Search papers, labs, and topics across Lattice.
This paper introduces CERTIoT-6G, a Security-as-a-Service framework designed for automated cybersecurity certification and continuous compliance monitoring of IoT devices in 5G and 6G networks. By integrating automated compliance analysis, real-time traffic monitoring, and adversarial testing, the framework addresses the limitations of traditional static certification methods, which struggle to scale in diverse IoT environments. Evaluation on an advanced 5G testbed highlights critical compliance gaps, particularly in traffic encryption and availability, while demonstrating minimal impact on live network traffic.
Critical compliance gaps in IoT device security were uncovered, revealing vulnerabilities in traffic encryption and availability that could jeopardize future 5G and 6G networks.
The massive adoption of Internet of Things (IoT) devices across critical domains such as healthcare, smart cities, industrial automation, and critical infrastructure introduces significant cybersecurity and regulatory challenges. Current and forthcoming European regulations, including the Cyber Resilience Act (CRA) and the NIS2 Directive, require manufacturers, operators, and other organizations to ensure secure-by-design devices, continuous vulnerability management, and resilient operation throughout the device lifecycle. Traditional certification mechanisms remain static, manual, and difficult to scale across heterogeneous IoT ecosystems. This paper presents CERTIoT-6G, a Security-as-a-Service (SECaaS) framework that enables automated cybersecurity certification and continuous compliance monitoring of IoT devices operating in 5G and future 6G networks. The framework integrates automated compliance analysis, real-time traffic monitoring, and adversarial testing capabilities. We validate the CERTIoT-6G framework on different IoT device categories operating in an advanced 5G testbed. Evaluation results reveal critical compliance gaps, particularly in traffic encryption and availability under unstable conditions, and demonstrate that the framework produces actionable verdicts mapped to regulatory requirements across heterogeneous device types. Furthermore, we show that the monitoring pipeline has a negligible impact on live 5G traffic.