"There has to be some kind of product validation or security certification (to start with)."
if it's inexpensive [such that it doesn't crowd independent engineers from selling their wares on the intarwebs] it _MIGHT_ work... but consider the cost of F.C.C. and CE marks, ALREADY a road block for startup businesses to get a product into the market. It's bad enough that Micro-shaft, Apple, and others are INSISTENT on some kind of "approval" or paid-for certification for software, which helps to *KILL* open source (and independent developers).
Do you REALLY want "these kinds of roadblocks" IN THE WAY of TECHNOLOGY? I don't.
If the liability laws are such that the manufacturer of a device can be held liable for flaws that RESULT in a DDoS, you can bet those flaws will be PROPERLY FIXED. If that means (for their insurance, for example) that they MUST have some kind of cert, they'll get it. At the same time, a PUBLIC project for an open source OS for IoT stuff (let's say) would NOT be hampered, but would need to "self certify" (through proper testing and documentation during development, let's say) in order to get people to use it.
So yeah, gummint would have to be involved a little bit, legislating the liability laws that would basically put some pressure on IoT makers to make sure their devices have some basic protection in place to prevent being "negligent" and therefore liable for damages.