Wi-Fi 6 is a speed standard, not a security setting
Router boxes advertise a generation number, and it is easy to read that number as a security rating. It is not one. Wi-Fi 6 describes how the radio works — throughput, efficiency in crowded environments, battery behaviour on connected devices. What actually protects your traffic is the encryption mode selected in the router’s wireless settings, and that is a separate choice you can get wrong on the newest hardware available. The agencies’ guidance is about the dropdown, not the generation.
The setting that decides it
- FTC: "update your router settings to either WPA3 Personal or WPA2 Personal. WPA3 is the newer — and best — encryption available."
- CISA specifies the variant: "WPA3 Personal or WPA2 AES (also referred to as WPA2 Pre-Shared Key [PSK])".
- FTC: routers offering only WPA or WEP are "outdated and not secure" and should be replaced.
- CISA: WEP, WPA or WPA2 TKIP means the router must be replaced or upgraded by the ISP — so "WPA2" alone is not sufficient guidance.
- NIST IR 8425A (September 2024) sets manufacturer requirements for consumer routers, including unique initial passwords that must be changed on installation.
What the number on the box describes
A Wi-Fi generation is a radio specification. It governs how fast data moves, how well the access point copes with many devices at once, and how efficiently connected devices use power. Those are real improvements and they are worth having in a busy household.
None of them describe how your traffic is encrypted. That is set by the security mode you choose in the wireless configuration, and a router capable of the newest radio standard will happily run an old encryption mode if that is what is selected — often because it was selected years ago on the router this one replaced, and the settings were carried over.
What actually determines your Wi-Fi encryption
One dropdown, usually labelled Security, Security Mode or Encryption, in the wireless section of the router’s admin pages. The FTC’s instruction is to set it to WPA3 Personal or WPA2 Personal, describing WPA3 as the newer and best encryption available.
CISA goes a step further and names the acceptable WPA2 form: WPA3 Personal, or WPA2 AES — also written as WPA2 Pre-Shared Key or WPA2-PSK. That distinction is the one people miss. "WPA2" is not a single setting; WPA2 with TKIP is in the replace-the-router category as far as CISA is concerned, alongside WEP and original WPA.
So the checkable question is not what generation your router is. It is what that dropdown currently says.
Where the confusion comes from
Partly from timing. Newer routers tend to ship with newer encryption available and often default to something sensible, so the two do correlate. Correlation is not the same as the number meaning anything about security.
Partly from marketing, which does not distinguish between features that make your Wi-Fi faster and features that make it safer, because both sell.
And partly because router upgrades usually involve importing the old configuration. A settings migration can carry an old security mode onto new hardware without anything on the screen saying so.
What to check instead of the generation number
- Log into the router’s admin interface and open the wireless settings.
- Read the security mode. If it says WPA3, or WPA2 with AES/PSK, you are where the agencies want you. If it says WEP, WPA, or WPA2 with TKIP, change it — and if those are the only options offered, the router needs replacing.
- While you are there, confirm the administrative username, password and network name are not defaults. CISA wants the router login password long, random and unique; the FTC adds that it should not contain your name, address or the router brand.
- Turn off WPS. CISA: it "increases the likelihood that a threat actor could gain unauthorized access to your Wi-Fi network." Turn off UPnP and remote management too, per the FTC.
- Check the firmware version and enable automatic updates if the router supports them. CISA notes some routers do.
The requirements that genuinely changed in 2024
If you want a recent development that actually concerns router security rather than router speed, it is NIST IR 8425A, published September 2024, which sets out recommended cybersecurity requirements for consumer-grade router products.
Its content shifts work onto manufacturers rather than owners. Routers should ship with unique initial passwords that must be changed to a strong password or passphrase on installation — treating shared default credentials as a product defect. They should be able to keep firmware up to date with protection against rollback attacks. They should follow secure-by-design principles that minimise the number of interfaces, logical and physical. And they should be restorable to a secure, uninitialised default configuration.
That is a more useful thing to look for in a new router than a generation number, and it is not printed on the box either.
Sources: FTC — How to secure your home Wi-Fi network · CISA Project Upskill, Module 5 · NIST IR 8425A — Requirements for consumer-grade router products
Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from the FTC, CISA and NIST. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.