In a connected product project the phone app is usually the least difficult component and the one everybody talks about. The difficulty is in getting a device onto a network in a stranger's home, keeping it reachable, and being able to update its firmware safely for years without turning any of them into an expensive brick.
Provisioning is where users abandon the product
Getting a device onto a home network is the single worst experience in most connected products: unfamiliar network names, hidden networks, captive portals, dual band routers, guest networks and people who do not know their own password. Every one is a support call or a return. Ask a bidder to describe its provisioning flow and its fallbacks in detail, and require it to be tested with people who did not build it, in homes rather than in an office.
Firmware update is the capability you cannot add later
Devices live for years and will need fixes, so the update mechanism has to be designed first and be close to infallible: signed images, resumable transfer, verification before switching, a recovery path if an update fails midway, and staged rollout so a bad build does not reach the whole fleet. A device that cannot be recovered from a failed update is a warranty return. This deserves more engineering attention than any feature.
Security has to assume physical access
Anyone can buy your device and take it apart, so secrets in firmware are not secret and shared credentials across a fleet are a single point of catastrophic failure. Each device needs its own identity and credentials, provisioned securely and revocable individually. The NIST Cybersecurity Framework gives a common structure for identify, protect, detect, respond and recover across a deployed fleet, and detection is the part most products genuinely lack.
Decide what happens when the cloud is unreachable
Users judge a connected product on whether basic function survives an outage. A lock that cannot be opened, a thermostat that cannot be adjusted or a light that cannot be switched when your service is down converts a minor incident into a reputational one. Decide explicitly which functions work locally and which require connectivity, and specify it in the requirements rather than discovering it during your first outage.
Questions people ask about iot app development services
What is the hardest part of an IoT product?
Provisioning and firmware updates. Getting a device onto a stranger's home network is where users abandon the product, and an update mechanism that cannot recover from a failed update turns fixes into warranty returns.
How should connected device security be approached?
Assume physical access. Secrets in firmware are not secret, and shared fleet credentials are a single catastrophic failure point. Give each device its own identity and individually revocable credentials, and make sure detection capability exists.
What should work when the cloud is down?
Decide explicitly and specify it. A lock that will not open or a thermostat that will not adjust during your outage turns a minor incident into a reputational one, and retrofitting local control is expensive.