Britain’s Smart-Device Security Law Turns Basic Hygiene Into a Product Requirement

From 29 April 2024, consumer connectable products placed on the UK market became subject to three deceptively simple security requirements. The difficult part is proving that the whole supply chain meets them.

The United Kingdom’s Product Security and Telecommunications Infrastructure regime made baseline security requirements enforceable for relevant consumer connectable products on 29 April 2024.

The first requirements are deliberately practical: stop shipping guessable universal passwords, provide a route for reporting vulnerabilities, and tell customers how long security updates will be supplied.

These are modest controls. Their importance lies in making them product obligations rather than voluntary good practice.

Passwords must belong to the product or the user

A relevant password must be unique per product or capable of being defined by the user. A “unique” password cannot simply be an obvious counter or an easily derived serial number.

The requirement challenges manufacturing and support processes. A unique credential needs secure generation, injection, storage and presentation. Support teams need a recovery process that does not create a universal bypass. Refurbishment and resale must not silently restore a predictable credential.

For products without passwords, the organisation should still record why the requirement is not applicable. Absence of a conventional login does not mean absence of authentication elsewhere in the product or associated service.

Vulnerability disclosure becomes part of the product

Manufacturers must publish information explaining how security issues can be reported. They must also state when the reporter can expect acknowledgment and status updates.

A security.txt file or email address is only the front door. Behind it, the organisation needs triage, severity assessment, component ownership, remediation, coordinated disclosure and communication with importers and distributors.

The channel must remain monitored for the supported life of the product. A reporting address abandoned after a reorganisation does not meet the practical objective.

The support period must be visible before purchase

Manufacturers must publish the minimum period during which security updates will be provided, including an end date. The information must be accessible, clear and understandable without specialist knowledge.

This prevents an uncomfortable but common pattern: a connected product remains physically useful while its software support ends without warning.

Declaring a period is not the same as delivering updates. Manufacturers need evidence that supported products remain in vulnerability monitoring, that fixes can be built and distributed, and that the update mechanism itself is trustworthy.

Manufacturers are not the only parties involved

The regime creates duties for manufacturers, importers and distributors. Products must be accompanied by a statement of compliance, and supply-chain organisations need processes for dealing with suspected non-compliance.

This matters for white-label products. A UK brand cannot assume that a distant original equipment manufacturer owns the legal and operational problem. The party placing its name on the product needs contractual rights to obtain component information, build fixes and continue support.

How it differs from the EU Cyber Resilience Act

The UK regime begins with a narrow set of baseline consumer-product requirements. The EU Cyber Resilience Act is broader, covering many products with digital elements and imposing secure-development, vulnerability-handling, reporting and lifecycle obligations.

An organisation selling into both markets should avoid two isolated programmes. A common product-security system can support both:

  1. Product and software-component inventories.
  2. Secure default configuration.
  3. Vulnerability intake and coordinated disclosure.
  4. Update design, signing and distribution.
  5. Support-period governance.
  6. Supplier evidence and contractual access.
  7. Market-specific conformity documentation.

Baseline does not mean trivial

The three UK controls are easy to put on a slide. They are harder to sustain across thousands of product variants, outsourced firmware, mobile applications and cloud backends.

That is precisely why the regime matters. It moves elementary product security from a recommendation to a condition of participating in the market.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *