Leveraging IoT Apps for Supply Chain Optimization and Management
21.1 billion IoT devices are connected and 77% of supply chain leaders plan to adopt sensors. Here's what actually pays back, and what changed in 2026.
By Tart Labs·Published
Want to start a Project?
share
share
Written by Gowtham Raj, Director at TartLabs, who leads mobile and custom software engagements for logistics, manufacturing, and enterprise clients.
The Short Answer
The test for an IoT supply chain app is whether it changes a decision that was already being made badly. Putting a sensor on a pallet is not that test. Sensors are the inexpensive part of the exercise; the app is what turns a stream of readings into something that happens soon enough to count, whether that is a truck rerouted, a consignment refused, or a maintenance window pulled forward a fortnight.
Hold that distinction and the field stops looking contradictory. Some 21.1 billion IoT devices are connected worldwide, and about three in four supply chain leaders expect sensors to be running in their operations inside five years. Most deployments nonetheless stall before anything operational shifts, and the reasons rarely have much to do with hardware.
Operations directors, logistics CTOs, and product leads weighing up a build are the readers this is written for. Three things get covered: which returns can actually be measured in 2026, which regulatory and network deadlines landed during the year, and which architectural calls separate a system still running in year three from one abandoned quietly once the pilot ended.
Key Takeaways
The number of connected IoT devices reached 21.1 billion at the end of 2025, up 13% year over year, with 45% of those connections enterprise rather than consumer, and the enterprise IoT market at $324 billion (IoT Analytics, State of Enterprise IoT 2026, February 2026)
77% of supply chain professionals expect to adopt IoT and sensor technology within five years, third only to advanced analytics (86%) and cloud (85%) (MHI and Deloitte, 2026 MHI Annual Industry Report, April 2026, n=500)
Cargo theft losses hit an estimated $725 million in 2025, up 60% year over year, while incident volume stayed flat, because the average value per theft rose 36% to $273,990 as criminal groups shifted to targeting high-value loads (Verisk CargoNet, January 2026)
Only 6.2% of organisations report full visibility into their tier-2 and tier-3 suppliers, and close to half report limited or no visibility past their direct suppliers (Achilles Global Supplier Risk and Sustainability Survey, March 2026, n=2,805)
Two hard deadlines reshape 2026 builds: T-Mobile retired its 2G GSM network on 3 August 2026, stranding legacy trackers, and the EU Cyber Resilience Act's incident-reporting duty for connected products begins
Frequently Asked Questions (FAQ)
Conventional tracking apps report events created by a person or a barcode scan: dispatched, scanned at hub, delivered. An IoT supply chain app pulls continuous readings from sensors (location, temperature, shock, door state, engine diagnostics) with nobody doing anything at all. In practice the gap is between knowing where a shipment was last seen and knowing where it sits right now and in what condition, and the second of those is what makes intervention possible instead of merely reporting.
Let's connect and create something amazing together!
Got an idea or project in mind? Whether it's custom software, a dedicated dev team, or help with digital transformation, we're here for it. Reach out—we'll bring your vision to life.
81% of financial firms use AI; only 14% call it transformational. Where AI in finance actually pays back in 2026, and what the EU's deadline shift changed.
India's e-retail GMV hit $65-66 billion in 2025 and UPI cleared 241 billion transactions in FY26. Here's what actually made apps the default storefront.
Global app spending hit $167 billion in 2025 and apps convert up to 1.8x better than mobile web. Here's how to calculate real ROI before you build one.
The widely repeated "75% of IoT projects fail" figure is a misreading of a 2017 Cisco survey, which actually found 60% stalling at proof-of-concept and 26% reaching complete success (Cisco, May 2017, n=1,845)
What an IoT Supply Chain App Actually Is
Because the label gets stretched over anything with a radio in it, the three layers involved are worth naming precisely. Most failed projects can be traced to a team that staffed one layer properly and quietly assumed the other two belonged to someone else.
The edge layer is the sensing hardware: GPS and cellular trackers on trailers and containers, temperature and humidity loggers in reefer units, RFID tags at item or case level, accelerometers detecting shock and tilt, and telematics units reading a vehicle's own CAN bus. Procurement drives most of this layer, and it is the one people mistake for the entire project.
The transport and ingestion layer carries readings from the edge to somewhere they can be processed, whether over cellular (LTE-M, NB-IoT, or legacy 2G), LoRaWAN, satellite for ocean and remote road, or ordinary Wi-Fi inside a facility. Devices that vanish for hours, readings that arrive out of sequence, duplicate reports after a reconnect: this layer has to absorb all of it.
The application layer is where value is either created or lost. It holds the rules deciding that a reading counts as an exception, the dashboards and mobile apps putting that exception in front of a person, the integrations pushing it into a WMS, TMS, or ERP, and the audit trail that settles the argument when a customer disputes a shipment.
Commercially, the third layer is what people mean by an "IoT app", assuming it was built with informed views about the first two. Skip it and buy trackers alone, and the result is a dataset nobody opens. Of everything we see when a team hands over a stalled deployment, that is the most common outcome by a wide margin.
Where the Measurable Value Actually Sits
Intent to adopt runs high, and the shape of it tells you more than the headline number does. The 2026 MHI Annual Industry Report, produced with Deloitte from a survey of 500 supply chain professionals, puts IoT and sensors third on the five-year adoption list. Ahead of them sit the two horizontal technologies every other capability leans on, analytics and cloud; behind them sits robotics.
Intent and deployment are different things, though. Four use cases carry a defensible business case in 2026, and they are separated from the rest by a margin wide enough to steer scoping decisions.
1. Condition monitoring, where the exception is the product
Sensitive freight watched for temperature, humidity, shock, and tilt makes the clearest case of the four, since what it replaces is not an inferior system. It is nothing at all. An unmonitored shipment reports its condition when it arrives, by which point filing a claim is the only move left. A monitored one flags at hour six that a reefer setpoint has drifted, early enough for the load to be rescued.
Pharmaceuticals, fresh produce, and specialty chemicals all show favourable economics here, and battery and electronics logistics increasingly do too. Treat the numbers that circulate around this topic with some care, however. That much-quoted $35 billion in yearly pharmaceutical losses from temperature-controlled logistics failures comes from a 2019 IQVIA Institute study. As an order of magnitude it holds up; as a 2026 measurement it is not one, though it is routinely quoted as if it were.
2. Loss prevention, now the fastest-moving case
Nowhere has the business case shifted faster over two years than cargo theft, and the shift changed what the app is required to do.
Across the US and Canada in 2025, Verisk CargoNet logged 3,594 supply chain crime events, near-identical to 2024's 3,607. Losses behaved differently. They climbed roughly 60% to an estimated $725 million, driven by confirmed cargo thefts rising 18% to 2,646 and average value per theft jumping 36% to $273,990.
Into 2026 the same pattern persisted. Q1 brought 767 crime events, a 5.3% decline, yet losses of $131.58 million barely moved, and food and beverage led the target list at 144 events (CargoNet, April 2026).
Theft that is selective and high-value calls for a different product than theft that is opportunistic. Once a load has been picked out in advance, geofence-and-alert stops being sufficient. Three things start to matter instead: deviation detection sharp enough to register an unscheduled 20-minute stop, tamper and door-open events tied to location, and, since impersonation is where the growth is, an app that serves as the system of record for who was cleared to collect which load.
Our take: Of all the use cases, loss prevention is the likeliest to survive a budget review, and also the likeliest to get scoped as a hardware purchase. Nothing is prevented by a tracker reporting every 15 minutes into a portal that goes unwatched at 2am. Value lives in the alerting path: who gets woken, at what threshold, holding what authority to act. None of that is procurement; all of it is application work.
3. Inventory accuracy and the visibility that stops at tier one
Item-level sensing sits at the mature end of this market with well-documented returns. It is also where the honest limitation is easiest to see, because what it reports on is inventory already under your control.
Upstream is the harder problem. Of the 2,805 organisations in the 2026 Achilles Global Supplier Risk and Sustainability Survey, just 6.2% claimed full visibility into tier-2 and tier-3 suppliers, and close to half described limited or no visibility beyond their direct suppliers. Sensing inside your own four walls cannot close that gap, for the simple reason that the missing data is somebody else's. Multi-tier visibility is really a data-sharing and contracting problem carrying a software component, not a sensing problem, which is worth saying out loud during scoping so nobody asks an IoT budget to solve it.
4. Predictive maintenance on the assets that move goods
Fitting telematics to trucks, forklifts, reefer units, and conveyors is the least glamorous of the four and often the quickest to pay back, precisely because the starting point is so weak. Time-based maintenance schedules still govern most fleets, and they manage to be too frequent for lightly used assets and too sparse for hard-worked ones at the same time.
Surveying 600 executives at companies above $500 million in revenue, Deloitte's smart manufacturing research recorded respondents reporting gains of up to 20% in production output, up to 20% in employee productivity, and up to 15% in unlocked capacity from smart manufacturing initiatives (Deloitte, May 2025; fieldwork August–September 2024). Read "up to" as the ceiling it is, and bear in mind the fieldwork is now two years behind us.
Three 2026 Deadlines That Change the Build Decision
Most writing on this subject would have read the same in 2022. These three items would not have, and each overturns a decision a team would otherwise make without thinking.
The 2G sunset has already happened in the US
On 3 August 2026, T-Mobile switched off its 2G GSM network, the last major US carrier to do so; AT&T had gone in 2017 and Verizon around 2020. What remained on 2G by then was almost entirely legacy IoT, meaning asset trackers, alarm panels, and vehicle tracking hardware.
Supply chain deployments walk into this trap more easily than most, because trackers stay in the field for years. A great deal of hardware specified in 2016 for a decade of service was never given any migration path, and the failure is a quiet one. Reporting simply stops, and it reads as a flat battery right up until someone audits the fleet. The consequence for new builds is that LTE-M is generally the correct default wherever the asset moves. Whatever its power profile promises on a datasheet, NB-IoT cannot hand off between cells in motion, which disqualifies it from most tracking work.
The EU Cyber Resilience Act starts reporting on 11 September 2026
Beginning 11 September 2026, any manufacturer of products with digital elements has to report actively exploited vulnerabilities and severe security incidents to its national CSIRT and to ENISA via the CRA Single Reporting Platform. The clock runs at 24 hours for an early warning, 72 hours for full notification, and either 14 days for exploited vulnerabilities or one month for severe incidents before a final report is due (European Commission). Product security requirements more broadly arrive on 11 December 2027.
Building an IoT supply chain product bound for the EU market, or writing the spec for one, means treating that duty as live rather than pending. Architecture follows from it: knowing the firmware version on every device in the field, holding a route to patch it, and running vulnerability intake and triage capable of producing a report within 24 hours. Adding fleet-wide OTA update capability after launch costs considerably more than designing it in, and this deadline is what converts it from sound practice into a legal requirement.
India's mandates make the data available by default
Two pieces of public infrastructure reshape the build-versus-integrate question for Indian operations. The first is AIS-140, the Ministry of Road Transport and Highways standard covering Vehicle Location Tracking Devices, which calls for GPS and NavIC tracking, an emergency button, and real-time transmission into a certified backend. Rule 125H of the Central Motor Vehicles Rules scopes it to public service vehicles and national-permit vehicles rather than every truck on the road, yet a meaningful slice of India's commercial fleet still arrives instrumented before you have spent anything of your own.
Making that data addressable falls to the Unified Logistics Interface Platform. ULIP links 43 systems across 11 ministries via 129 APIs spanning more than 1,800 data fields, and crossed 100 crore (1 billion) cumulative API transactions in March 2025, sustaining roughly 1 crore transactions a week across more than 1,300 registered companies (Press Information Bureau, March 2025). Pull VAHAN, FASTag, and e-way bill data through ULIP and a dispatch confirmation stops being a phone call and becomes a verifiable event, with no sensor of yours involved.
Our take: On India-based supply chain builds, ask first what the public rails already hand you, and only then what needs instrumenting. More than once the cheapest useful version of "real-time visibility" turned out to be an integration project rather than a hardware one, and it shipped in a fraction of the time. It also happened to build the argument for the sensors that were genuinely warranted.
Why Most Deployments Still Stall
No statistic gets repeated in this field more often than the claim that 75% of IoT projects fail. Pulling it apart is worthwhile, because the number and its vintage are both wrong in consequential ways.
It originates in a Cisco survey from May 2017 covering 1,845 IT and business decision-makers across the US, UK, and India. The actual findings were these: 60% of IoT initiatives stalled at proof-of-concept, 26% of companies rated an IoT initiative a complete success, and a third of finished projects were judged unsuccessful. No respondent reported a 75% failure rate; the figure looks like a rounded blend of those three. It is also nine years old, and nine years in this field predates LTE-M, today's low-power silicon, and virtually every managed IoT platform now on the market.
What has aged better than the number is the underlying finding. Projects do stall at proof-of-concept, and the reasons repeat, all of them organisational:
No named owner of the operational change. Data capture gets proven by the pilot. Rewriting the standard operating procedure that would consume that data belongs to nobody, so it is captured and then ignored.
The integration was scoped as phase two. Any visibility system sitting outside the WMS or TMS asks somebody to watch a second screen. They do not, and reproducing the pilot's numbers quietly stops happening.
Device lifecycle was never budgeted. Batteries run down, firmware wants updating, devices disappear along with the pallets carrying them. Absent a replacement and provisioning process, a deployment decays into uselessness within roughly eighteen months.
Alert thresholds were set by the vendor. Left untuned, they throw off enough false positives in month one that operations mutes the lot, and from then on the system is ornamental.
Not one of these is a technology problem, and better sensors solve none of them.
Architecting the App So It Survives the Warehouse
Granted a real business case and a settled answer on ownership, a short list of design decisions determines whether anyone is still using the system in year three.
Design for silence, not just for data. Devices drop offline. Give "no reading for four hours" its own first-class state and its own handling, instead of allowing a gap to render as a stale last-known position that passes for current. That is how most misleading dashboards go wrong.
Put exception logic where the network isn't. Evaluate anything that has to be reliable, a temperature breach alarm or a tamper event for instance, on the device or the gateway rather than in the cloud. For analytics, cloud-side rules are fine; for anything time-critical crossing an unreliable link, they are a poor choice. It is worth registering how early this remains: as of December 2025, IoT Analytics found fewer than 1% of the 21.1 billion IoT connections carried a true edge AI component.
Make the mobile app the intervention surface. Whoever can act on an exception is usually behind the wheel, standing on a dock, or crossing a warehouse floor. Require a desktop and the action gets postponed. Native mobile app development earns its place here for one specific reason: push, background location, and offline-tolerant state are what let the loop close.
Treat ingestion as the scaling constraint. Reporting every five minutes, a thousand devices produce 288,000 events daily, and that counts as small. Event-driven, horizontally scalable ingestion belongs in the cloud-native architecture decision taken up front, not in a migration attempted once the pilot works.
Budget OTA updates and observability from day one. Following the CRA point above, you have to know what is running in the field and be able to change it. Apply DevOps thinking to hardware fleets, and expect this to be the line item most often struck from a first estimate.
Instrument the decisions, not just the assets. Record which alerts fired, which prompted action, and what followed. Skip it and thresholds cannot be tuned, nor can you answer the CFO in month nine when the question becomes what the system actually prevented.
Where a team is weighing a build against an off-the-shelf platform, our comparison of custom and generic software development works through the tradeoffs. If capacity rather than direction is the binding constraint, dedicated development teams in India can carry delivery, and where predictive maintenance or anomaly detection falls inside scope, our AI development practice handles the modelling layer riding on this data.
The Bottom Line
Whether the sensors work is no longer the interesting question about IoT in the supply chain. Given 21.1 billion connected devices in the field and 77% of supply chain leaders expecting to adopt sensing inside five years, the technology has become ordinary. A deployment that reliably changes an operational decision has not. That gap is why so much of the adoption intent showing up in surveys has yet to become a system anyone would notice losing.
Two developments make 2026 a materially different year to build in. The regulatory floor rose: from 11 September, fleet-wide firmware visibility and fast vulnerability reporting stop being engineering preferences under the EU's Cyber Resilience Act and become legal obligations. The connectivity floor rose too, with the US 2G era closing in August, obsoleting a generation of trackers on the way out and settling the LTE-M question for anything new. Any team still filing these under future problems has already fallen behind.
Work that succeeds starts from the far end. Identify the decision currently being made badly, identify who will make it differently, and only then reason backwards to the least sensing that will change it. To scope what that means for your operation, contact TartLabs.