Jadwal Sholat

Memuat jadwal sholat…

Ilmu Komputer & AI editorial

Open AccessOA2026

CERTIoT-6G: Continuous Cybersecurity Certification for IoT Devices in 5G/6G Networks

A Security-as-a-Service framework for automated certification and continuous compliance monitoring of heterogeneous IoT devices in advanced 5G testbeds
Evangelos Lempesis; Fabio Palmese; Hamed Haddadi; Anna Maria Mandalari· 2026· DOI 10.48550/arXiv.2608.23339

The core problem

The rapid proliferation of Internet of Things (IoT) devices across healthcare, smart cities, industrial automation, and critical infrastructure has created substantial cybersecurity and regulatory challenges. European regulations such as the Cyber Resilience Act (CRA) and the NIS2 Directive now mandate secure-by-design devices, continuous vulnerability management, and resilient operation across the entire device lifecycle. However, traditional certification mechanisms remain static, manual, and poorly suited to scale across heterogeneous IoT ecosystems. This paper introduces CERTIoT-6G, a Security-as-a-Service (SECaaS) framework designed to enable automated cybersecurity certification and continuous compliance monitoring of IoT devices operating in 5G and future 6G networks. The framework combines automated compliance analysis, real-time traffic monitoring, and adversarial testing to produce actionable verdicts mapped to regulatory requirements. The authors validate CERTIoT-6G across different IoT device categories in an advanced 5G testbed, revealing critical compliance gaps—particularly in traffic encryption and availability under unstable conditions—while demonstrating that the

Innovation

Evaluation across different IoT device categories in the 5G testbed reveals significant compliance gaps. The most prominent deficiencies are found in traffic encryption and availability under unstable network conditions. Many devices fail to meet the encryption requirements expected under the CRA and NIS2 Directive, exposing sensitive data in transit. Availability testing further shows that devices often degrade or disconnect when network conditions fluctuate, undermining the resilience mandated by current regulations.

The framework successfully produces actionable verdicts that map each device's behavior to specific regulatory requirements. These verdicts differentiate between compliant and non-compliant devices across heterogeneous types, demonstrating the framework's ability to scale certification efforts. Importantly, the monitoring pipeline introduces negligible impact on live 5G traffic, meaning continuous compliance monitoring can be performed without degrading network performance. The results highlight that static certification alone would miss these dynamic weaknesses, validating the need for continuous, automated assessment.

The rapid proliferation of Internet of Things (IoT) devices across healthcare, smart cities, industrial automation, and critical infrastructure has created substantial cybersecurity and regulatory challenges. European regulations such as the Cyber Resilience Act (CRA) and the NIS2 Directive now mandate secure-by-design devices, continuous vulnerability management, and resilient operation across the entire device lifecycle. However, traditional certification mechanisms remain static, manual, and poorly suited to scale across heterogeneous IoT ecosystems. This paper introduces CERTIoT-6G, a Security-as-a-Service (SECaaS) framework designed to enable automated cybersecurity certification and continuous compliance monitoring of IoT devices operating in 5G and future 6G networks. The framework combines automated compliance analysis, real-time traffic monitoring, and adversarial testing to produce actionable verdicts mapped to regulatory requirements. The authors validate CERTIoT-6G across different IoT device categories in an advanced 5G testbed, revealing critical compliance gaps—particularly in traffic encryption and availability under unstable conditions—while demonstrating that the monitoring pipeline has a negligible impact on live 5G traffic.
CERTIoT-6G is architected as a SECaaS platform that integrates three core capabilities: automated compliance analysis, real-time traffic monitoring, and adversarial testing. The framework operates within 5G and future 6G network environments, where it continuously assesses IoT devices against regulatory requirements derived from the CRA and NIS2 Directive. The monitoring pipeline is designed to observe live traffic without disrupting network performance, while adversarial testing probes device behavior under adverse conditions to uncover weaknesses in encryption and availability.

Why it matters

The findings underscore a fundamental mismatch between static certification regimes and the dynamic threat landscape of IoT in 5G/6G networks. CERTIoT-6G addresses this by shifting certification from a one-time, manual process to a continuous, automated service. The framework's ability to detect encryption and availability gaps in real time provides manufacturers and operators with the evidence needed to meet CRA and NIS2 obligations throughout the device lifecycle.

The negligible monitoring overhead is a critical enabler for adoption, as it removes a common barrier to continuous monitoring in production networks. However, the study also reveals that many current IoT devices are not designed to satisfy emerging regulatory requirements, suggesting that secure-by-design principles are not yet universally implemented. The adversarial testing component adds another layer of assurance by simulating adverse conditions that static audits cannot replicate.

Future work may extend CERTIoT-6G to 6G-specific features such as network slicing and AI-driven resource management, where certification requirements could become even more complex. Overall, the framework represents a practical step toward scalable, regulation-aware cybersecurity certification for heterogeneous IoT ecosystems.

Who should read this

CS practitioners and researchers

Opening member content…