Since 29 April 2024, UK law has required manufacturers, importers and distributors to meet security requirements when making covered consumer connectable products available in the UK. The rules prohibit universal or easily guessed default passwords, require a way to report security vulnerabilities, and require manufacturers to disclose the minimum period for important security updates. They do not set one fixed update period for every device.
What are the UK rules for smart devices?
The regime is based on Part 1 of the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 and the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023. It has applied since 29 April 2024. The government describes its purpose as improving the security of consumer connectable products sold in the UK. UK government announcement
The requirements apply across the product supply chain: manufacturers have core product-security and disclosure duties, while importers and distributors have related compliance and statement-of-compliance duties. Regulations and guidance
Which products are covered?
The rules concern relevant consumer products that connect to the internet or another network. Government examples include smartphones, televisions, smart speakers, games consoles, smart doorbells and connected household appliances. Whether a particular product falls within scope depends on the legal definition and any applicable exclusion, not simply on whether it is marketed as “smart.” Regulations and guidance
Recommended Free Tools
#1 Best Overall
Important exclusions
Examples of excluded products include medical devices, smart meters, EV charge points and certain vehicles. Desktop, laptop and tablet computers without cellular capability are also excluded, unless designed exclusively for children under 14. Check the regulations for the full scope and definitions rather than assuming every networked device is covered. Regulations and guidance
What must manufacturers do?
Stop using universal or easily guessed default passwords
Manufacturers must not use universal default passwords or passwords that are easily guessable. This does not mean every product must use the same specific sign-in method; it means the prohibited weak default-password practices cannot be used. Regulations and guidance
Rank #2
Provide a vulnerability-reporting route
Manufacturers must publish a way for users and security researchers to report vulnerabilities. When assessing a device, look for a clear reporting contact or process rather than assuming that a general customer-support page is sufficient. Regulations and guidance
Disclose the minimum security-update period
Manufacturers must tell consumers the minimum period during which important security updates will be provided. The rules require disclosure of that period; they do not prescribe one universal number of years for every product. For a particular model, check its product information or the manufacturer’s support pages and note the stated end point or duration. Regulations and guidance
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchHow to assess a smart device before buying
- Check whether it is a covered product. Confirm that it is a consumer product connecting to the internet or another network, and check whether an exclusion applies.
- Find the update commitment. Look for the manufacturer’s disclosed minimum period for important security updates. Compare products using the stated periods, not assumptions based on brand or price.
- Find the vulnerability-reporting process. Check that the manufacturer explains how users or researchers can report a security issue.
- Consider the initial password setup. Avoid products that rely on a universal or easily guessed default password; the UK requirements prohibit manufacturers from using these defaults on covered products.
These checks help distinguish a clear, usable security commitment from a vague claim that a product is “secure.” The law’s disclosure requirement makes the update period a practical comparison point, but it does not guarantee that a product will receive updates indefinitely.
Do smart TVs and doorbells need security updates?
Smart TVs and smart doorbells are among the government’s examples of products in the regime’s scope. For a covered model, the manufacturer must disclose the minimum period for important security updates. That is not the same as a law setting an identical support period for all TVs or doorbells: check the specific product’s published commitment. Regulations and guidance
Rank #4
Why the safeguards matter
Connected devices are common in UK homes. A government release on 29 April 2024 reported that 57% of UK households owned a smart TV, 53% owned a voice assistant, and 49% owned a smart watch or fitness wristband. The same release said the 2016 Mirai attack compromised 300,000 smart products. Those figures describe adoption and a past incident; they are not a measure of the current security of any particular device. UK government announcement
NCSC chief executive Lindy Cameron welcomed the standards, saying they would “put security at the heart of technology design” and help ensure connected devices consumers rely on are secure from the outset. UK government announcement
What consumers should still do
The product rules set baseline duties for industry; they do not replace secure use at home. Follow official guidance to secure your accounts, install available device updates and protect your privacy. NCSC guidance: top tips for staying secure online
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

