The problem with expiration dates for software/hardware is that it's difficult to predict when they expire. A new malware attack can make an entire class of device obsolete overnight. IoT devices might be fine if you keep them on a private network but expire quickly if exposed to the internet. A device might be abandoned by a company (no more firmware updates) but later adopted by the open source movement and then updated for a decade. Everyone might be using a device thinking it's safe when actually an APT has had a compromise for it for years. Maybe a better solution is the ability to force obsolescence, but then companies might misuse that and it could be an attack route itself to turn off the devices. An expiration date or forced obsolescence can destroy many things that are actually still useful. A companies commitment to provide updates may be some indication of expected life, but is also a guess and how can you trust that small companies (innovators) will be around in the future?
Maybe the solution is the old fashioned approach to hardening devices; keep improving them until we know they are stable and reliable and then keep making the same thing, like old Unix servers. But people like new things and there are always desirable features that could be added. All changes are the potential creation of new vulnerabilities.
The Soviet Union used common parts to make many different devices, which made them last forever because they were easy to fix. But that also kept them from switching to new devices because it would obsolete so much infrastructure and the social functions built around it.
The only long term solution may be to change society so no one has an interest in doing bad things, it becomes boring and unattractive. That doesn't eliminate all risks though, because the world itself changes and can cause new unforeseen problems.
A layered approach could protect devices better, giving them a longer useful life. And if they were designed well (by iterating) to start with, that would help too. A plan for what to do, just in case, might help as well. Risk and cost assessment can help make wise decisions. Sometimes the only solution will be to just pull all the devices and replace them, at high cost.
We're already facing multiple problems along these lines (compromised home routers, bugs in CPU's, zero days, people not updating software) so there is something to be learned from current problems and solutions.
One really difficult problem is we don't really know how to make things that last a long time at a reasonable cost. Have a look at the projects of the Long Now Foundation:
http://longnow.org/