What the Law Now Requires of Smart Devices, and the Failures That Produced It
How CodoraTech is funded: CodoraTech is supported by advertising and, in some articles, by affiliate links. Where an article contains affiliate links, we say so at the top of that article.
Since 29 April 2024, a consumer connected product sold in the United Kingdom cannot ship with a universal default password. That is not a best practice or a supplier commitment; it is a legal requirement enforced by the Office for Product Safety and Standards, and it exists because of an attack pattern documented in 2016. The European Union’s Cyber Resilience Act sets its own schedule, the second stage of which arrived in September 2026. The United States took a different route: a voluntary label whose lead administrator withdrew in December 2025.
Three requirements, enforceable in Britain since April 2024
The Product Security and Telecommunications Infrastructure Act 2022 and the 2023 regulations made under it came into force on 29 April 2024. As summarised by the trade association techUK, they impose three mandatory requirements on internet-connected consumer products: no universal default passwords; a published vulnerability disclosure policy so that researchers have somewhere to report flaws; and transparency about the minimum period for which security updates will be provided. The Office for Product Safety and Standards regulates, working with the Department for Science, Innovation and Technology.
None of the three is technically demanding. Each addresses a documented failure mode rather than an abstract risk, and the third is arguably the most consequential, because it forces a manufacturer to state on the record how long a device will be defended. It is worth noting what is still missing: no manufacturer identified for this article has published measured security outcomes attributable to a compliance programme, such as a fall in compromised units. Compliance statements exist; measured results do not.
The Cyber Resilience Act’s three dates
Regulation (EU) 2024/2847 is the broader instrument, covering products with digital elements rather than consumer devices alone, and its timetable is staged. Anyone selling into the European market needs the three dates the European Commission publishes, in the right order.
- 10 December 2024: the regulation entered into force
- 11 September 2026: reporting obligations apply, which means they are live now
- 11 December 2027: the main obligations apply
A voluntary American label that has already changed hands
The Federal Communications Commission established its voluntary cybersecurity labeling programme for consumer wireless devices in March 2024. Certified products carry the Cyber Trust Mark with a QR code linking to security details: how to change passwords, configuration guidance, how updates are obtained and how long support lasts. Between September and December 2024 the Commission conditionally approved eleven Cybersecurity Label Administrators and designated UL Solutions as Lead Administrator.
That arrangement did not hold. An FCC public notice records UL Solutions withdrawing as Lead Administrator effective 19 December 2025, and Cybersecurity Dive reported that the withdrawal followed an administration investigation into the company’s ties to China. A fresh Lead Administrator filing window ran from 7 to 28 January 2026 and an administrator application window from 27 January to 24 February 2026. On 14 April 2026 the Commission appointed the non-profit ioXt Alliance, with FCC Chair Brendan Carr saying the Commission was confident ioXt would implement the programme in a way consistent with its original purpose. The telecoms lawyer Paul Besozzi of Squire Patton Boggs noted that ioXt had made some twenty filings during the programme’s development, and the Consumer Technology Association said the appointment put the programme on a path to success.
The comparison a buyer should draw is about force rather than content. The British requirements are mandatory and already enforced, the European ones are mandatory with fixed dates, and the American mark is voluntary with no confirmed date on which labelled products reach shelves. Whether any labelled product has actually shipped could not be confirmed from the sources available here.
Three different ways to lose customer video
The Federal Trade Commission’s 31 May 2023 action against Ring produced $5.8 million in consumer refunds and a documented account of two separate failures. One employee viewed thousands of video recordings from female users over several months, including footage from bathrooms and bedrooms, and Ring had no monitoring capable of detecting that access. Separately, approximately 55,000 US customers had accounts accessed through credential stuffing and brute force, with attackers reaching stored video, live streams and profiles, and using two-way audio to harass people including elderly users and children, with racist slurs and ransom demands. The engineering point is in the timeline: Ring suffered credential-stuffing attacks in 2017 and 2018 but did not implement multifactor authentication until 2019, and the FTC characterised the eventual implementation as poor. The order requires deletion of pre-2018 customer videos and face data, deletion of algorithms derived from unlawfully reviewed videos, and a privacy and security programme including MFA and restricted employee access to video.
Wyze failed differently. GeekWire reported that between 16 and 19 February 2024 more than 13,000 customers, which Wyze put at under 0.3 percent of its users, were shown camera thumbnails belonging to other people, and 1,504 users clicked through to those thumbnails, with some viewing videos that were not theirs. Wyze attributed it to a third-party caching client library recently integrated into its system: an Amazon Web Services outage forced devices offline, and when they reconnected simultaneously the library mixed up device and user identifier mapping and connected data to the wrong accounts. Wyze told customers it knew this was very disappointing news and that it did not reflect its commitment to protect customers. The context that matters is that this was the second such incident, after a September 2023 breach that let customers see other users’ live feeds, following which the New York Times’ Wirecutter withdrew its recommendation of Wyze products.
Verkada is the third pattern, and the simplest. Security Magazine reported that on 9 and 10 March 2021 roughly 150,000 live surveillance camera feeds were exposed, at Tesla, Cloudflare, women’s health clinics, psychiatric hospitals, police departments, prisons, schools and Verkada’s own offices. No software vulnerability was exploited. The attackers obtained super-admin credentials and reached the database, and a group including Tillie Kottmann claimed responsibility, saying the point was to demonstrate the pervasiveness of video surveillance and how easily such systems could be broken into. Verkada disabled all internal administrator accounts, notified law enforcement and committed to breach notifications.
Sixty default passwords, and the statute that followed
On 21 October 2016, distributed denial-of-service attacks driven by the Mirai malware hit the DNS provider Dyn and took down access to GitHub, Twitter, Reddit, Netflix, Airbnb and a long list of other sites. The method is the reason this incident still matters: Mirai identified vulnerable devices using a table of more than sixty common factory default usernames and passwords. Devices from Huawei, D-Link and Netgear were referenced in reporting on the malware, and roughly 900,000 Deutsche Telekom routers made by Arcadyan crashed as a result of failed exploitation attempts.
Draw the line from that table of sixty passwords to the first requirement of the British regulations that came into force in 2024 and the shape of this field becomes clear. It took eight years to turn a well-understood, cheaply fixed defect into a legal obligation, and the fix was not a new technology. The regulatory instruments described here mostly encode things security engineers were asking for a decade ago, which is a reasonable argument for buying against the strictest regime available rather than the most convenient one.
Sources: techUK · European Commission · Federal Communications Commission · Cybersecurity Dive · Federal Trade Commission · GeekWire · Security Magazine · Wikipedia