Marc Plante Speaks with IMC on IoT Security, Regulation and How SomosID® Helps Close the Gaps
In a recent interview with the IoT M2M Council (IMC), Somos’ Marc Plante offered insight into the shifting landscape of connected device security and what organizations must do to stay ahead. As the IMC continues to lead conversations in the global IoT community, Marc spoke to both the technical and regulatory realities enterprise leaders are now facing, and how SomosID®can help.
Regulation Is Reshaping Expectations
During the interview, Marc spotlighted the Cyber Resilience Act (CRA), set to begin enforcement in late 2026, as one of several regulatory efforts transforming how organizations think about IoT risk. From the EU to the United States and beyond, new cybersecurity frameworks are demanding more than traditional perimeter protection. Organizations must now demonstrate transparency into their device fleets, document their software components, and actively monitor for vulnerabilities.
This represents a fundamental shift from passive detection to proactive accountability, where governance and disclosure are just as critical as firewalls and segmentation.
Visibility Remains the Greatest Challenge
Despite growing awareness, most enterprises still struggle to maintain accurate, real-time intelligence on the IoT and OT devices operating within their environments. As Marc explained to the IMC, many of these assets fall outside traditional IT management, operate with outdated firmware, and are built and managed in a very fragmented supply chain. deployed by departments that lack centralized oversight.
Without a clear view into what devices are connected, what they are running, and how they are behaving, CISOs and compliance teams are left in the dark, unable to meet regulatory expectations or respond effectively to threats.
How SomosID Closes the Gap
Marc introduced SomosID as the solution designed to bring clarity to this complexity. SomosID creates a centralized source of truth for connected device intelligence — identifying each asset's software, hardware, certification status and connectivity profile. The platform supports SBOM and HBOM analysis, maps vulnerabilities to impacted devices and provides ongoing insights into exploit activity.
Importantly, SomosID is agentless, integrates easily into existing workflows, and delivers the kind of verifiable data regulators increasingly expect. It gives security, risk and compliance teams the confidence to respond to audits, reduce incident response times and demonstrate due diligence.
Marc’s Takeaway for the IMC Community
“Organizations don’t just need tools, they need trustworthy intelligence,” Marc told the IMC. “SomosID delivers the visibility needed to manage connected device risk in a way that satisfies both technical teams and legal expectations. That’s what makes it so powerful in today’s regulatory climate.”
Watch the full IMC interview with Marc Plante.
Want to see SomosID in action? Connect with us iot@somos.com