Product Security Requirements for Connectable Products
Product Security and Telecommunications Infrastructure Act 2022 c. 46, Part 1; Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, SI 2023/1007
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 29 April 2024.
A product security requirements rule binding private bodies.
As of 12 September 2026.
What it requires
- This binds a manufacturer, importer or distributor of a physical internet- or network-connectable consumer product placed on the UK market, and does not by itself reach a company that only publishes an app or other software with no connectable product of its own.
- Ban universal default passwords and easily guessable passwords across the product's hardware and pre-installed or required software; a password must be unique per unit or set by the user, and must not be built from incremental counters or from publicly derivable identifiers.
- Publish at least one point of contact for reporting a security issue affecting the product, in English, free of charge, without requiring the reporter's personal information, and state when the reporter will get an acknowledgment and status updates.
- Publish the minimum period for which the product will receive security updates, in plain language, before or at the point of sale, and never shorten that stated period once published.
- The duties to publish a reporting contact and a minimum update period do not reach software used on a smartphone or a cellular-capable tablet computer, and the whole regime excepts a desktop computer, a laptop computer, a non-cellular tablet computer, an electric-vehicle charge point, most medical devices, and an assured smart meter.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Failing to comply with a compliance, stop or recall notice issued under the Act is an offence under section 32, triable summarily: an unlimited fine in England and Wales, and a fine of up to level 5 on the standard scale in Scotland and Northern Ireland. The underlying failure to meet a security requirement is not itself a criminal offence; the civil monetary penalty in sections 36 to 41 is the primary sanction for that.
Penalty structure
Section 38: the relevant maximum for a fixed monetary penalty under section 36 is the greater of 10,000,000 pounds sterling and 4% of the person's qualifying worldwide revenue for its most recent complete accounting period. Section 37 separately allows a daily penalty of up to 20,000 pounds sterling for each day a failure to comply with an enforcement notice continues beyond the notice's deadline, which this structure does not carry a field for.
- Rule
- Higher of
- As of
- 12 September 2026
- Currency
- GBP
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
The Secretary of State, who under a memorandum of understanding delegates day-to-day enforcement to the Office for Product Safety and Standards (OPSS), part of the Department for Business and Trade.
Enforcement record
OPSS's own published register of enforcement actions lists every enforcement notice OPSS has issued, broken out into six-month periods since April 2018. Its most recent period report, 1 October 2025 to 31 March 2026 (entries recorded through February 2026), lists four enforcement actions, two under the Construction Products Regulations 2013 and two under the General Product Safety Regulations 2005 (each issued by virtue of the Toys (Safety) Regulations 2011), and names none under the Product Security and Telecommunications Infrastructure Act 2022 or the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, which have applied since 29 April 2024. The two preceding six-month period reports, 1 April 2025 to 30 September 2025 and 1 October 2024 to 31 March 2025, list actions under the Construction Products Regulations, the General Product Safety Regulations, environmental protection and timber rules, and neither names a PSTI action either.
- As of
- 17 September 2026
- Source link
- https://www.gov.uk/government/publications/opss-enforcement-actions/opss-enforcement-actions-1-october-2025-to-31-march-2026
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.gov.uk/government/publications/the-uk-product-security-and-telecommunications-infrastructure-product-security-regime
- Guidance body
- Office for Product Safety and Standards (OPSS), Department for Business and Trade
- Open questions
- Where a relevant connectable product depends on companion software developed and updated by a party other than the product's own manufacturer, importer or distributor under section 7, does the section 8 duty to comply with the reporting-contact and update-period requirements of Schedule 1 reach that third-party software developer directly, or does it reach only the relevant person who places the finished product on the market?
What it reaches
Obligation class
Security, Disclosure, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A manufacturer of a UK consumer connectable product, an internet- or network-connectable product that is not excepted, must comply with the security requirements of the 2023 Regulations, and an importer or distributor who supplies the product must not do so while aware of a manufacturer compliance failure.
Schedule 1 of the Regulations bans universal or easily guessable default passwords and requires the manufacturer to publish a point of contact for reporting a security issue, with a commitment on when the reporter will get an acknowledgment and status updates. The manufacturer must publish the minimum period for which security updates will be provided. That published period cannot later be shortened once it is published.
The duties reach firmware, software pre-installed on the product, and companion software that must be installed for the product's intended purpose. The reporting-contact and update-period duties do not reach the software of a smartphone or a cellular-capable tablet computer. The excepted-products schedule separately excepts a desktop computer, a laptop computer, and a non-cellular tablet computer, unless the product is designed for a child under 14.
It also excepts an electric-vehicle charge point, most medical devices, and an assured smart-meter product from the regime entirely.
The Secretary of State, acting through the Office for Product Safety and Standards under a memorandum of understanding with the Department for Science, Innovation and Technology, enforces the regime with compliance, stop and recall notices and can impose a civil monetary penalty of up to the greater of 10,000,000 pounds sterling or 4% of a person's qualifying worldwide revenue.
OPSS guidance states a further daily penalty of up to 20,000 pounds sterling for continuing non-compliance with an enforcement notice. Failing to comply with an enforcement notice is separately a criminal offence carrying a fine.
When LexLint raises it
distributes_software_product
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.