Back to The FOLO-UP Briefing
Connected product safety

When software support ends, product safety changes

Smart products depend on updates, apps and cloud services long after purchase. With six in ten UK adults using smart or IoT products, the published support period has become part of a product’s practical safety life.

Published by the FOLO-UP editorial team

Smart home devices on a desk in front of a laptop showing the FOLO-UP public safety intelligence platform.
FOLO-UP illustration showing connected products and a public-safety intelligence workflow.

What this briefing shows

Smart products depend on updates, apps and cloud services long after purchase. With six in ten UK adults using smart or IoT products, the published support period has become part of a product’s practical safety life.

A connected product has a physical body and a software dependency. A baby monitor, smart lock, camera, toy or appliance may still look perfect when its security updates, app or cloud service have ended. That does not mean every unsupported device becomes immediately unsafe, but it changes the risk the owner is accepting.

The latest OPSS Product Safety and Consumers tracker shows how mainstream that dependency has become. Wave 9 surveyed a representative sample of 10,037 UK adults. Fifty-nine per cent reported owning or using smart appliances or Internet of Things devices in the previous year. Software support is therefore no longer a specialist concern affecting only a small group of early adopters.

The UK’s consumer connectable-product security regime has applied since 29 April 2024. For products in scope, the rules ban universal default and easily guessable passwords, require information on how to report security issues, and require manufacturers to publish the minimum period for which security updates will be provided.

The published period must include an end date and be clear, accessible, free of charge and understandable without technical knowledge. It is a minimum commitment rather than a prediction of when the product will fail. A manufacturer may extend the period, but the Regulations say it must not shorten a defined support period after publishing it.

The support date matters because vulnerabilities are discovered throughout a product’s life. If a security flaw is found after updates stop, the manufacturer may no longer provide a fix. NCSC guidance says an out-of-support smart device is easier to hack or may stop working altogether, and suggests treating the support date as a “use by” date.

Software can also be part of a physical safety remedy. In a 2025 OPSS report concerning Fitbit Sense and Versa 3 smartwatches, the identified hazard was battery overheating and burns. The corrective action included a remote firmware update that reduced battery capacity and therefore reduced the overheating risk. The case does not mean every update is safety-critical, but it shows why continued software delivery can matter to the physical product.

The consequences depend on the device and its use. A compromised camera or baby monitor can expose a household. A smart lock can fail or be misconfigured. A connected toy can retain accounts and recordings. An appliance may lose important functions after an app or cloud-service change. These are reasons for proportionate checks, not for claiming that every old connected product is dangerous.

Before buying, consumers should find the minimum support period, check how security problems are reported, avoid products with shared default passwords, confirm whether an app or cloud service is essential, and record the support end date. Automatic updates should be enabled where available. Before resale or disposal, accounts and personal data should be removed with a factory reset.

OPSS reinforced that message with its smart connected products campaign in December 2025, including advice to check that a new product states a minimum security-update period. The legal prominence rule is clearest for invitations to purchase on a manufacturer’s own website. FOLO-UP’s view is that online marketplaces should surface the same support date, update method, manufacturer contact and service dependencies wherever a connected product is listed.

The practical conclusion is simple: the useful life of a connected product is not defined only by whether its hardware still switches on. Buyers need enough information to judge how long the complete product—hardware, software and supporting service—is expected to remain secure and functional.

What other press says

Selected reporting, official evidence and practical guidance connected with this article.

OPSS and DSIT

Regulations: consumer connectable product security

The current guidance explains the UK baseline requirements, including minimum security-update periods and statements of compliance.

Updated 17 March 2025Read report →
NCSC

Smart devices: using them safely in your home

The guidance explains why out-of-support smart devices are easier to hack or may stop working and how to check support dates.

Reviewed 23 February 2024Read report →
OPSS

Product Safety and Consumers Wave 9

The latest tracker provides current evidence on UK ownership and attitudes towards smart and AI-enabled products.

10 December 2025Read report →

These links open external websites. Their access terms and editorial responsibility apply.