IoT Security Foundation
- Company typePrivate
- Founded2015
- HeadquartersLivingston, United Kingdom
- Headcount1–10
- GTM typeB2B
- OfferingServices
IoT Security Foundation firmographics
Firmographics- Name
- IoT Security Foundation
- Legal name
- IoT Security Foundation
- Website
- https://iotsecurityfoundation.org
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Ownership category
- akta.pro rank
IoT Security Foundation industry classification
Industry- Product category
- IoT Security Standards and Best Practices
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- IoT Vulnerability Assessment, Penetration Testing & Risk Audits (HSAHAJAC)
- akta.pro secondary industries
- Smart Home Device & Hub Hardening Services (HSAHAJAA), Secure Configuration, Firmware/Software Update & Patch Management (HSAHAJAD), Privacy, Data Protection & Identity/Account Security for Smart Home Ecosystems (HSAHAJAF), Threat Monitoring, Intrusion Detection & Incident Response for Smart Home (HSAHAJAE)
Keywords
Where IoT Security Foundation is headquartered
LocationHeadquarters
- HQ city
- Livingston
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
IoT Security Foundation business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- Membership Fees: Annual membership providing access to guidance documents, working groups, chapters, events, networking, and member-only assets like compliance questionnaire tools. Described as 'significant value at low cost'.
- Conference Revenue: Annual conference with ticket sales, sponsorship packages, and exhibition opportunities. 2026 exhibitor packages start from £1,750 GBP.
- Training Courses: IoT security training courses covering product security from design through deployment. Course attendees receive certificate of completion and access to training alumni platform.
- Sponsorship Packages: Sponsorship opportunities at annual conferences including Platinum Headline Sponsor, Gold Track Sponsor, Networking Reception Sponsor, Silver and Bronze Sponsorships, plus lanyard, registration, tote bag and summit guide branding opportunities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Unit Pricing | One time/ perpetual license | Conference exhibitor packages |
| Freemium | Pay-as-you-go | Best Practice User Mark |
| Freemium | Pay-as-you-go | Publications and guidance documents |
Go-to-market motion2 records
Distribution channels6 records
Marketing channels9 records
IoT Security Foundation product offering
Product offeringCore offering
The IoT Security Foundation is a global not-for-profit membership association that provides IoT cybersecurity best-practice frameworks, guidance documents, self-certification, training, conferences, and working-group collaboration to help IoT vendors, integrators, and regulators adopt fit-for-purpose security. Its flagship IoT Security Assurance Framework (Release 4.0) is delivered as both a downloadable PDF and an interactive online tool, supported by the Best Practice User Mark certification badge and a portfolio of consumer-IoT quick guides, secure-design guides, and vulnerability-disclosure guidelines.
Product overview
IoT Security Foundation is a global, not-for-profit membership association that provides a comprehensive portfolio of IoT security guidance, frameworks, and tools. The core offering is the IoT Security Assurance Framework (available as interactive online tool and downloadable PDF), which helps IoT vendors achieve fit-for-purpose security through a risk management process. This is supported by complementary products including the Best Practice User Mark (a self-certification badge), Consumer IoT Security Quick Guides and webinars on topics like password management and vulnerability disclosure, Secure Design Best Practice Guides, Vulnerability Disclosure Best Practice Guidelines, and IoT Security Training Courses. The foundation also organizes the annual IoTSF Conference (the world's longest-running IoT security conference since 2015), manages the ManySecured Project for AI-powered router security, and has launched the Security by Demand initiative to drive market demand for secure products. Publications include annual Vulnerability Disclosure reports tracking industry progress.
Differentiator
Problem solved
Functional benefit
Products and services
- IoT Security Assurance Framework A pre-compliance, multi-faceted framework that helps IoT vendors provide fit-for-purpose security in their products and services. Acts as a guide, tool, and expert reference, leading users through a risk management process to determine security objectives and collect evidence demonstrating security claims. Available as downloadable PDF and interactive online version at af.iotsf.org.
- Best Practice User Mark (Self-Certification) A free self-certification badge organizations can display on marketing materials, websites, email footers, and product packaging to demonstrate commitment to IoT security best practices following IoTSF guidance and the Assurance Framework.
- Consumer IoT Security Quick Guides Free quick reference guides helping global organisations understand and comply with international standards, regulations, and national guidance on consumer IoT security, covering password management, software updates, and vulnerability reporting.
- Consumer IoT Security On-Demand Webinars On-demand training webinars delivered by IoTSF security experts covering consumer IoT cybersecurity topics including password management, software updates, and vulnerability reporting.
- Secure Design Best Practice Guides Pragmatic and easily consumable guides for companies with limited security knowledge, covering the most common issues affecting product, service, and user security; targeted at new companies and those adding connectivity to products.
- Vulnerability Disclosure Best Practice Guidelines Guidelines helping companies make provision for third parties to contact them regarding security vulnerabilities discovered in their systems, supporting coordinated vulnerability disclosure (CVD) processes while preserving customer privacy and safety.
- IoT Security Training Courses Paid in-person and virtual training courses covering how to secure a connected IoT product from scratch, including Foundation of IoT Security courses. Attendees receive certificates of completion and access to a training alumni platform.
- Annual IoTSF Conference The world's longest-running conference dedicated to IoT security, delivering cutting-edge insights since 2015. Features hardware security, post-quantum technology, regulation, supply chain management, and AI in defence topics, with ticket sales and sponsorship packages.
- ManySecured Project A collaborative project developing AI for Cognitive Security focused on routers and gateways which have a unique defensive position in IoT networks; develops open standards for next-generation router and gateway security.
Quantifiable outcome
- 40.53% of 491 manufacturers now provide vulnerability disclosure contact methods (2025), up from 35.59% in 2024, showing measurable improvement in IoT security practices due to awareness and regulatory pressure.
- +3 more outcomes
Companies that use IoT Security Foundation
Customer profileNamed customers7 records
Segments6 records
Ideal customer profiles5 records
IoT Security Foundation technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
IoT Security Foundation partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered core and minor.
- TechWorkscoreParent organization of IoTSF. TechWorks is celebrating its 30th anniversary in 2026. IoTSF conference is co-located with TechWorks events including NMI, AESIN, TechWorks-AI, and DESN sessions. TechWorks provides organizational infrastructure and umbrella for deep tech industry associations.
- Copper Horse LtdcoreAnnual co-publisher of 'The State of Vulnerability Disclosure Policy Usage in Global Consumer IoT' report series, now in its 8th edition. Provides research methodology and analysis for longitudinal tracking of vulnerability disclosure practices in consumer IoT sector.
- ManySecuredcoreCollaborative project on next-generation router and gateway security. IoTSF references ManySecured as initiative developing collaborative AI for Cognitive Security. ManySecured whitepaper on router vulnerabilities published through IoTSF resources.
- CHERI AlliancecoreTechWorks/IoTSF is a founding member of the CHERI Alliance. CHERI (Capability Hardware Enhanced RISC Instructions) technology provides hardware-based memory safety solutions for IoT devices and routers. IoTSF publishes research on CHERI-based secure networking infrastructure.
- IET (Institution of Engineering and Technology)minorVenue partner for annual 2025 IoTSF conference at IET London location.
- The Things ConferenceminorIoTSF is official ecosystem partner of The Things Conference 2026, held at De Kromhouthal, Amsterdam.
- Global IoT CongressminorIoTSF is official event supporting partner of Global IoT Congress 2026 (GIC26) in Riyadh, Saudi Arabia.
- AESIN (Automotive Electronic Systems Innovation Network)coreIoTSF partnered organization for automotive security conference addressing automotive electronics security, connectivity, and cybercrime. Co-locates events with AESIN for cross-industry collaboration.
- ThalesminorHosted and sponsored the AESIN Automotive Security Conference 2017 partnered with IoTSF.
- Digital CatapultminorUK innovation center hosting IoTSF Plenary Session 12 in 2017 for members and invited guests.
- IoTSF Chapter OrganizationsminorLocal chapter organizations including Bangalore Chapter, with call for interest in forming additional chapters globally to extend IoTSF reach and activities regionally.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
IoT Security Foundation competitors and assessment
Company assessmentDirect peers
- ETSI (European Telecommunications Standards Institute): European standards body whose EN 303 645 consumer IoT security standard directly informs IoTSF's Quick Guides and frameworks. Both organisations publish guidance that vendors rely on for compliance, and ETSI is a peer in shaping global IoT security norms.
- GSMA: Mobile industry organisation that produces IoT security guidelines (e.g., NESAS, IoT Security Assessment) targeting connected devices and networks. Comparable to IoTSF in providing cross-industry security guidance and assessment frameworks for IoT stakeholders.
- OWASP Foundation: Non-profit cybersecurity community producing widely adopted free guidance (e.g., OWASP IoT Top 10). Closely parallels IoTSF's vendor-neutral, free-publication model and its role as a global convener for security practitioners.
- Cloud Security Alliance (CSA): Non-profit that produces free security best-practice frameworks, certifications, and research, supported by membership and events. Mirrors IoTSF's model of monetising membership, events, and training while distributing core guidance for free.
- ISACA: Global professional association offering cybersecurity/IoT credentials, training, and guidance to practitioners and enterprises. Comparable in operating a membership-and-events monetisation model around professional security education.
- (ISC)²: Non-profit cybersecurity professional body offering certifications, training, and thought-leadership. Similar to IoTSF in monetising training and certifications while advancing vendor-neutral security practice globally.
Broad incumbents
- ENISA (European Union Agency for Cybersecurity): EU agency that publishes IoT cybersecurity guidelines, supports the CRA implementation, and convenes stakeholders. A larger, government-backed peer producing overlapping guidance that vendors and regulators reference alongside IoTSF materials.
- NIST (National Institute of Standards and Technology): U.S. government agency publishing widely adopted IoT cybersecurity guidance (e.g., NIST IR 8259, SP 800-183). A broader incumbent with overlapping authority on IoT baseline security that vendors align with alongside IoTSF.
Emerging players
- OpenSSF (Open Source Security Foundation): Linux Foundation-hosted non-profit cross-industry collaboration producing free security tooling, guidance, and frameworks. Comparable as a vendor-neutral, member-funded convener advancing baseline security practices across software supply chains including IoT.
- Connectivity Standards Alliance (CSA / Matter): Industry alliance behind the Matter smart-home standard with its own IoT security certification programme. Comparable because it sets security expectations for IoT product vendors and competes for influence over IoT security assurance frameworks.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights6 records
Customer concentration
IoT Security Foundation social profiles
Digital presenceIoT Security Foundation financial estimates
Financial estimateRevenue estimate
Valuation estimate
IoT Security Foundation leadership team
Management profileNumber of profiles
Profiles2 records
IoT Security Foundation funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
IoT Security Foundation M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about IoT Security Foundation
What does IoT Security Foundation do?
The IoT Security Foundation is a global not-for-profit membership association that provides IoT cybersecurity best-practice frameworks, guidance documents, self-certification, training, conferences, and working-group collaboration to help IoT vendors, integrators, and regulators adopt fit-for-purpose security. Its flagship IoT Security Assurance Framework (Release 4.0) is delivered as both a downloadable PDF and an interactive online tool, supported by the Best Practice User Mark certification badge and a portfolio of consumer-IoT quick guides, secure-design guides, and vulnerability-disclosure guidelines.
Is IoT Security Foundation a public or private company?
IoT Security Foundation is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was IoT Security Foundation founded?
IoT Security Foundation was founded in 2015. It employs 1 to 10 people.
Where is IoT Security Foundation based?
IoT Security Foundation is headquartered in Livingston, United Kingdom, in the Europe region.
How does IoT Security Foundation make money?
Four revenue lines are on record. Membership Fees are the primary driver. The others are conference Revenue, training Courses and sponsorship Packages.
Who are IoT Security Foundation's main competitors?
Direct peers on record are ETSI (European Telecommunications Standards Institute), GSMA, OWASP Foundation, Cloud Security Alliance (CSA), ISACA and (ISC)². Broad incumbents are ENISA (European Union Agency for Cybersecurity) and NIST (National Institute of Standards and Technology). Emerging players are OpenSSF (Open Source Security Foundation) and Connectivity Standards Alliance (CSA / Matter).
Does IoT Security Foundation have an API?
No public API is recorded for IoT Security Foundation.
What industry is IoT Security Foundation in?
IoT Security Foundation's product category is IoT Security Standards and Best Practices. Its primary akta.pro industry code is HSAHAJAC, IoT Vulnerability Assessment, Penetration Testing & Risk Audits, with a secondary code of HSAHAJAA, Smart Home Device & Hub Hardening Services. Its NAICS code is 54151 and its SIC code is 7370.