Trusted IoT device onboarding for critical networks using standards-based trust infrastructure
UK technology inside the US standard for trusted IoT device onboarding.
The Challenge
When an IoT device joins a network, both sides are flying blind: the network cannot verify what the device is or whether its security posture is acceptable, and the device cannot verify it is joining a legitimate network. This missing “handshake of trust” at the network layer is a root cause of IoT compromise at scale, and it is the problem the US NIST National Cybersecurity Center of Excellence (NCCoE) set out to solve in its Trusted IoT Device Network-Layer Onboarding and Lifecycle Management project.
The Solution
NQM joined the NCCoE effort as a collaborating vendor in a standards-driven collaboration spanning the USA and Canada. NQM contributed a complete build (Build 5) demonstrating trusted IoT device network-layer onboarding, supplying both the onboarding infrastructure and the IoT devices used in it, alongside co-build collaborators including Sandelman Software Works and SEALSQ (a WISeKey subsidiary) and industry participants such as HPE/Aruba, CableLabs and Kudelski IoT. The work was supported through the IoT Security Foundation’s ManySecured working group, defining data structures and protocols to assess a device’s security posture before onboarding and continuously thereafter.
Outcomes
The headline output is NIST Special Publication 1800-36, Trusted Internet of Things (IoT) Device Network-Layer Onboarding and Lifecycle Management (final published 25 November 2025), of which NquiringMinds staff — Nick Allott, Alexandru Mereacre and Ashley Setter — are recognised co-authors. NQM implementations were presented at the NCCoE IoT Open House in Washington DC, drawing interest from NIST and US CISA.

Features
Full working build (Build 5) of trusted IoT network-layer onboarding at the NCCoE, including NQM-supplied IoT devices.
Pre-onboarding checks and ongoing lifecycle monitoring.
Data structures and protocols for device trust claims, developed via the IoTSF ManySecured working group.
A UK SME as recognised co-author of a US NIST Special Publication, with its technology embodied in a reference build.
Benefits
Co-authors Nick Allott, Alexandru Mereacre, Ashley Setter; NQM provided the network-layer onboarding infrastructure and IoT devices for Build 5.
Reducing onboarding compromise risk across critical networks (published guidance; adoption impacts projected).
NQM implementations presented at the NCCoE IoT Open House (Washington DC, April 2025); interest from NIST and US CISA.
Credibility bridge from UK NCSC-sponsored router work to US federal cyber security guidance.

