, adding cameras over WebRTC, a unified model for closures such as shades, gates and garage doors, soil sensors and wider energy data features.

    What the app does:for a device maker, the Matter app often shrinks to setup, firmware updates and the features that go beyond the standard. Everyday control can happen in Apple Home, Google Home or Alexa. That's the trade. Less code to maintain, but less time with your customer inside your app.

    Why it matters for builders:a smart home brand in 2026 has to decide early whether its app is the main interface or a companion. I'd usually pick companion plus one thing the ecosystems can't do well, such as detailed energy history or multi-home management.

    6

    Cold Chain Monitoring

    vaccines that tell you they are warm

    Deployment: vaccine storage in the US Vaccines for Children program. The American Academy of Pediatrics' vaccine storage guidance tells practices to use digital data loggers with buffered probes, with a primary and a backup logger for VFC vaccines, following the CDC Vaccine Storage and Handling Toolkit. Every participating clinic is, in effect, running a small IoT deployment.

    What the app does: it turns a logger into a phone call at 2 a.m. when the fridge fails, and into an audit trail when the state program asks for temperature records. The alert is the product. The log is the compliance.

    Why it matters for builders: food is the next big cold chain driver, but on a longer clock than many vendors imply. The FDA Food Traceability Rule now has a compliance date of July 20, 2028, after Congress directed FDA not to enforce it before then. Traceability records are not the same as temperature monitoring, but the two tend to get bought together.

    7

    Smart Meters

    the utility's app in your pocket

    Deployment: PSE&G in New Jersey. In July 2021 Landis+Gyr announced a 10-year agreement to supply PSE&G with 2.3 million advanced meters, network infrastructure and software on its Gridstream Connect platform, with installation planned over about four years.

    What the app does: for customers, near daily usage data, outage status and bill forecasts. For the utility, remote reads and connect or disconnect, which removes truck rolls. The meter network is the IoT part. The customer app is where the utility gets its credit or its complaints.

    Why it matters for builders: utilities move slowly and buy through long contracts, so the opening for most app teams is on top of the data: energy management apps, landlord tools and solar or battery apps that use meter data through utility programs.

    8

    Item and Asset Tracking

    networks of other people's phones

    Deployment: Apple AirTag and Amazon Sidewalk. On January 26, 2026 Apple introduced a new AirTag with a second-generation Ultra Wideband chip, which Apple says extends Precision Finding up to 50% farther. Amazon took a different route: in March 2023 it opened Sidewalk to outside developers and said the network, built from Echo and Ring devices sharing a little bandwidth over Bluetooth and 900 MHz LoRa, covered 90% of the US population. Both figures are the companies' own claims.

    What the app does: the tracker is nearly dumb. The finding network is the product, and the app is the interface to it. For business asset tracking, the same pattern shows up with tags on pallets, tools and trailers.

    Why it matters for builders:tracking products carry an obligation most founders miss: unwanted tracking. Any tracker that works on a crowd network has to think about stalking alerts and how a person discovers a tag they didn't consent to. Build that in from the first spec.

    9

    Smart Locks and Building Access

    the phone as the key

    Deployment: Level Lock Pro, sold through Apple with Matter support and Apple home keys, so a key in Apple Wallet on an iPhone or Apple Watch opens the door. The same pattern powers employee badges in Wallet for offices and campuses.

    What the app does: issue keys, share them for a time window, revoke them, and show who came in when. For a property manager or a short-term rental host, the key sharing flow is the business, and the lock is the endpoint.

    Why it matters for builders: wallet keys are native platform features. This is one area where I push clients toward native iOS development for the access piece, even if the rest of the product is cross-platform, because the entitlements and Wallet integration are platform specific. And the failure mode is physical: someone locked out in the rain. Design the offline and battery-dead path first.

    10

    Connected Fitness

    where wellness meets the FDA

    Deployment: WHOOP, and the line it ran into. On July 14, 2025 the FDA sent WHOOP a warning letter saying its Blood Pressure Insights feature was a device being marketed without clearance, because estimating blood pressure is tied to diagnosing hypertension. WHOOP publicly disputed that reading and said the feature was about wellness and performance.

    What the app does:in connected fitness the wearable collects, and the app interprets: sleep, strain, recovery, trends. The interpretation is where the value is, and it's also where the regulatory risk is. Words like "detect", "diagnose" and "monitor your condition" move a product toward device territory.

    Why it matters for builders:write your feature copy with the same care as your code. I'm not a regulatory lawyer, and this isn't legal advice, but I tell every health wearable client to get a regulatory opinion on the claims before launch, not after the letter.

    The Ten Side by Side

    Read across the table and one pattern stands out: the higher the regulatory weight, the more the app becomes part of the product's safety case.

    #Use caseNamed deploymentRadio / linkWhat the app doesRegulatory weight
    1Glucose monitoringDexcom Stelo; FreeStyle Libre 2 and 3Bluetooth LEShows readings, alerts, shares dataHigh: FDA cleared devices
    2Fleet telematicsSamsara at EstesCellular gatewaysLocation, safety video, maintenanceMedium: driver privacy, ELD rules
    3Predictive maintenanceSiemens Senseye at SachsenmilchPlant network, vibration sensorsFlags anomalies, raises work ordersLow to medium: plant safety
    4Precision agricultureJohn Deere Operations CenterCellular from machinesField maps, machine data, planningLow: data ownership terms
    5Smart home controlMatter certified devicesThread, Wi-Fi, Bluetooth for setupPairing, scenes, remote controlMedium: PSTI, CRA, Cyber Trust Mark
    6Cold chain monitoringVFC vaccine storage with data loggersWi-Fi or cellular loggersTemperature alarms, audit logsHigh: program rules
    7Smart metersPSE&G with Landis+GyrUtility mesh networkUsage display, outage and billing dataHigh: utility regulators
    8Item and asset trackingApple AirTag; Amazon SidewalkUWB, Bluetooth, LoRaFind, alert, share locationMedium: anti-stalking duties
    9Smart locks and accessLevel Lock Pro with Apple home keysBluetooth, NFC, ThreadKeys, sharing, access logsMedium: physical safety
    10Connected fitnessWHOOP and the FDA warning letterBluetooth LETrends, coaching, health insightsMedium to high: wellness line

    The radio column matters more than it looks. Six of the ten rely on Bluetooth for at least part of the job, usually setup or the phone link. Bluetooth is also the single biggest source of support tickets in the connected apps I've worked on, because every OS release changes something about background permissions and reconnection.

    The other pattern: in half the rows, the most valuable user isn't the device owner. It's the dispatcher, the maintenance planner, the utility, the property manager. The consumer app is sometimes the smaller product.

    Which of the ten pays back fastest? The ones where a single missed event is expensive and easy to count. A ruined refrigerator of vaccines, a stopped filling line, a trailer that went missing. In those, the app replaces a person walking around with a clipboard, and the arithmetic is short: cost of one event times events avoided, against the price of the software.

    The slowest are the consumer ones, and that surprises people. A smart home app rarely earns money directly. It's a feature that sells the hardware and keeps returns down, so its payback shows up as fewer support calls and better reviews, which are real but hard to put in a spreadsheet. Fitness and tracking sit in between, because a subscription can ride on top of the device.

    Why does this matter before you build? Because it changes what you optimize. An industrial app should be judged on how few alerts it sends that turn out to be wrong. A consumer device app should be judged on how quickly a new owner gets from the box to a working device. Those are different products even when the radio and the cloud look the same.

    One more reading of the table. The regulated rows (glucose, cold chain, meters) have something in common beyond rules: someone else already defined what a good outcome looks like. The FDA, a state vaccine program, a utility commission. That makes those products slower to launch and easier to sell, because the buyer already knows what they're buying. The unregulated rows have to invent their own definition of success, which is freedom and a trap at the same time.

    Security Rules in Force

    As of September 29, 2026, two connected product security regimes are binding law (the UK PSTI regime and the first phase of the EU Cyber Resilience Act), and the main US label is still being set up.

    Rule or standardWhereStatus on September 29, 2026What it asks of an app team
    Cyber Resilience Act (EU) 2024/2847EU marketIn force since Dec 10, 2024; reporting from Sep 11, 2026; main obligations Dec 11, 202724 hour early warning, 72 hour notification, vulnerability handling, secure updates
    UK PSTI regimeUK marketIn force since Apr 29, 2024No default passwords, published reporting route, stated update period
    ETSI EN 303 645Standard, used worldwidePublished European standardBaseline provisions for consumer IoT
    NIST IR 8259 seriesUS guidanceFinal NIST guidance, voluntaryDevice identity, configuration, data protection, update, customer information
    US Cyber Trust MarkUS, voluntary labelAdministrators being approved; no labelled product foundTesting against FCC criteria once applications open

    EU Cyber Resilience Act. Regulation (EU) 2024/2847 entered into force on December 10, 2024. Its first obligations landed on September 11, 2026. From that date, per the European Commission's CRA reporting page, manufacturers must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform: an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days of a fix being available (one month for severe incidents). The Commission says the platform became operational on September 11, 2026.

    The detail that catches people: the reporting duty covers products already on the market, not just new ones. The main product requirements, including secure by design duties and conformity assessment, apply from December 11, 2027. The EU's Digital Omnibus proposal aims to merge incident reporting channels across NIS2, GDPR, the CRA and other laws into a single entry point. As of today it's a proposal, and I found nothing showing it moved either CRA date.

    UK PSTI. The UK's product security regime has been in force since April 29, 2024. It bans universal and easily guessable default passwords, requires a published way to report security issues, and requires manufacturers to state the minimum period they will provide security updates. It's short, and it's law.

    ETSI EN 303 645 and NIST IR 8259. ETSI EN 303 645 is the consumer IoT baseline standard that the UK rules draw on; its thirteen provisions cover passwords, vulnerability disclosure, updates, secure storage and secure communication. In the US, NIST's NISTIR 8259A defines a core baseline of device capabilities (identity, configuration, data protection, logical access, software update and cybersecurity state awareness). Both are voluntary on their own. Both are the practical checklist most regulators and big buyers point at.

    US Cyber Trust Mark. This one needs the most care, because its status changed several times. UL Solutions was the program's lead administrator until it withdrew on December 19, 2025, after FCC Chairman Brendan Carr opened an investigation into its ties to China, including testing labs there. The FCC ran an application window in January 2026 and named the ioXt Alliance lead administrator effective April 13, 2026. On August 11, 2026 the FCC's Public Safety and Homeland Security Bureau conditionally approved label administrators and opened a new filing window.

    What I could not find is any announcement that a product actually carries the mark. So the precise status is: voluntary program, created, administrators being approved, no labelled product I could confirm as of September 29, 2026. The FCC's program page is the place to re-check, though it blocks automated readers.

    Borrowed concept: the building code, not the inspection sticker.A house is safe because it was built to code, not because it has a sticker on the door. The Cyber Trust Mark is a sticker, and it isn't even printing yet. ETSI EN 303 645, NIST IR 8259, PSTI and the CRA are the code. Build to the code now, and the sticker becomes paperwork later rather than a redesign.

    For app teams, the practical translation is short. No shared default credentials. Signed firmware and app updates with a rollback path. A published vulnerability disclosure page with a named owner. A stated support period. And, for anything reaching the EU, a written plan for who files the 24 hour early warning. If you want an outside view of where your product stands, that's what our security audit engagements check against.

    What We Have Built

    Our clearest connected device project is LIVV Audio, a Bluetooth Low Energy headphone platform, which is use case 8's cousin: a small device whose value is exposed through an app.

    In the LIVV Audio build, we shipped a Swift iOS app using CoreBluetooth and a Kotlin and Java Android app, a NestJS backend and a React admin dashboard. The case study describes two paths: a local BLE path for latency-sensitive work such as playback, volume, battery level and live equalizer changes, and a cloud path for accounts, preference sync and a device registry. The phone talks to the headphones directly; the server only remembers.

    That split is the lesson I'd carry into any of the ten use cases above. Anything a person expects to happen instantly, or with no signal, goes over the local link. Anything that needs history, sharing or another device goes through the backend. When teams blur that line, the app freezes in a parking garage.

    The case study also lists BLE reliability as the recurring challenge, handled through extensive device testing and defensive coding. That matches everything I've seen since: the radio layer is where schedules slip. It's also why LIVV went native on both platforms, and why for BLE-heavy work I lean toward native Android development and iOS over a shared codebase. For lighter device apps, a cross-platform framework with native modules is fine; we compared the options in our ranking of hybrid app frameworks.

    To be clear about scope: LIVV is consumer audio, not a medical, utility or industrial deployment. I cite it for the architecture, not as evidence that we've shipped every use case on this list. We haven't.

    A Worked Example

    A worked example, framed as a scenario, not a client result: a regional pediatric group deciding whether a temperature monitoring app is worth building or buying.

    Consider a group with 8 clinics, each with one vaccine refrigerator. Per the AAP guidance above, each unit needs a primary and a backup digital data logger for VFC vaccines, so the group has 16 loggers already. The question isn't whether to monitor. It's whether anyone gets told in time.

    Suppose the group's own records show one overnight refrigerator failure per clinic every two years. That's 8 clinics divided by 2 years, or about 4 excursions a year across the group. The cost of each one is whatever that fridge held plus staff time and rescheduled visits. I won't put a dollar figure on that, because it depends entirely on the group's inventory, and any number I printed would be invented. The group should pull its own last inventory count.

    Now the arithmetic that decides it. If off-the-shelf loggers with cloud alerts already call a manager's phone, the build case is weak: buy, and spend the money on a written response plan. If the group also needs the alerts joined to its scheduling system, so affected patients are flagged for revaccination automatically, that's a single workflow integration, and it fits the $28,000 to $70,000 band below.

    Divide that band by the 4 expected excursions a year and you get roughly $7,000 to $17,500 per excursion in the first year, falling after that. If one spoiled refrigerator costs the group more than that, the integration pays. If it costs less, buy the loggers and stop. That's the whole test, and it's the same one I'd run for any of the ten use cases: count the cost of one missed event, count the events, then price the software.

    What Breaks First

    In connected apps, the failures are rarely in the dashboard. They're in pairing, offline behavior, updates and who answers the security inbox.

    What breaksThe signalWhat to do
    Bluetooth reconnectionSupport tickets about pairing after an OS updateTest on the oldest supported phones every release; keep a pairing reset flow
    Offline behaviorBlank screens on a job site or in a basementCache last known state; queue commands; show data age
    Firmware updatesDevices stuck on old versionsSigned images, staged rollout, rollback, version dashboard
    Alert fatigueUsers muting notificationsFewer, ranked alerts; quiet hours; escalation rules
    Backend dependencyDevices useless during an outageLocal control path for core functions
    Vulnerability reportsNobody owns the inboxPublished policy, named owner, CRA timing plan

    The one I'd fix first is updates. A device that can't be patched safely is a liability under every regime in the security section. It's also the reason the CRA's 72 hour clock is scary: if a vulnerability is being exploited and your update path is manual, you'll be reporting a problem you can't fix quickly.

    The second is backend dependency. When a cloud service shuts down, devices that only work through it become bricks, and customers remember. Keep a local control path for the core function, like LIVV's BLE path, even if the fancy features need the server.

    Cost and Timeline

    Our published bands for connected product software run from $9,000 for a discovery audit to $420,000 or more for enterprise and regulated builds. Firmware and hardware certification are separate.

    EngagementRangeTimelineFits
    Discovery and audit$9k to $22k2 to 4 weeksChoosing the use case, radio and rules that apply
    Single-workflow build$28k to $70k4 to 9 weeksOne device, one app, one alert path
    Multi-workflow platform$70k to $180k9 to 16 weeksCompanion app plus console plus integrations
    Enterprise or regulated$180k to $420k+14 to 24 weeksHealth, utility or multi-site deployments

    Senior-led time is $150 to $225 an hour, retainers run $2,500 to $9,500 a month, and every build gets a 30-day post-launch warranty. Full source code and IP transfer to you, and we send a fixed-price phased proposal within 5 business days of discovery. We don't hold SOC 2, ISO 27001 or HITRUST attestations; if your buyer requires one from the vendor, factor that in.

    Whether you hire an agency, a consultant or a freelancer for this matters more for IoT than for most apps, because the work crosses firmware, mobile and cloud. We laid out the trade-offs in consultant vs agency vs freelancer.

    Red Flags

    Walk away from an IoT proposal that can't answer, in writing, how updates are signed, what happens offline, and who handles vulnerability reports.

    • No offline story: If the answer to 'what if there is no signal' is 'it shows an error', the app will fail where devices live.
    • Market size in the pitch: A proposal that opens with a trillion-dollar IoT market figure is selling the category, not your product.
    • Shared default credentials: Illegal for consumer products in the UK since April 2024 and against every baseline standard.
    • Certification promises: Nobody can promise a US Cyber Trust Mark today; ask what standard they build to instead.
    • Vendor cloud lock-in: If you don't own the cloud accounts and code, you don't own the product.
    • Wellness copy that diagnoses: Feature text that says detect or diagnose without a regulatory opinion behind it.

    What I Could Not Verify

    Several numbers that dominate IoT articles are missing here on purpose, because I couldn't trace them to a method.

    The big ones are the device counts and market sizes: tens of billions of connected devices, trillion-dollar markets, fixed percentages of pilots that fail. They circulate in different versions with different totals, usually from analyst firms whose method sits behind a paywall or from vendors quoting each other. I don't print them, and I'd be wary of a proposal that leans on them.

    I also refused a few specific claims. I couldn't find a named, sourced cold chain deployment from a monitoring vendor with published results, so use case 6 rests on public health guidance rather than a vendor case study. Siemens' "lower six figures" saving at Sachsenmilch is Siemens' own statement with no baseline. Samsara's customer list and Deere's engaged acres are the companies' own measures. Amazon's 90% Sidewalk coverage figure dates from 2023 and I found no newer independent measurement.

    On the Cyber Trust Mark, the FCC's own pages block automated readers, so the August 11, 2026 administrator update is cited from the FCC listing as surfaced in search and from trade press. I found no product carrying the mark, but absence from search results isn't proof. Re-check before relying on it. And the PSE&G contract is from 2021; I did not confirm how many of the 2.3 million meters are installed today.

    Three Things This Week

    If you're planning a connected product, three steps before you spend on anything else.

    • 1. Write the decision, not the sensor: One sentence: who gets told what, and what they do next. If you can't write it, you aren't ready to build.
    • 2. Count one missed event: Price a single failure (spoiled stock, a stopped line, a lockout) from your own records, and how often it happens.
    • 3. Map your markets to the rules: EU means CRA reporting now; UK means PSTI now; US means NIST IR 8259 as your checklist. Put a named owner on vulnerability reports.

    Then build the smallest version that closes that one loop. Everything else can wait.

    Planning a Connected Device App?

    Book a discovery call. We map the device, the radio, the backend and the rules that apply, and send a fixed-price phased proposal within 5 business days.

    1517 S Bentley Ave Apt 204, Los Angeles CA 90025

    Frequently Asked Questions

    Sources & References

    1. 1FDA, FDA clears first over-the-counter continuous glucose monitor (Dexcom Stelo, March 5, 2024)↗
    2. 2Abbott press release via Nasdaq, FDA clears FreeStyle Libre 2 and 3 sensors for integration with automated insulin delivery (March 6, 2023)↗
    3. 3Samsara, Q4 and fiscal year 2026 results (March 5, 2026)↗
    4. 4Siemens, Sachsenmilch Leppersdorf reference: Senseye Predictive Maintenance↗
    5. 5Deere & Company, Business Impact Report 2025↗
    6. 6EE Journal, Matter 1.5 introduces cameras, closures and enhanced energy management (CSA announcement, November 2025)↗
    7. 7American Academy of Pediatrics, vaccine storage and handling (digital data loggers, CDC toolkit)↗
    8. 8FDA, FSMA Food Traceability Rule page (compliance date July 20, 2028)↗
    9. 9POWER, Landis+Gyr and PSE&G sign contract for advanced metering deployment (July 2021)↗
    10. 10Apple Newsroom, Apple introduces new AirTag with expanded range and improved findability (January 26, 2026)↗
    11. 11Light Reading, Amazon opens Sidewalk network to outside developers (March 28, 2023)↗
    12. 12Apple Store, Level Lock Pro (Matter) with Apple home keys support↗
    13. 13FDA, warning letter to WHOOP, Inc. (July 14, 2025)↗
    14. 14Cybersecurity Dive, FCC IoT labeling program loses lead company after China probe↗
    15. 15Nextgov/FCW, FCC selects ioXt Alliance to lead cyber labeling program (April 13, 2026)↗
    16. 16FCC, U.S. Cyber Trust Mark program page (blocks automated readers)↗
    17. 17FCC, PSHSB conditionally approves Cybersecurity Label Administrators and opens filing window (August 11, 2026; blocks automated readers)↗
    18. 18European Commission, Cyber Resilience Act reporting obligations↗
    19. 19Freshfields, CRA reporting obligations take effect on 11 September 2026↗
    20. 20GOV.UK, the UK PSTI product security regime↗
    21. 21NIST CSRC, NISTIR 8259A IoT Device Cybersecurity Capability Core Baseline↗
    22. 22CNX Software, ETSI releases EN 303 645 IoT security standard for consumer devices↗
    Chris Machetto - CEO & Founder, Frenchy Digital of Frenchy Digital

    Chris Machetto

    CEO & Founder of Frenchy Digital. Building apps and digital products since 2016 for startups and enterprises across LA, San Francisco, Paris, Geneva, and more globally.