
The IoT community came together in Amsterdam on 22nd–23rd September for The Things Conference 2026, bringing together more than 2,000 attendees from 83 countries for two days of discussion, demonstrations, networking and debate about the future of connected technology.
The IoT Security Foundation (IoTSF) was proud to return as an official ecosystem partner, contributing to the programme through a series of sessions focused on one of the most important issues facing the industry today: how we build security and regulatory compliance into the rapidly expanding IoT ecosystem.
This year’s conference, held under the theme ‘Put Your Demo Where Your Mouth Is’, placed a strong emphasis on practical technology and real-world deployments. Alongside the demonstrations and technical discussions, however, security and regulation remained central themes.
A global IoT community
The scale and international reach of The Things Conference was once again evident throughout the event.
With more than 2,000 people attending from 83 countries, the conference provided an opportunity for organisations from across the IoT ecosystem to exchange ideas and discuss how connected technologies are moving from individual deployments and pilots towards increasingly critical real-world applications.
The programme covered a broad range of technologies and applications, including LoRaWAN, cellular IoT, embedded technology, edge AI, Bluetooth, Wi-Fi, sensors, energy harvesting, satellite and space IoT, and the emerging role of physical AI.
A recurring theme was the need to move beyond simply demonstrating what IoT technology can do and focus on how it can be deployed reliably, securely and at scale.
The Cyber Resilience Act takes centre stage
For the IoTSF, one of the most significant themes of the conference was the European Union’s Cyber Resilience Act (CRA).
The CRA is creating major new obligations for manufacturers, software developers and other organisations involved in products with digital elements. As implementation progresses, understanding exactly what the regulation means in practice is becoming increasingly important for the IoT industry.
The IoTSF contributed directly to this conversation through three sessions covering different aspects of CRA compliance:
‘CRA reporting obligations‘, chaired by IoTSF’s Chris Bennison, with Joe Lomako of TÜV SÜD, David Nosibor of Red Alert Labs and Çağatay Büyüktopçu of CyberWhiz.
‘SBoM and vulnerability requirements for the CRA‘, chaired by Mustanir Ali of Element, with Florian Lukavsky of SignPath and James Penney of Device Authority.
‘CRA assessment responsibilities‘, also chaired by Mustanir Ali, with Alex Buchan of SafeShark and Ian Pearson of Microchip.
Together, these sessions examined some of the practical questions organisations are now having to address as the CRA moves from legislation towards implementation.
The IoTSF’s presence on the programme also reflected the Foundation’s wider work helping organisations understand and implement effective cybersecurity practices across the IoT ecosystem.
From regulation to implementation
One of the important messages emerging from discussions around the CRA is that compliance cannot be treated simply as a paperwork exercise.
Organisations need to understand how requirements around vulnerability handling, reporting, software bills of materials (SBoMs), security assessments and ongoing product security translate into their existing development and operational processes.
For IoT manufacturers in particular, this can involve a significant shift in the way security is considered throughout the product lifecycle.
The conversations in Amsterdam demonstrated that there is considerable interest across the industry in understanding not just what the CRA requires, but how organisations can practically meet those requirements.
This is an area where collaboration between manufacturers, technology providers, security specialists, standards organisations and regulators will be increasingly important.
Seven wireless alliances, one stage
Another notable moment at The Things Conference was the ‘Wireless IoT Standards: State of the Union’ panel.
For the first time, seven major wireless alliances shared a stage: the DECT Forum, Connectivity Standards Alliance, Thread Group, Bluetooth SIG, Wi-Fi Alliance, LoRa Alliance and Z-Wave Alliance.
The session provided a rare opportunity to hear representatives from across the wireless connectivity ecosystem discuss the future of connected technology together.
With IoT increasingly incorporating multiple connectivity technologies, interoperability and the ability to select the right technology for a particular application remain important considerations for developers and organisations deploying connected products.
Practical IoT takes centre stage
The conference’s focus on demonstrations was visible throughout the event.
The Things Industries described the 2026 conference as bringing together the IoT community around the technologies and applications moving the industry forward, while the event itself featured dedicated demonstration areas alongside keynotes, panels and technical sessions.
The emphasis on practical demonstrations was particularly relevant to conversations around security.
As IoT moves further into critical infrastructure, buildings, industrial environments, healthcare, energy and other important applications, security needs to work in the real world as well as on paper.
That means considering security alongside connectivity, reliability, interoperability, cost and long-term maintainability from the beginning of a project.
The IoTSF at The Things Conference
For the IoTSF, The Things Conference provided an important opportunity to engage directly with the international IoT community.
Our participation also gave attendees the opportunity to learn more about the Foundation’s work, including its guidance, working groups and activities focused on improving IoT security.
The conference demonstrated that cybersecurity is no longer a separate consideration sitting alongside IoT development. Increasing regulatory requirements, growing awareness of supply-chain risks and the expanding role of connected technology in critical applications are making security an integral part of the IoT conversation.
The discussions in Amsterdam reinforced the importance of bringing the security community together with developers, manufacturers, standards organisations and other parts of the IoT ecosystem.
Looking ahead
The Things Conference 2026 provided a valuable snapshot of an IoT industry that is continuing to mature.
The technologies being demonstrated are becoming increasingly capable, while organisations are moving towards larger and more consequential deployments. At the same time, regulations such as the Cyber Resilience Act are raising the expectations placed on organisations to demonstrate that security has been properly considered throughout the product lifecycle.
For the IoTSF, that creates both an opportunity and a responsibility.
By sharing practical guidance, bringing experts together and helping organisations understand what good IoT security looks like in practice, the Foundation will continue to support the industry as it navigates this changing landscape.
The Things Conference may have been about putting demos where the mouth is. For the IoTSF, it was also an opportunity to reinforce a simple message: secure IoT needs to work in the real world.
We look forward to continuing those conversations with the IoT community.
