Instead of mandatory updates, there are lower hanging fruits you can win, and will have just as much, if not more positive security impact.
1. No default password, one must be set at initial configuration
2. Devices must function without public internet connection (unless it is one of the device's primary function to transmit out)
3. Devices must function without centralized host
4. Explicit disclosure of all "phone home" destination hosts, and ability to change or disable this
5. Explicit disclosure what information is transmitted out, and ability to disable this
I think the above five can be implemented relatively easily, requires no continued maintenance from the manufacturers, and improves the CIA triad of IoTs.