I have a vested interest in IoT devices beings secure, and the idea of the US government defining "be secure" is laughable at best, terrifying at worst.
You will pine for the bad, old days of "completely insecure" when you have a TSA-like entity defining your security.
But what about something like firmware updates? What should be the frequency of update? How long am I required to support a device? Which update networking modalities am I required to support?
These aren't small decisions. They can make a product viable--or not. Having this in the hands of something with the proven competence of the TSA (har har) is far from desirable.
On one hand this can be abused to create artificial end-of-life scenarios by some hardware companies, but allows for a wide variety of choice in the companies providing alternatives. It also provides the end-user with less restrictions. Caveat emptor.
On the other hand, a regulatory agency could reign in companies trying to artificially shorten the lifespan of a piece of hardware, but at the same time make the standard of support a huge barrier to entry that restricts choice to only the largest companies. There might be less rampant IoT exploits, but there'd also likely be less personal freedom to do what you want on your devices.
Given how other industries like telecom and cable have trended, we'll probably get the worst of both worlds. There'll be expensive regulations that serve as barriers to entry for smaller companies, but the regulations won't do much to restrict corporate malfeasance.
Liability?
I'm not exaggerating. Medical devices are the extreme form of this.
Look at the (some would say lack of) progress is creating an artificial pancreas for Type-1 diabetes, for example. The progress has been so slow that Type-1 sufferers with tech knowledge have been reverse engineering existing pumps and sensors in the hope that they can hack them and break the bottleneck themselves.
Or, alternatively, everybody will release a product and almost immediately wind up the company so that you can't get at any of the profits or use Hollywood accounting so that there magically never are any profits.
Or are you willing to make security problems a criminal offense? (Now there's a fun can of worms--write a bug, go to jail).
Be careful what you wish for.
If your company makes no attempt to patch vulnerabilities, and your devices become one more bot in the botnet, there should be some liability for this.