Product Security Requirements for Connectable Products
Product Security and Telecommunications Infrastructure Act 2022 c. 46, Part 1; Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, SI 2023/1007
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 29 April 2024.
A product security requirements rule binding private bodies.
As of 12 September 2026.
What it requires
- This binds a manufacturer, importer or distributor of a physical internet- or network-connectable consumer product placed on the UK market, and does not by itself reach a company that only publishes an app or other software with no connectable product of its own.
- Ban universal default passwords and easily guessable passwords across the product's hardware and pre-installed or required software; a password must be unique per unit or set by the user, and must not be built from incremental counters or from publicly derivable identifiers.
- Publish at least one point of contact for reporting a security issue affecting the product, in English, free of charge, without requiring the reporter's personal information, and state when the reporter will get an acknowledgment and status updates.
- Publish the minimum period for which the product will receive security updates, in plain language, before or at the point of sale, and never shorten that stated period once published.
- The duties to publish a reporting contact and a minimum update period do not reach software used on a smartphone or a cellular-capable tablet computer, and the whole regime excepts a desktop computer, a laptop computer, a non-cellular tablet computer, an electric-vehicle charge point, most medical devices, and an assured smart meter.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Failing to comply with a compliance, stop or recall notice issued under the Act is an offence under section 32, triable summarily: an unlimited fine in England and Wales, and a fine of up to level 5 on the standard scale in Scotland and Northern Ireland. The underlying failure to meet a security requirement is not itself a criminal offence; the civil monetary penalty in sections 36 to 41 is the primary sanction for that.
Penalty structure
Section 38: the relevant maximum for a fixed monetary penalty under section 36 is the greater of 10,000,000 pounds sterling and 4% of the person's qualifying worldwide revenue for its most recent complete accounting period. Section 37 separately allows a daily penalty of up to 20,000 pounds sterling for each day a failure to comply with an enforcement notice continues beyond the notice's deadline, which this structure does not carry a field for.
- Rule
- Higher of
- As of
- 12 September 2026
- Currency
- GBP
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
The Secretary of State, who under a memorandum of understanding delegates day-to-day enforcement to the Office for Product Safety and Standards (OPSS), part of the Department for Business and Trade.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.gov.uk/government/publications/the-uk-product-security-and-telecommunications-infrastructure-product-security-regime
- Guidance body
- Office for Product Safety and Standards (OPSS), Department for Business and Trade
- Open questions
- Where a relevant connectable product depends on companion software developed and updated by a party other than the product's own manufacturer, importer or distributor under section 7, does the section 8 duty to comply with the reporting-contact and update-period requirements of Schedule 1 reach that third-party software developer directly, or does it reach only the relevant person who places the finished product on the market?
What it reaches
Obligation class
Security, Disclosure, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A manufacturer of a UK consumer connectable product, an internet- or network-connectable product that is not excepted, must comply with the security requirements of the 2023 Regulations, and an importer or distributor who supplies the product must not do so while aware of a manufacturer compliance failure.
Schedule 1 of the Regulations bans universal or easily guessable default passwords and requires the manufacturer to publish a point of contact for reporting a security issue, with a commitment on when the reporter will get an acknowledgment and status updates. The manufacturer must publish the minimum period for which security updates will be provided. That published period cannot later be shortened once it is published.
The duties reach firmware, software pre-installed on the product, and companion software that must be installed for the product's intended purpose. The reporting-contact and update-period duties do not reach the software of a smartphone or a cellular-capable tablet computer. The excepted-products schedule separately excepts a desktop computer, a laptop computer, and a non-cellular tablet computer, unless the product is designed for a child under 14.
It also excepts an electric-vehicle charge point, most medical devices, and an assured smart-meter product from the regime entirely.
The Secretary of State, acting through the Office for Product Safety and Standards under a memorandum of understanding with the Department for Science, Innovation and Technology, enforces the regime with compliance, stop and recall notices and can impose a civil monetary penalty of up to the greater of 10,000,000 pounds sterling or 4% of a person's qualifying worldwide revenue.
OPSS guidance states a further daily penalty of up to 20,000 pounds sterling for continuing non-compliance with an enforcement notice. Failing to comply with an enforcement notice is separately a criminal offence carrying a fine.
When LexLint raises it
distributes_software_product