UK / PSTI Act / Consumer IoT Security

The UK's default-password ban has been enforceable since April 2024. Most non-UK IoT makers still haven't checked.

The Product Security and Telecommunications Infrastructure (PSTI) Act's security requirements apply to any consumer connectable product sold into the UK — smart TVs, speakers, toys, baby monitors, wearables, smart home appliances — regardless of where the manufacturer is based. OPSS has enforced it since 29 April 2024, with penalties up to £10m or 4% of global turnover.

Last updated 17 August 2026

29 Apr 2024PSTI security requirements became enforceable
£10m / 4%maximum penalty — global turnover, whichever is greater
3core security-by-design requirements, all mandatory

Who this actually applies to

PSTI covers "relevant connectable products" placed on the UK consumer market — internet- or network-connectable devices, including smartphones, smart TVs, smart speakers, IoT toys, baby monitors, wearables, and smart home appliances. The obligation sits with manufacturers, importers, and distributors selling into the UK, not just UK-incorporated companies. A product built and certified for the EU or US market is not automatically PSTI-compliant.

Source: Smart Regulations, "UK Product Security and Telecommunications Infrastructure Act"; Finite State, "Navigating the UK PSTI Act".

The three requirements

Universally-guessable or hardcoded default passwords are banned — every unit must ship with a unique password, or force the user to set one on first use. Manufacturers must publish a point of contact for reporting security vulnerabilities. And manufacturers must disclose, at the point of sale, the minimum period during which the product will keep receiving security updates. All three are set out in the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, which came into force alongside the Act's security provisions.

Source: National Law Review, "The PSTI Act FAQ"; techUK, "PSTI Regulations come into force".

What OPSS enforcement looks like

The Office for Product Safety and Standards enforces PSTI with a graduated toolkit: compliance notices requiring a specific fix, stop notices blocking further sale, recall notices, and monetary penalties of up to £10 million or 4% of global annual turnover — whichever is greater — plus up to £20,000 per day for ongoing non-compliance. Non-compliance can also be disclosed publicly.

Source: Center for Cybersecurity Policy, "The UK PSTI Act Comes into Effect"; Bitdefender, "UK Becomes First Country to Ban IoT Devices with Default Passwords".

Questions

What is the PSTI Act and when did it take effect?

The Product Security and Telecommunications Infrastructure (PSTI) Act received Royal Assent in December 2022. Its consumer security requirements — set out in the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 — came into force on 29 April 2024 and have been enforceable ever since.

Which products does PSTI cover?

PSTI applies to "relevant connectable products" sold to UK consumers — internet-connectable and network-connectable devices such as smartphones, smart TVs, smart speakers, IoT toys, baby monitors, wearables, and smart home appliances. It covers manufacturers, importers, and distributors placing these products on the UK market, not just UK-based companies.

What does PSTI actually require?

Three core security-by-design requirements: (1) no default or universally-guessable passwords — each device must ship with a unique password or force the user to set one; (2) manufacturers must provide a public point of contact for reporting security vulnerabilities; (3) manufacturers must publish the minimum period during which the product will receive security updates, disclosed at the point of sale.

Who enforces PSTI and what are the penalties?

The Office for Product Safety and Standards (OPSS) enforces PSTI. It can issue compliance notices, stop notices, and recall notices, and impose monetary penalties of up to £10 million or 4% of a company's global annual turnover — whichever is greater — plus up to £20,000 per day for ongoing non-compliance.

Where we fit

Most PSTI failures we see aren't malicious — they're a device that was built and certified for a different market and never checked against the UK's specific three requirements before going on sale here. We check your product and its point-of-sale disclosures against PSTI directly, alongside the rest of your UK/EU market-access work.

Book a scoping call