Good luck enforcing something like that.
No, it isn't
>"This device has no security holes" is often not provable even if they try to secure it.
That's not how security compliance is determined
Just as is done with HIPAA compliance, NIST compliance, etc. there would be a framework of security controls that need to be adhered to