Skip to main content

Smart devices: new law helps citizens to choose secure products

Download the NCSC’s point-of-sale leaflet explaining how new PSTI regulation affects consumers and retailers.

This image was generated using Copilot, Microsoft's 'AI-powered digital assistant'.

From 29 April 2024, manufacturers of consumer ‘smart’ devices must comply with new UK law.

The law, known as the Product Security and Telecommunications Infrastructure act (or PSTI act), will help consumers to choose smart devices that have been designed to provide ongoing protection against cyber attacks.

The law means manufacturers must ensure that all their smart devices meet basic cyber security requirements. Specifically:

  1. The manufacturer must not supply devices that use default passwords, which can be easily discovered online, and shared. If the default password is used, a criminal could log into a smart device and use it to access a local network, or conduct cyber attacks.
  2. The manufacturer must provide a point of contact for the reporting of security issues which – if ignored – could make devices exploitable by cyber criminals.
  3. The manufacturer must state the minimum length of time for which the device will receive important security updates. When updates are no longer provided, devices are easier to hack, or may stop working as designed. 

Note:

Most smart devices are manufactured outside the UK, but the PSTI act also applies to all organisations importing or retailing products for the UK market. Failure to comply with the act is a criminal offence, with fines up to £10 million or 4% of qualifying worldwide revenue (whichever is higher).






Written by

Carla V Citizen Resilience Officer, NCSC