Guidance

Regulations: consumer connectable product security

Guidance for manufacturers, importers and distributors.

Key announcements

The UK’s consumer connectable product security regime will come into effect on 29 April 2024. Businesses involved in the supply chains of these products will need to be compliant with the new legislation from that date.

Read full details of the legislative framework.

Overview

The use and ownership of consumer products that can connect to the internet or a network is growing rapidly. UK consumers should be able to trust that these products are designed and built with security in mind.

The Product Security and Telecommunications Infrastructure Act 2022 (PSTI) and the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 will mandate that manufacturers of consumer connectable products who sell to UK consumers comply with baseline security requirements. These are based on the top three principles in the Code of Practice for Consumer Internet of Things (IoT) Security, and align with key provisions of the leading global standard for cyber security for consumer IoT, ETSI EN 303 645 (ETSI website).

When the regulations come into effect, consumers who purchase new connectable products will benefit from world-leading security protections from the threat of cyber-crime.

What is covered

The regulations apply to relevant consumer products that can connect to the internet or a network.

The regulations do not cover:

  • products made available for supply in Northern Ireland to which relevant legislation applies (legislation listed in Annex 2 of the Windsor Framework, and contains a free movement article)
  • charge points for electric vehicles
  • medical devices
  • smart meter products
  • desktop computers, laptop computers and tablet computers which do not have the capability to connect to cellular networks (unless according to the manufacturer’s intended purpose they are designed exclusively for children under 14 years)

Extent of the obligations

The regulations will come into force on the 29 April 2024.

The regulations apply to:

  • any person who manufactures a product or has a product designed or manufactured and markets that product under that person’s name or trademark
  • any person who markets a product manufactured by another person under that person’s name or trademark
  • any person who imports the product from a country outside the UK to the UK and is not a manufacturer of the product
  • any person who distributes (makes the product available) in the UK and is not the manufacturer or importer of the product

How to comply

Manufacturers, importers, and distributors (i.e. retailers) have a duty to comply with the obligations in the Act and the security requirements stated in the Regulations 2023, including duties concerning the statement of compliance. The security requirements relate to:

  • banning universal default and easily guessable passwords
  • publishing information on how to report security issues
  • publishing information on minimum security update periods

There are additional duties for manufacturers, importers and distributors which include, but are not limited to, investigating potential compliance failures, duties to maintain records and duties to take action in relation to compliance failures.

There is also a duty on authorised representatives to take action in relation to a manufacturer’s compliance failure.

These duties are laid out in Chapter two of the PSTI Act 2022.

Role of the Office for Product Safety and Standards (OPSS)

OPSS is the enforcement authority responsible for ensuring compliance with the regulations on behalf of the Department for Science, Innovation and Technology.

Our approach to carrying out our regulatory activities is explained in our Service Standards. Our approach to addressing non-compliance by those we regulate is set out in our Enforcement Policy.

Read our Service Standards.

Read our Enforcement Policy.

Where to find more information

Legislation

ETSI Standards and Implementation Guide

Supporting guides and resources

Contact us

If you have a specific enquiry about compliance or wish to contact us regarding suspected non-compliance, please email OPSS.enquiries@beis.gov.uk.

Alternatively, you can contact our helpdesk on 0121 345 1201.

Or in writing to:

Office for Product Safety and Standards
4th Floor Cannon House
18 The Priory Queensway
Birmingham
B4 6BS
United Kingdom

Published 8 January 2024