Two cellular wearables can look identical and sit in different worlds. One passed carrier certification and a network operator's own security review. The other cleared the legal minimum and shipped. Nothing on the box tells you which is which.
Every wireless device legally sold in the US has FCC authorization — that's the floor, and it only concerns radio behavior. Devices sold through a mobile network operator clear two further layers: PTCRB certification and the carrier's own internal testing and security requirements. Devices bought on the open market usually clear neither, and there is no label that says so.
| Layer | Who requires it | What it actually checks | Open-market device | Carrier-sold device |
|---|---|---|---|---|
| FCC equipment authorization | US law, for any RF device sold or imported | Radio emissions, interference, SAR. Nothing about data, privacy or app quality. | Required | Required |
| PTCRB | North American network operators | 3GPP conformance, behavior under real radio conditions, correct frequencies, no unwanted transmission, secure SIM handling, carrier-specific requirements. | Often not held | Required |
| Operator's own certification | The individual carrier | Additional internal testing, plus the operator's own security, data-handling and regulatory obligations applied to the device and its platform. | Not applicable | Required before it reaches the shelf |
An FCC ID on the back of a device is genuine and meaningful — it means the radio was tested and granted authorization, and it's where published SAR figures come from. It is also narrow. FCC authorization says nothing about whether the device connects reliably, whether your data is encrypted in transit, where that data is stored, how long it's kept, or whether the companion app is competently built.
A device can be fully FCC-authorized and still transmit a child's location over an unencrypted connection to a server in another jurisdiction. Those are separate questions, and only one of them is on the box.
PTCRB — the PCS Type Certification Review Board — is the certification program North American operators use for devices on their networks. Operators that belong to it require certification and may block devices that lack it.
Testing covers conformance to 3GPP standards, consistent performance under real-world radio conditions, transmitting on the correct frequencies without interfering with others or sending unwanted data, and secure SIM handling. In practice it's the difference between a device engineered for a network and a device that merely attaches to one.
It applies to cellular devices. A wearable that is Bluetooth-only, or Wi-Fi-only, has no cellular radio to certify — which is worth remembering, because a phone-tethered device sidesteps this layer entirely by not having the capability in the first place.
PTCRB is an industry standard. A carrier selling a device under its own brand or in its own channel typically goes further: its own laboratory and field testing, its own acceptance criteria, and its own obligations around data retention, security and regulatory compliance applied to the device and the platform behind it.
That last part is the one families never see and it is the one that matters most for a child's or an older adult's device. A carrier operates under regulatory scrutiny, holds the relationship with the customer, and carries the reputational and legal consequences if the data is mishandled. An importer shipping through a marketplace holds none of those.
COPPA, CCPA and GDPR are frequently described as things a device "passes." They aren't. They're laws, and they apply according to who a company serves, not how the product is sold.
An overseas manufacturer selling a children's smartwatch to families in the United States is subject to COPPA. Selling through a marketplace instead of a carrier doesn't exempt anyone.
The real difference is enforcement, and it's threefold:
So the honest way to read it: the law protects your child either way. Whether anyone enforces that protection before something goes wrong depends heavily on who sold you the device.
Both of these are free, public, and take about a minute.
ViaMondo is not a test laboratory and issues no certifications. What we do is look up what already exists: every cellular device we cover is checked against the public FCC and PTCRB databases, and we state which certifications it holds and which it doesn't — alongside whether it's sold through a carrier or on the open market. We don't treat open-market as automatically bad; plenty of established brands certify properly. We treat it as a fact buyers are entitled to know before they choose.
Every acronym on this page belongs to a real body with a public website. If you want to check something yourself — or read the rule rather than our summary of it — go straight to the source.
| Body | What it is | Official site |
|---|---|---|
| PTCRB | Cellular device certification for North America. Established 1997 by wireless operators; administered by CTIA Certification. | ptcrb.com/about Search certified devices |
| CTIA Certification | The industry body that administers PTCRB, plus battery, IoT cybersecurity and over-the-air performance programs. | ctiacertification.org |
| GCF | Global Certification Forum — the international equivalent of PTCRB, for devices built on 3GPP standards. Over 300 members. Publishes a wearables certification list. | globalcertificationforum.org Certified wearables |
| FCC | US regulator. Equipment authorization is the legal minimum to sell a radio device in the United States. | FCC ID search |
| SAR | Specific absorption rate — the RF exposure measurement the FCC sets limits against, in watts per kilogram. | FCC consumer guide to SAR |
| COPPA | US rule governing collection of personal information from children under 13. Amended rule, 16 CFR Part 312. | ftc.gov — COPPA rule |
| CCPA | California Consumer Privacy Act. Rights over personal information held by businesses, enforced by the California Attorney General. | oag.ca.gov — CCPA |
| GDPR | EU General Data Protection Regulation. Applies to any company processing the personal data of people in the EU, wherever the company sits. | European Commission Plain-English summary (third party) |
Certification is not the same thing as a privacy law. PTCRB, GCF and FCC authorization say something about the radio. COPPA, CCPA and GDPR govern the data. A device can be fully certified and still handle a child's location badly, and the reverse is also possible.
Note. Certification status changes over time, and the same brand may sell certified and uncertified variants in different markets. Check the specific model you intend to buy rather than the brand.