Smart locks, video doorbells and app-controlled alarm hubs have become a normal part of UK home security, but until recently there was no legal minimum for how securely those devices themselves had to be built. Since 29 April 2024, there is. The Product Security and Telecommunications Infrastructure Act 2022, together with its 2023 regulations, sets baseline cybersecurity requirements for consumer connectable products, and it directly covers the category of equipment this site compares.
What the Act actually requires
The Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 came into force on 29 April 2024, giving manufacturers, importers and distributors of “relevant connectable products” a set of minimum security duties. Based on the GOV.UK product security factsheet and the underlying legislation on legislation.gov.uk, the regime centres on three core requirements. First, a ban on universal default passwords: devices can no longer ship with weak, guessable factory logins such as “admin” or “1234”; passwords must either be unique per unit or set by the user during setup. Second, manufacturers must publish a vulnerability disclosure policy, giving security researchers a route to report flaws before they can be exploited maliciously. Third, manufacturers must be transparent about the minimum period a product will keep receiving security updates, so a buyer knows upfront how long a smart lock or camera is supported before it stops being safe to trust with an internet connection.
What counts as a “relevant connectable product”
The regime applies broadly to consumer products that can connect to the internet or to other devices, which in a home security context covers smart locks, Wi-Fi and app-connected cameras and video doorbells, alarm hubs, and sensors that report to a phone app or cloud service. It sits within the government’s wider “Secure by Design” programme for consumer Internet of Things devices, which had previously operated as a voluntary code of practice before being put on a statutory footing through this Act.
Who enforces it
The Office for Product Safety and Standards (OPSS), part of the Department for Business and Trade, enforces Part 1 of the Act and the 2023 Regulations on behalf of the Department for Science, Innovation and Technology. OPSS has powers to issue compliance notices, stop notices and recall notices against non-compliant products, and the Act allows for financial penalties, reported as being up to £10 million or 4% of a company’s qualifying global revenue, whichever is higher, for serious or repeated breaches.
What this actually changes for someone buying a smart security device
In practical terms, it should now be harder to buy a smart camera or lock that ships with an unchangeable default password, one of the most common ways cheap connected devices have historically been compromised at scale. It does not mean every device on the market is automatically safe: the regime sets a legal floor for password practices, vulnerability handling and update transparency, not a certification that a specific product is well engineered. A device can technically comply with PSTI and still have a short minimum support period, meaning it stops receiving security patches well before it physically wears out.
It is also worth understanding what PSTI does not do. It does not require pre-market certification or independent testing of every device before sale, unlike, for example, the PAS 24 test applied to doorsets under Building Regulations. Compliance is largely a manufacturer self-declaration backed by OPSS’s power to investigate and act after the fact, which means a genuinely non-compliant product can still reach UK shelves and marketplaces before it is identified and removed. Buyers researching a specific brand are still better served by checking independent reviews and any OPSS recall notices than assuming the presence of a UK retailer listing is itself proof of compliance.
Because the requirements fall on manufacturers, importers and distributors rather than retailers acting purely as a marketplace, buyers researching a smart lock or camera have a reasonable basis to ask a specific question before purchase: what is the stated minimum security update period, and where is the vulnerability disclosure policy published? A manufacturer that cannot answer either question directly is a weaker bet for a device that will sit on your home network controlling physical access, regardless of how well reviewed its app is.
The security update period is worth paying particular attention to. A budget smart camera with a two-year minimum support commitment may be perfectly adequate if you plan to replace it within that time, but the same device left running for five or six years, well past its stated support window, is a device that will keep working functionally while quietly losing the vulnerability patches that keep it safe. That gap between “still works” and “still secure” is exactly the problem PSTI’s transparency requirement is designed to make visible, provided the buyer actually checks the figure before it is forgotten about.
What it does not cover
PSTI is a product cybersecurity regime, not a physical security or installation standard. It has no bearing on whether a smart lock’s mechanical components resist physical attack, which is a separate question governed by standards such as PAS 24 for doorsets or BS3621 for traditional mortice locks. A smart lock can be fully PSTI-compliant on the software side while still being a poor mechanical choice for a final exit door, so the two should be checked independently rather than treating “PSTI compliant” as a general security seal of approval.