What Is the PSTI Act and What Does It Mean for Your Smart Home Devices?

James Whitfield

23 July 2026

In January 2024, someone monitoring their own home network noticed their washing machine was quietly uploading around 3.66GB of data a day, roughly 5% of the household’s entire internet traffic, for reasons the manufacturer never properly explained. Stories like that are more or less why the UK government spent the best part of five years building a law aimed squarely at the smart plug, video doorbell and connected fridge sitting in millions of British homes.

That law is the Product Security and Telecommunications Infrastructure Act, usually shortened to the PSTI Act. It has been fully in force since 29 April 2024, and if you’ve bought a smart speaker, robot vacuum or Wi-Fi kettle since that date, it already applies to the device on your kitchen counter.

What the PSTI Act actually is

The PSTI Act received Royal Assent in December 2022, but the part that affects consumers directly, the product security regime, only became enforceable on 29 April 2024, once the accompanying Security Requirements Regulations 2023 took effect. There’s a gap of well over a year between those two dates, and it caught a fair number of smaller manufacturers off guard.

Enforcement sits with the Office for Product Safety and Standards (OPSS), part of the Department for Business and Trade. Not Ofcom, which is a mix-up I still see fairly often. The National Cyber Security Centre (NCSC) has also been heavily involved on the public-facing side, publishing a point-of-sale leaflet for retailers and its own explainer for shoppers.

Which devices are covered, and which aren’t

The law applies to “relevant connectable products”, essentially anything sold to UK consumers that can connect to the internet or to another device over a network. That covers a long list: smartphones, smart TVs, video doorbells, baby monitors, fitness trackers, smart speakers, connected light bulbs and plugs, thermostats, and washing machines, fridges or ovens with an app.

A handful of categories are carved out. Laptops, desktops and tablets without cellular connectivity are excepted, along with smart meters, EV charge points and medical devices, mostly because they’re already regulated elsewhere. Products supplied only in Northern Ireland sit outside the scope too, likely tied to the different arrangements for goods regulation there.

The three security requirements manufacturers must meet

The Act doesn’t force manufacturers to follow every clause of the international ETSI EN 303 645 standard it’s loosely based on. It picks out three provisions and makes them legally binding.

No default or easily guessed passwords

Devices can no longer ship with the same password, like “admin” or “1234”, set across every unit sold. A default password is still allowed, but only if it’s unique to that individual device, or if the device forces the buyer to set their own during setup.

A published contact for reporting security flaws

Every manufacturer now has to give security researchers, and technically anyone else, a clear route to report a vulnerability. That contact point has to be free to use, available in English, and accessible without the person handing over personal details first.

Clear information on how long security updates will last

This is the requirement most people skip past. Manufacturers must state, with an actual end date, the minimum period they’ll keep providing security updates. It’s meant to sit in a Statement of Compliance document that accompanies the product, though in practice plenty of brands bury it on a support page rather than printing it anywhere near the box.

What this means for you as a smart home owner

For most people, the day-to-day change is subtle. A new device bought after 29 April 2024 shouldn’t nag you with a factory-set password you could look up on a forum in thirty seconds. That matters more than it sounds, given how often Mirai-style botnets have relied on exactly that weakness to hijack routers, cameras and DVRs at scale over the past decade.

The update-period disclosure is worth actually checking before you buy, especially for anything pricier like a smart lock or a video doorbell. A budget smart plug picked up for under £15 is a different proposition to a premium security camera costing £150 or more, and the law now requires that support information to exist somewhere, even if you have to dig for it.

One thing worth knowing: the Act only applies going forward. If you bought your Hive thermostat or Amazon Echo back in 2022, it isn’t retroactively covered, and older stock already sitting in a retailer’s warehouse before the cutoff could still be sold legally without meeting the new bar.

Penalties, and how seriously the rules are being enforced

On paper, the penalties are substantial. OPSS can fine a business up to £10 million or 4% of its global turnover, whichever is higher, plus daily penalties of up to £20,000 for a breach that continues. It can also order products off the market entirely and force recalls.

In practice, I checked OPSS’s own published enforcement log covering October 2025 to March 2026, and every case listed there is a construction product or a general consumer safety issue, unsafe children’s toys and a flammable foaming soap among them. Nothing PSTI-specific had been named publicly as of that update. That doesn’t mean nothing is happening behind the scenes, since a lot of compliance work happens through quiet correspondence long before it becomes a public notice, but it’s a reasonable sign the regime is still finding its feet nearly two years past the deadline.

A couple of honest caveats

The Act relies on manufacturers self-declaring compliance rather than an independent body testing every device before sale, which is a lighter touch than some campaigners wanted. There’s also no minimum length of update support mandated by law, only a requirement to disclose whatever period the manufacturer has chosen. A genuinely short support window, six months, say, is still legal as long as it’s stated upfront.

Buying from smaller marketplace sellers changes the picture too. Compliance on listings from unfamiliar overseas sellers on sites like AliExpress, or through third-party Amazon Marketplace accounts, tends to be far less consistently checked than stock sold through Currys, John Lewis or Argos.

Worth knowing if you buy gadgets from EU-based brands as well: the European Union’s own connected-device rules, under the Radio Equipment Directive’s cybersecurity provisions, landed with a deadline of August 2025, and its wider Cyber Resilience Act follows on a longer timeline after that. The two regimes overlap heavily but aren’t identical, and most manufacturers selling into both markets simply build to whichever standard is stricter, then apply it everywhere. It’s one reason UK shoppers sometimes benefit from EU rules even when buying a device that never mentions the PSTI Act by name.

What to actually do about it

Before buying anything that connects to your home network, look for the Statement of Compliance, usually tucked away on the manufacturer’s website rather than in the box, and check the stated end date for security updates. Change any default password anyway the first time you set the device up, even if it’s already unique to your unit. And if you’re buying second-hand or from an unfamiliar overseas seller, treat the PSTI Act as a floor rather than a guarantee: enforcement against products sold outside mainstream UK retail is still catching up with the law itself.

Leave a Comment