/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Draft EU legislation, set to be unveiled next week, mandates IoT product makers to meet cybersecurity rules or face heavy fines of €15M or 2.5% of turnover

Companies will face fines of €15mn or 2.5% of turnover if they do not comply with cyber security requirements

Financial Times Javier Espinoza

Context & Ripple Effects

This draft is the next step in a decade-long Brussels arc: the EU passed its first cybersecurity law in 2016, imposing security and reporting duties on businesses and forcing member-state cooperation on network security, and the UK followed by fining laggards in critical industries up to £17M under the NIS directive. What changes here is the target — from network operators to the products themselves.

First-order effects

  • IoT and smart-device makers selling into the EU must now treat security as a pre-market requirement, not a patch-after-ship practice, or face fines of €15M or 2.5% of turnover.
  • The penalty structure copies the template floated in the leaked EU AI rules, which set non-compliance fines at €20M or 4% of turnover — signaling Brussels standardizing turnover-based penalties across tech regimes.

Second-order effects

  • Device makers will push security testing and certification costs upstream to component suppliers and downstream into retail prices, reshaping who can profitably sell connected hardware into Europe.
  • The proposal formalized days later as the Cyber Resilience Act gives compliant vendors a marketing wedge against cheaper rivals, pressuring the whole category toward audited-by-default products.

Third-order effects

  • Enforcement credibility is the open question: the EU later chose to impose only minimal fines on Apple and Meta under the DMA, far below its caps, to avoid friction with Washington — if that restraint carries over, the €15M threat may bite selectively rather than uniformly.
  • If the pattern holds, the EU's combined product-security regimes effectively write the default spec for global IoT hardware, since few manufacturers will build separate insecure SKUs for other markets.

The trend: Brussels is extending its regulatory reach from networks and platforms down to individual connected products, using turnover-based fines as the enforcement lever across successive tech laws.

Discussion

  • @vessonsecurity Vess on x
    Oh, good. This will get rid of IoTs in the EU... We apparently won't have electricity for them anyway. https://twitter.com/...
  • @realhamed Hamed Haddadi on x
    EU making an impactful move: “Under the proposed rules, which are expected to become law by 2024, internet of things (IOT) makers need to inform authorities and consumers about attacks and must be able to put in place quick fixes, the proposals state” https://www.ft.com/...
  • @1br0wn @1br0wn on x
    Companies will have to obtain mandatory certificates that show they are meeting the basic requirements of cyber safety that minimise the risk of attacks on IoT devices under draft EU legislation to be published next week https://www.ft.com/...