Ilmu Komputer & AI editorial
CERTIoT-6G: Continuous Cybersecurity Certification for IoT Devices in 5G/6G Networks
The core problem
Innovation
Evaluation across different IoT device categories in the 5G testbed reveals significant compliance gaps. The most prominent deficiencies are found in traffic encryption and availability under unstable network conditions. Many devices fail to meet the encryption requirements expected under the CRA and NIS2 Directive, exposing sensitive data in transit. Availability testing further shows that devices often degrade or disconnect when network conditions fluctuate, undermining the resilience mandated by current regulations.
The framework successfully produces actionable verdicts that map each device's behavior to specific regulatory requirements. These verdicts differentiate between compliant and non-compliant devices across heterogeneous types, demonstrating the framework's ability to scale certification efforts. Importantly, the monitoring pipeline introduces negligible impact on live 5G traffic, meaning continuous compliance monitoring can be performed without degrading network performance. The results highlight that static certification alone would miss these dynamic weaknesses, validating the need for continuous, automated assessment.
Why it matters
The findings underscore a fundamental mismatch between static certification regimes and the dynamic threat landscape of IoT in 5G/6G networks. CERTIoT-6G addresses this by shifting certification from a one-time, manual process to a continuous, automated service. The framework's ability to detect encryption and availability gaps in real time provides manufacturers and operators with the evidence needed to meet CRA and NIS2 obligations throughout the device lifecycle.
The negligible monitoring overhead is a critical enabler for adoption, as it removes a common barrier to continuous monitoring in production networks. However, the study also reveals that many current IoT devices are not designed to satisfy emerging regulatory requirements, suggesting that secure-by-design principles are not yet universally implemented. The adversarial testing component adds another layer of assurance by simulating adverse conditions that static audits cannot replicate.
Future work may extend CERTIoT-6G to 6G-specific features such as network slicing and AI-driven resource management, where certification requirements could become even more complex. Overall, the framework represents a practical step toward scalable, regulation-aware cybersecurity certification for heterogeneous IoT ecosystems.
Who should read this
Opening member content…