Smart Devices: Security

(asked on 14th July 2023) - View Source

Question to the Department for Science, Innovation & Technology:

To ask the Secretary of State for Science, Innovation and Technology, whether her Department is taking steps to require online distributors to inform consumers of the minimum length of time a smart product sold via their website will receive security updates.


Answered by
George Freeman Portrait
George Freeman
This question was answered on 31st July 2023

When the Product Security and Telecommunications Infrastructure Act’s product security regime comes into effect, manufacturers will be required to publish the minimum period of time the product will receive security updates for (the “defined support period”), including in a ‘statement of compliance’ that accompanies the product. This will be required if they are aware or ought to be aware that their product will be made available to UK consumers, including via online spaces.

The Government does not currently plan to make it mandatory for the distributors of these products to publicise the defined support period available, however we do encourage distributors to take this action voluntarily. If the manufacturer fails to publish the defined support period, the enforcement authority can issue notices demanding that the manufacturer, importer or distributor stop selling the product. They can also seize products from any person in the supply chain and recall them from end users.

We will be monitoring the effectiveness of the product security regime when it comes into effect. If evidence emerges suggesting further action to ensure the availability of the defined support period at points of purchase would be appropriate, the PSTI product security regime empowers Ministers to take such action.

Reticulating Splines