CERTIoT-6G: Continuous Cybersecurity Certification for IoT Devices in 5G/6G Networks
2026-08-24 • Networking and Internet Architecture
Networking and Internet ArchitectureCryptography and Security
AI summaryⓘ
The authors address security problems caused by many Internet of Things (IoT) devices used in important areas like healthcare and smart cities. They created CERTIoT-6G, a system that automatically checks if these devices follow European security rules and keeps an eye on them while they work in 5G and future 6G networks. They tested their system on different IoT devices and found important security issues, especially with traffic encryption and how devices handle unstable network conditions. Their system gives clear feedback linked to the rules and does not slow down the network.
Internet of Things (IoT)Cybersecurity5G networks6G networksCyber Resilience Act (CRA)NIS2 DirectiveSecurity-as-a-Service (SECaaS)Compliance monitoringTraffic encryptionVulnerability management
Authors
Evangelos Lempesis, Fabio Palmese, Hamed Haddadi, Anna Maria Mandalari
Abstract
The massive adoption of Internet of Things (IoT) devices across critical domains such as healthcare, smart cities, industrial automation, and critical infrastructure introduces significant cybersecurity and regulatory challenges. Current and forthcoming European regulations, including the Cyber Resilience Act (CRA) and the NIS2 Directive, require manufacturers, operators, and other organizations to ensure secure-by-design devices, continuous vulnerability management, and resilient operation throughout the device lifecycle. Traditional certification mechanisms remain static, manual, and difficult to scale across heterogeneous IoT ecosystems. This paper presents CERTIoT-6G, a Security-as-a-Service (SECaaS) framework that enables automated cybersecurity certification and continuous compliance monitoring of IoT devices operating in 5G and future 6G networks. The framework integrates automated compliance analysis, real-time traffic monitoring, and adversarial testing capabilities. We validate the CERTIoT-6G framework on different IoT device categories operating in an advanced 5G testbed. Evaluation results reveal critical compliance gaps, particularly in traffic encryption and availability under unstable conditions, and demonstrate that the framework produces actionable verdicts mapped to regulatory requirements across heterogeneous device types. Furthermore, we show that the monitoring pipeline has a negligible impact on live 5G traffic.