UK Product Security Amendments 2025: What businesses must do now
What has changed
The Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2025 amend the Product Security and Telecommunications Infrastructure Regulations 2023. The amendment makes miscellaneous changes and corrections to the 2023 regime, clarifying and updating the security obligations that apply to relevant connectable products placed on the UK market.
Who is affected
Manufacturers, importers and distributors of connectable products, and suppliers of devices used in UK networks and consumer technology, will be subject to the updated security requirements.
Why the change matters
The amendments tighten the framework for security by design in connectable products and help ensure safer devices across their lifecycle. Compliance supports consumer protection, market access and resilience of critical infrastructure that relies on connected technology.
What organisations should do now
- Review the updated provisions of the 2023 Regulations as amended by the 2025 Regulations to identify new or clarified requirements for relevant connectable products.
- Map product design, development, procurement and supply chain processes to the amended rules to ensure security by design and secure update pathways.
- Update product risk assessments and implement incident response and vulnerability disclosure arrangements where required by the amendments.
- Review supplier contracts and third party risk management to ensure alignment with the security requirements for relevant connectable products.
- Ensure governance and documentation are in place to demonstrate compliance for market access and audits.
Practical steps and where to seek help
Engage with an experienced compliance partner to interpret the amendments and align management systems with best practice. Synergos Consultancy can support with ISO 27001 alignment and product security mapping. See ISO 27001 for a framework to manage information security across product development and supply chains: https://synergosconsultancy.co.uk/iso27001/
For organisations seeking cyber security baselines, consider Cyber Essentials as part of your risk management approach: https://synergosconsultancy.co.uk/iasme-certifications/
As you implement the changes, integrate security into your risk management and governance to protect customers and maintain regulatory compliance.
Adopting these amendments now helps organisations maintain market access and reduce the risk of interruptions to operations and supply chains.
These updates underscore the importance of timely compliance with UK product security law to safeguard users and maintain competitive advantage.