California SB327 is just a regulatory provision, and Tuya is following 8259 for assessment;
The regulation requires manufacturers to manage cybersecurity by themselves, whether the finished product needs to report depends on the actual market needs,if the customer's finished product needs to report, a report for the finished product has to be done on the basis of the module report.
📎 CBU CBU-IPEX NISTIR 8259 Report 6818922001601_TRF.pdf