In this guide
The UK's product security regime for connected devices has been in force since 29 April 2024, when the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 came into effect1. It applies to consumer connectable products, meaning products that can connect to the internet or a network, and it places three baseline duties on manufacturers who sell to UK consumers: no universal default passwords, a published route for reporting security flaws, and a defined support period stating how long security updates will be issued2.
For a household, the regime matters because it converts vague assurances about "security" into three things that can be checked before money changes hands. The statement of compliance is the document that carries those commitments, and the manufacturer, importer and distributor must each ensure it accompanies the product and meets the legal requirements2. Enforcement sits with the Office for Product Safety and Standards, acting on behalf of the Department for Science, Innovation and Technology2.
The regime does not cover everything. Smart meter products supplied or installed by or on behalf of a licence holder under the Gas Act 1986 or the Electricity Act 1989, and successfully assured under an assurance scheme, are excepted products under the 2023 Regulations1. That exception matters for anyone trying to work out where a smart meter, an in-home display or a home energy hub sits in the rules, and it is the point at which the PSTI regime hands over to the separate smart metering framework run by government and Ofgem.
What the PSTI regime is and why it exists
The regime exists because a connected device sold into a UK home is a small computer with a network connection, and the security of that connection is not something a buyer can inspect at the point of sale. The regulations answer that by mandating baseline security requirements for manufacturers of consumer connectable products who sell to UK consumers2. The duties are deliberately narrow and checkable rather than open-ended: they concern passwords, the reporting of security issues, and the length of time a product will be supported.
The wider policy context is the shift toward flexible, connected energy use in the home. The Smart Secure Electricity Systems programme was designed to create the technical and regulatory frameworks to enable the untapped flexibility from small scale devices, such as domestic electric vehicle charge points and heat pumps3. Every one of those devices is a connectable product, and each one is a potential entry point. The PSTI regime is the floor beneath that market.
There is a second, older layer of product safety law that still applies alongside it. Under the General Product Safety Regulations 2005, producers must adopt measures to enable them to be informed of risks the product might present, including sample testing, investigating complaints and keeping a register where necessary, and informing distributors of monitoring results where a product presents or may present a risk4. Where a producer or distributor discovers a supplied product is unsafe and poses risks, they must immediately notify the relevant enforcement authority in writing4. PSTI adds security-specific duties on top of that general safety duty rather than replacing it.
For a household's energy independence, the regime is a precondition rather than a benefit in itself. A home that runs its heating, hot water, solar diversion or battery charging through connected controls is only as independent as those controls are trustworthy. The PSTI duties do not make a device secure; they make the maker's security commitments visible and enforceable, which is what allows a household to judge whether a device is a long-term asset or a short-term convenience.
Scope: which connected consumer devices are covered
The regulations apply to relevant consumer products that can connect to the internet or a network2. That is a broad definition, and it captures the ordinary contents of a connected home: smart plugs, smart thermostats, hubs and controllers, energy monitors with a cloud service, connected appliances, and the growing category of energy smart appliances that can be controlled remotely.
The regime also carves out specific exemptions. Agricultural and forestry vehicles to which Regulation (EU) No 167/2013 applies are exempt2. On 25 February 2025, further categories were exempted from the PSTI regime, including certain automotive vehicles2. These are edge cases for most households, but they show that the scope is defined by product category rather than by whether a device happens to have a radio in it.
The most consequential exclusion for this subject is smart metering. Products are excepted under the 2023 Regulations if they are smart meter products supplied or installed by or on behalf of a licence holder under section 7AB of the Gas Act 1986 or section 6 of the Electricity Act 1989, and have been successfully assured under an assurance scheme1. In other words, the smart meter in the meter box is not governed by PSTI; it is governed by the smart metering assurance regime, which is a separate and older structure.
That separation is worth understanding because the two regimes answer different questions. PSTI asks whether a maker has published a support period and removed default passwords. The smart metering framework asks whether a device is compliant with the Smart Energy Code and capable of operating in smart mode. A household trying to assess the security of a home energy setup is therefore dealing with at least two rulebooks, and the device in the meter cupboard is on the other one.

The three security requirements manufacturers must meet

The baseline requirements are set out as three duties, and they are the whole of the regime's substantive content for manufacturers.
- Passwords. Banning universal default and easily guessable passwords2. The detail sits in the Regulations: passwords must be unique per product or defined by the user of the product1.
- Vulnerability reporting. Publishing information on how to report security issues2. The Regulations require at least one point of contact to allow a person to report security issues to the manufacturer, plus when an acknowledgement of receipt and status updates until resolution will be received1.
- Support period. A defined period during which security updates will be published, stated before the product is supplied.
Alongside those three, manufacturers, importers and distributors carry additional duties: investigating potential compliance failures, maintaining records, and taking action in relation to compliance failures2. Those duties are what give the three headline requirements teeth, because a published support period that is not honoured is a compliance failure rather than a marketing disappointment.
There is also a deemed-compliance route, which allows a manufacturer to satisfy the vulnerability reporting requirement by meeting a recognised standard instead of demonstrating compliance directly. Compliance with provision 5.2-1 of ETSI EN 303 645, or with paragraphs 6.2.2, 6.2.5 and 6.5 of ISO/IEC 29147, satisfies the requirement, as does holding a current Japan JC-STAR STAR-1 conformance label or a current Singapore Cybersecurity Labelling Scheme label at any level1. ETSI EN 303 645 provides a set of baseline provisions applicable to all consumer IoT devices, which is why it functions as the reference standard here5.
For a household, the practical effect of the three requirements is that a compliant product should arrive with a password that is either unique to that unit or set by the owner, a documented way to report a flaw, and a stated date range for security updates. Those three facts are the difference between a device that can be maintained and one that cannot.
Passwords: the ban on default universal passwords
The password requirement is the part of the regime most likely to be noticed by a buyer, because it changes what is in the box. The ban is on universal default and easily guessable passwords2, and the Regulations put it precisely: passwords must be unique per product or defined by the user of the product1. A single password shared across an entire production run, printed in the manual and never changed, is the practice the regime ends.
The reason is straightforward. A universal default password is a credential published to everyone who buys the device and to anyone who reads a manual online. It provides the appearance of protection without the substance, and it is the mechanism by which large numbers of identical devices can be accessed at once. Requiring either a per-device unique password or a user-defined one removes that shared secret.
The requirement sits alongside a broader interoperability concern in the energy market. Ofgem guidance states that flexibility service providers should provide sufficient information on the possibility of lock-in from certain energy smart appliances they may offer to customers as part of a load control arrangement6. A device that is locked into one platform is a different problem from a device with a weak password, but both bear on whether a household can change its mind later.
There is a related safety standard that applies to the physical connection rather than the software. The Plugs and Sockets etc. (Safety) Regulations 1994 require that plugs conform to BS 13637. A connected device that plugs into a UK socket is therefore subject to both regimes: PSTI for its software credentials and the plug regulations for the physical interface.
Vulnerability reporting: how manufacturers must handle flaws

The second requirement is that manufacturers publish information on how to report security issues2. The Regulations specify what that means in practice: at least one point of contact to allow a person to report security issues to the manufacturer, and information on when an acknowledgement of receipt and status updates until resolution will be received1. A generic contact form is not the same as a named route with stated response times.
The reporting duty is paired with an internal duty. Manufacturers, importers and distributors must investigate potential compliance failures, maintain records, and take action in relation to compliance failures2. That combination is what turns a reported flaw into an obligation rather than a suggestion: the report has somewhere to go, and the recipient has a duty to look into it.
The deemed-compliance routes for this requirement are the standards already described. Compliance with provision 5.2-1 of ETSI EN 303 645, or with paragraphs 6.2.2, 6.2.5 and 6.5 of ISO/IEC 29147, satisfies the requirement, as does a current Japan JC-STAR STAR-1 conformance label or a current Singapore Cybersecurity Labelling Scheme label at any level1. A manufacturer that already certifies to one of those schemes does not have to demonstrate the reporting duty separately.
For energy devices specifically, there is a parallel obligation in the electric vehicle charge point regulations. A charge point must be accompanied by a statement of compliance when the charge point is sold8. The Regulations also require that the charge point notifies the owner of an unauthorised change to the software, and that, in that circumstance, it does not connect to a communications network other than to make that notification8. That is a stronger, device-level response to a security event than PSTI requires, and it shows the direction the energy-specific rules have taken.
For a household, the reporting route is the practical test of whether a maker takes security seriously. A product page that names a security contact and states response times is doing what the regime requires. A product page with no such route is not.
Support periods: how long updates must be published for
The support period is the requirement with the longest reach into a household's ownership of a device, because it determines whether the product can be maintained after the warranty has expired. The regime requires a defined support period to be published, stating how long security updates will be issued, and it must be stated before the product is supplied.
The reason this matters more than the other two requirements is that a device does not stop being connected when its support ends. It keeps its network connection, keeps its app, and keeps whatever access it has to the home network. A support period is therefore a statement about how long the maker will keep fixing the software that sits behind that connection.
The wider market has its own rhythms that a household can compare against. Feed-in Tariff generators receive support for between 10 to 25 years9, which is the kind of horizon a solar installation is planned over. Domestic Renewable Heat Incentive participants must inform the scheme within 28 days of becoming aware of a change to the property affecting eligibility10. Those are support and reporting periods measured in years and decades, and they set an expectation that a home energy asset is a long-term commitment. A connected device with a two-year support period sits awkwardly beside a solar array with a 25-year support horizon.
There is also a practical administrative lag that affects how quickly a product reaches the market with its commitments in place. The required ECO4 register update to enable IM number notification takes approximately 4 to 6 weeks11. The Energy Smart Appliance regulations allow an implementation period of up to 20 months to let industry update production cycles12. Those periods show that regulatory change in this area is staged rather than instantaneous, and a household checking a support period should read the date it was published as well as the length.

Statement of compliance: what to look for before you buy
The statement of compliance is the document that carries a product's security commitments, and the regime places responsibility for it across the supply chain. The manufacturer, importer and distributor must ultimately ensure that the statement of compliance accompanies the product and meets the necessary legal requirements2. That shared responsibility means a buyer should expect to find it with the product, not have to request it.
There is a deemed-compliance route for the statement itself. A manufacturer is treated as having complied with the requirement at section 9(2) if the product has a current Japan JC-STAR STAR-1 conformance label or a current Singapore Cybersecurity Labelling Scheme label at any level1. A product carrying one of those labels has satisfied the statement requirement through the label rather than through a separate document.
For a household, the check is a short list of things that should be findable before purchase:
- The statement of compliance, supplied with the product or published on the maker's product page.
- The defined support period, with a start date and an end date.
- The security contact, with stated acknowledgement and update times.
- Whether the password is unique per device or set by the owner at first use.
The same logic applies to energy devices bought through a scheme. Where a smart thermostat is delivered under a government scheme, the product must meet the criteria set out in the Boiler Plus Standard13, and where the pre-retrofit assessment uses RdSAP10, the specific product must be listed in the Product Characteristics Database for use with the heat source of the home where it is installed14. Those are separate eligibility conditions from PSTI compliance, and a device can satisfy one without the other.
What PSTI means for smart meters and home energy devices
The honest answer is that PSTI does not govern the smart meter itself. Smart meter products supplied or installed by or on behalf of a licence holder under the Gas Act 1986 or the Electricity Act 1989, and successfully assured under an assurance scheme, are excepted products under the 2023 Regulations1. The meter in the cupboard is on the smart metering framework, not this one.
What the household sees alongside the meter is a different matter. Smart meters come with an in-home display so consumers can see and manage energy use15, and the display is a portable touchscreen device that shows near real-time energy usage data16. Issues with an in-home display fall within Ofgem's guaranteed standards work rather than PSTI: consumers with issues with their IHD are considered to be in scope of the standard on investigating smart meter operational issues17.
The energy devices that a household adds itself are squarely in PSTI's territory. Energy monitors and smart thermostats generally come at an additional cost and are operated via an app on a mobile phone19. Each of those is a connectable product with a cloud dependency, and each is covered by the baseline requirements. The same is true of the hubs and controllers that sit between the meter data and the household's own automation.
The dependence that remains is worth stating plainly. A smart meter's data reaches the household through the national communications network and the supplier's systems, and the meter's smart mode depends on the supplier operating it correctly. Ofgem has consulted on a new individual standalone regulation on smart meters not operating as intended, that is, not in smart mode17, and on a guaranteed standard under which a consumer whose smart meter is not operating in smart mode for over 90 days due to an issue within the supplier's control would receive compensation, with further payments proposed for every six months the meter continues not to operate in smart mode17. Those proposals address the operational dependence; PSTI addresses the device-level security of everything else in the home.

How PSTI fits with wider UK connected-device security standards

PSTI is one layer in a stack of standards that apply to connected energy devices in the UK, and the layers are being added to rather than consolidated.
The first layer is the baseline itself. ETSI EN 303 645 provides a set of baseline provisions applicable to all consumer IoT devices5, and it is the standard against which the vulnerability reporting duty can be deemed satisfied1. The second layer is the energy-specific regime. For the first phase of energy smart appliance regulations, conformity with cyber security standard EN 18031-3:2024 will be accepted as an equivalent route to compliance alongside ETSI EN 303 645 cyber security requirements20. That gives manufacturers two recognised paths rather than one.
The third layer is the smart metering framework, which sits apart from PSTI and carries its own operational obligations. Energy suppliers are required under their licence conditions to take all reasonable steps to install a smart meter where a meter is fitted for the first time or a traditional meter needs replacing due to a fault21. DESNZ has proposed amending the operational licence condition so that suppliers must take all reasonable steps to operate smart meters in smart mode within 90 days18. Those are duties on suppliers, not on device makers, and they run in parallel with the security regime.
The fourth layer is the emerging data and consent architecture. The Consumer Consent Solution is expected to meet suitable cyber security standards, including quantum-safe encryption22. That is a standard for a national data system rather than a consumer product, and it shows how far the security question extends beyond the box on the shelf.
There is a known friction in how standards reach the people who need them. The majority of British Standards require paid access, which can hinder widespread adoption and best practice23. A household trying to check whether a device meets a named standard may find the standard itself behind a paywall, which is why the statement of compliance and the published support period matter as the accessible summary of what a maker has committed to.
The direction of travel is toward more device-level obligations in energy specifically. The Smart Secure Electricity Systems programme was designed to create the technical and regulatory frameworks to enable the untapped flexibility from small scale devices, such as domestic electric vehicle charge points and heat pumps3. As more of a home's energy use moves under remote control, the security of the controlling devices becomes part of the security of the energy system, and PSTI is the floor that applies to all of them.
Sources23 cited
- The Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, legislation.gov.uk, 2023-09-14
- Regulations: consumer connectable product security, GOV.UK, 2024-01-08
- Delivering a smart and secure electricity system: implementation, GOV.UK, 2024-04-16
- General Product Safety Regulations 2005 (Great Britain), GOV.UK, 2024-12-13
- ECO4 Guidance: New Measures and Products, Ofgem, 2022-07-04
- Annex D: load control consumer protection guidance, Ofgem, 2026-08-07
- Plug-in solar consultation document, GOV.UK, 2026-06-16
- Guide to EVSCP regulations 2021, GOV.UK, 2026-09-18
- Feed-in Tariffs quarterly report, issue 60, Ofgem, 2025-06-27
- Domestic RHI essential guide, Ofgem, 2024-06
- ECO4 New Measures and Products Guidance v3.0, Ofgem, 2026-03-26
- Electricity distribution networks study: government response, GOV.UK, 2025-07-07
- Consultation on administration of mid-scheme changes to ECO4 and GBIS, Ofgem, 2025-04-07
- Decision on administration of mid-scheme changes to ECO4 and GBIS, Ofgem, 2025-06-26
- Smart meters: your rights and expectations, GOV.UK, 2025-08-08
- How do smart meters help the environment?, Smart DCC, 2026
- Smart Meter Guaranteed Standard: statutory consultation, Ofgem, 2025-08-08
- Final decision: smart meter GSOPs, Ofgem, 2026-01-30
- How do you know if you have a smart meter?, Smart DCC, 2026
- Smart Secure Electricity Systems: first phase energy smart appliances regulations, interim response, GOV.UK, 2026-09-17
- Smart meters, Energy Ombudsman, 2026-09-20
- Consumer Consent Decision, Ofgem, 2025-04-29
- Review of retrofit assessment in Scotland, Scottish Government, 2025-06-06

Can a Smart Meter Be Hacked?Can someone break into your smart meter, see your personal details or switch off your power?
Meter Standards and AccuracyHow UK smart meters are certified for accuracy, how their readings become a bill, what happens when a meter stops communicating, and how a metering or billing dispute is escalated to a supplier and then to the Energy Ombudsman.
Smart Meter RulesCan your supplier make you have a smart meter?
Firmware and Support LifeYour inverter or battery may stop getting updates at some point.
Smart Meter InstallationCan your supplier make you have a smart meter, and how long should you wait for an appointment?
The Full Smart Meters GuideDo smart meters really save you money, and how do you use one to cut your bills?