2026 Award Winner

2026 IoT Security Excellence Award Winner: Quectel

Engineering Trust Across the Entire IoT Product Lifecycle.

Quectel has been named the winner of the 2026 IoT Security Excellence Award for its Security Capability Infrastructure, an integrated program spanning independent assessment, incident response, vulnerability disclosure, software supply-chain assurance, cryptographic key management, and internationally recognized certification.

Quectel logo
2026 IoT Security Excellence Award winner badge

Why Quectel Won

Quectel earned this recognition for treating product security as a coordinated operational infrastructure rather than a collection of isolated controls. Its approach connects independent testing, structured response, software transparency, cryptographic safeguards, and certified development practices across the full product lifecycle.

Independently Assessed Security

Ongoing source-code auditing, binary analysis, and penetration testing by Finite State provide external scrutiny and measurable validation beyond internal assessment.

Accountable Vulnerability Response

A dedicated PSIRT, formal response process, public disclosure platform, and customer-facing SBOM and VEX resources create a repeatable path from discovery through remediation and disclosure.

Lifecycle-Wide Assurance

Supply-chain monitoring, secret key management, secure development practices, and international certifications extend security across design, manufacturing, deployment, maintenance, and regulatory compliance.

About the Winning Security Infrastructure

Connected products inherit risk from every layer beneath them, including embedded software, third-party components, cryptographic credentials, development processes, and the systems used to respond when new vulnerabilities emerge. Quectel’s Security Capability Infrastructure addresses that reality by coordinating security activities across the complete lifecycle of its IoT modules and connected-product portfolio.

Independent assessment is a central part of the program. Quectel maintains an ongoing relationship with Finite State for source-code auditing, firmware analysis, and penetration testing. Rather than treating these engagements as one-time certification exercises, Quectel uses continued external analysis to identify weaknesses, guide remediation, and measure improvements in its product security posture. Finite State testing has reported that Quectel modules perform significantly better than the industry average, providing customers with independent evidence in addition to the company’s internal security controls.

The infrastructure also establishes clear accountability when vulnerabilities are reported. Quectel’s Product Security Incident Response Team follows a structured process that moves reported issues through receipt, technical confirmation, remediation, coordinated disclosure, and continued monitoring. Its public vulnerability disclosure platform gives customers and researchers a defined channel for reporting issues and reviewing published security information.

Software supply-chain risk is addressed through monitoring of third-party and open-source components, tracking of public vulnerability sources, and severity-based remediation. Quectel supports this work with Software Bills of Materials and Vulnerability Exploitability Exchange documents that give customers greater visibility into embedded components and the status of known vulnerabilities. These resources help device manufacturers evaluate exposure, support compliance activities, and respond more efficiently when new software risks are identified.

Quectel further protects the cryptographic foundation of device trust through dedicated secret key management supporting secure boot, authentication, firmware signing, and data protection. That technical foundation is reinforced by certifications covering information security, privacy, automotive cybersecurity, and secure product development, including ISO/IEC 27001, ISO/IEC 27701, ISO/SAE 21434, and IEC 62443-4-1.

Together, these capabilities create a security system designed to remain active after a product leaves development. Independent assessment tests the technology, supply-chain visibility documents what is inside it, PSIRT operations provide a disciplined response path, key management protects device identity and integrity, and certification provides external validation of the processes supporting the portfolio.

Security excellence is not defined by a single test, certificate, or control. Quectel earned this recognition by connecting independent assessment, coordinated incident response, software supply-chain transparency, cryptographic governance, and certified development practices into one operational system. That lifecycle-wide discipline gives customers clearer evidence that security is being managed before deployment and after products reach the field.

Jordan HayesIoThinkTank Awards Coordinator

Winner Resources

Learn more about Quectel’s product security program, independent assessment, certifications, and recognition in the 2026 IoThinkTank Awards.

8
IoThinkTank Awards

A Fourth Consecutive Year of Recognition

This marks Quectel’s eighth individual IoThinkTank award and its fourth consecutive year receiving recognition across the IoThinkTank awards program.

Quectel received five honors in the Best of 2023 Awards. Three recognized collaborative IoT use cases and smart city technology involving BeeWaze, Polyptik, and Amazon Sidewalk. Quectel also earned the IoT Breakthrough of the Year Award for Wi-Fi HaLow and was named the Overall Winner and recipient of the IoT Excellence Award.

In 2024, Quectel won the IoT Security Excellence Award for advancing independent module testing, SBOM and VEX transparency, and DevSecOps integration. Its LG290P (03) high-precision GNSS module then earned the 2025 IoT Smart City Solution Award. The 2026 recognition builds on the earlier security win by showing how those foundations have expanded into a broader infrastructure for assessment, response, disclosure, supply-chain assurance, key management, and certification.

About the IoT Security Excellence Award

The IoT Security Excellence Award recognizes technologies, programs, and security practices that strengthen trust across connected devices and IoT ecosystems. Eligible innovations may include security-by-design programs, embedded safeguards, vulnerability management, product security operations, software supply-chain assurance, identity and key management, secure communications, compliance infrastructure, and other capabilities that reduce risk throughout the connected-product lifecycle.

Continue Exploring IoT Innovation

Discover more organizations and technologies recognized by IoThinkTank, or receive future award announcements, submission deadlines, and winner stories by email.