Router Security Updates: How Long Does Yours Actually Get?

Written by (LinkedIn) • Reviewed by Adrian James (LinkedIn)

Last reviewed: 17 August 2026

Quick summary: UK law makes router makers publish how long security updates last, but sets no minimum. What 15 manufacturers actually promise, checked by hand.

Router Security Updates
Illustration: Router Security Updates: How Long Does Yours Actually Get

Router Security Updates: How Long Does Yours Actually Get?

  • Checked by hand 16 August 2026
  • 15 manufacturers
  • Primary sources only, no vendor blogs
  • Reviewed by Dr Alex J. Martin-Smith
  • Next check 16 November 2026

The short answer

UK law makes router makers publish how long they will send security updates. It sets no minimum, so the period can be as short as they like. Of fifteen manufacturers, nine publish a period we could read and four publish nothing we could find. Checked 16 August 2026.

This page is for you if

  • You are buying a router and want to know how long it will be safe to use
  • Your router is a few years old and you are wondering whether it still gets patched
  • You want to know what UK product security law actually gives you
  • You are deciding whether to upgrade, and want a reason beyond speed

You want a different page if

Your router is the one device in the house that every other device goes through, it is switched on permanently, and it faces the open internet. It is also the device almost nobody thinks about again after the day it was plugged in.

Since 29 April 2024 there has been a UK law about this. It is genuinely useful and it is also narrower than the headlines suggested. It requires manufacturers to publish how long a product will receive security updates. It does not require that period to be any particular length.

So the practical question is not "am I protected by law". It is what did the manufacturer actually promise, where is it published, and has that clock already run out. We checked fifteen manufacturers on 16 August 2026 using their own published documents and the legislation itself. No vendor blogs, no news write-ups.

No minimumlength the law requires a support period to beonly that it is published
9 of 15router makers publish a period we could readfour publish nothing we could find, two publish no usable figure
75%of the in-scope devices OPSS assessed showed some non-compliancefrom 82 connected home and consumer devices, not router specific. OPSS does not publish how many were in scope
0enforcement actions published under the regimeon the OPSS registers we checked

The finding that surprised us

Everyone reported this law as forcing manufacturers to support devices for longer. Read the actual words and it does nothing of the kind. Schedule 1, paragraph 3(2) of the 2023 Regulations says, in full: "The defined support period must be published." That is the whole duty. There is no minimum length anywhere in the Act, the Regulations or the explanatory memorandum. A manufacturer can lawfully promise a very short period, provided it says so, does not shorten it afterwards, and gives it equal prominence at the point of sale.

The law is a transparency rule, not a longevity rule. Which makes the table below the whole point.

How long each manufacturer promises

Ordered by how useful the promise is to somebody standing in a shop. A period you can apply at the point of purchase beats one that depends on a date the manufacturer has not announced yet.

Published security update support periods for home routersFrom each manufacturer's own published documents. All rows checked 16 August 2026.
Manufacturer What it publishes Clock starts Where you have to look
eero5 years "guaranteed software security updates until at least five years from when you bought them new on eero.com or Amazon.com (or until the date stated below if later)", plus per-model dates to 31 August 2031From purchase, but written against those two storefrontsA help article, plus a signed statement of compliance
Google (Nest Wifi)5 years "At least five years from when the device first became available on the Google Store in the US". Google groups its products into four tiers running from two to seven years, and Nest Wifi sits in the five year groupFrom first availabilityHelp centre statement of compliance
ASUS4 years published as fixed calendar end dates per model group, from 31 December 2025 to 2030. The earliest group's date has already passed, so some ASUS models in this scheme are already out of supportFixed dates, no clockA support FAQ, not a product security page
ZyxelPer model calendar end dates from 2023 to 2031, with extensions "reflected on this page as soon as practicable". Some listed dates are already in the pastFixed dates, no clockTwo dedicated PSTI pages
DevoloPer model minimum dates from 30 April 2029 to 15 November 2030 across 18 productsFixed dates, no clockDedicated PSTI page
TP-Link3 years "The defined support period will end 3 years after the product's end-of-life date"From end of lifeDedicated PSTI page, plus per-model PDFs
Tenda3 years "will end in 3 years after the product's last end-of-life date"From end of lifeDedicated page, but with no model list on it
Linksys3 years "Unless otherwise set forth on the Product EOL page in the link below, Linksys UK Limited will support product hardware and firmware for 3 years following the product's End of Life (EOL) announcement"From the EOL announcement, and overridable per productA downloadable PDF only
NETGEARBy reference "Support is ended when product is End of Service", and End of Service "in general" occurs "three years after the last sale date"From last sale, across two documentsPer-model PDFs, plus a separate end-of-service page
DrayTekPublished, unread by us per-model statements of compliance are listed by name on each model's compliance tab and are one click away. DrayTek's robots file blocks automated download, so we have not read the contentsPublished per model, not read by usA PDF on each model's compliance tab
XiaomiRestates the law explains that manufacturers "must publish the minimum amount of time a product will receive security updates" without stating its ownNot applicableA policy page that points elsewhere
AVM (FRITZ!Box)Not found no support period and no UK compliance statement located on any AVM domainNot applicableNot applicable
D-LinkNot found it publishes an end-of-life process, giving at least three months' notice of end of support, but no forward-looking support period for any model we could findNot applicableNot applicable
UbiquitiNot found no PSTI statement on its compliance pageNot applicableNot applicable
HuaweiNot found no UK statement or router support period locatedNot applicableNot applicable
Sources: each manufacturer's own published pages and compliance documents, opened 16 August 2026. "Not found" means we could not locate it on that manufacturer's own site, not that no document exists, and not that any company is in breach. Note that section 9 of the Act requires a statement of compliance to accompany the product, so it may be in the box rather than on a website. A published date is also not the same as a live support period: check your own model's date against today.

What to take from this if you are buying

Only two manufacturers express the promise in a form you can use in a shop, and one of them comes with a catch. eero counts five years from the day you buy, but writes that promise against purchases made on eero.com or Amazon.com, so a UK buyer picking one up from a high street retailer should rely on eero's per-model end dates instead. Google counts five years from when the model first went on sale. Everything else either gives a fixed calendar date you have to look up per model, or counts from an end-of-life announcement that has not happened yet, which means the honest answer at the till is "we do not know".

A manufacturer that publishes nothing is a documentation problem, not proof that your router is unpatched. What matters is your own model. If your model's published end date has already passed, or your router has had no firmware update for two years or more, that is the point at which replacing it does more for your security than any settings change, and it is worth seeing what hardware comes with the packages at your address.

What the law actually says, and what it does not

The Product Security and Telecommunications Infrastructure Act 2022 is often described as banning default passwords. It does not do that directly. Section 1 is headed "Power to specify security requirements" and creates the power to make regulations. The three requirements themselves live in Schedule 1 to the 2023 Regulations, which came into force on 29 April 2024 and have been amended twice since, by SI 2025/211 and SI 2025/1267. Neither amendment introduced a minimum support period.

But the Act itself is not empty, and this matters. Section 8 is headed "Duty to comply with security requirements" and says a manufacturer "must comply with any relevant security requirements relating to the product". Section 9 adds a separate duty about paperwork. Sections 14 and 21 impose parallel duties on importers and distributors. So the Act supplies the duties and the enforcement machinery, and the Regulations supply the substance.

The duties, in the law's own words

Passwords, Schedule 1 paragraph 1(2)
"Passwords must be, (a) unique per product; or (b) defined by the user of the product." Note that the phrase "universal default passwords" does not appear anywhere in Schedule 1. That is the government's description of the rule rather than its wording.SI 2023/1007
A way to report security problems, Schedule 1 paragraph 2
Manufacturers must publish "at least one point of contact" for reporting security issues, and say when you will get an acknowledgement and status updates. It must be free, in English, and available "without prior request".SI 2023/1007
The support period, Schedule 1 paragraph 3(2)
"The defined support period must be published." A defined support period means "the minimum length of time, expressed as a period of time with an end date, for which security updates will be provided".SI 2023/1007
It cannot be shortened later, paragraph 3(6)
"The security requirements in this paragraph are not met if the defined support period is shortened after the publication of the information in sub-paragraph (2)."SI 2023/1007
It has to be as prominent as the product's main characteristics
Paragraph 3(5) requires the support period to be published "alongside or otherwise given equal prominence to" the main characteristics of the product in an invitation to purchase. In plain terms, it should be as easy to find as the specifications.SI 2023/1007
And it must be understandable
Paragraph 3(4)(e) requires it to be published "in such a way that is understandable by a reader without prior technical knowledge".SI 2023/1007
The statement of compliance goes in the box, not on a website
Section 9(2) says a manufacturer "may not make the product available in the United Kingdom unless it is accompanied by" a statement of compliance or a summary of one. That is a separate duty from publishing the support period, and it is the reason an absent website statement is not by itself evidence of a breach.PSTI Act 2022, s.9
A civil penalty, and a separate criminal offence
Two routes exist. Under section 36 the Secretary of State may issue a monetary penalty where satisfied "on the balance of probabilities" that a duty has been breached, which is a civil standard. Section 32 separately makes it "an offence for a person to fail to comply with an enforcement notice".PSTI Act 2022, ss.32, 36
The maximum is large
Section 38 sets it at "the greater of, (a) £10 million, and (b) 4% of the person's qualifying worldwide revenue for the person's most recent complete accounting period". Section 36 adds a daily penalty of up to £20,000 for each day a breach continues after the deadline for paying a fixed penalty, so it only bites once a penalty notice has been served.PSTI Act 2022, ss.36, 38
But no enforcement action has been published
We checked the OPSS enforcement registers published since the rules took effect and found no action recorded under the Act or the Regulations. The most recent, covering October 2025 to March 2026, lists actions only under construction products, general product safety and toy safety rules.OPSS

The regulator's own compliance figure is not encouraging

OPSS, the body that enforces this, published its own assessment: "Projects have been undertaken including the assessment of 82 connected home devices, consumer lifestyle devices and child related products. These items were assessed against the three security requirements and 75% of those in scope were found to have varying levels of non-compliance."

That is the regulator saying three quarters of the in-scope devices it looked at fell short in some way. Two caveats worth holding on to: it is not a router-specific figure, and the 75% is a percentage of the in-scope subset rather than of all 82, and OPSS does not say how large that subset was. With those attached, it is still the best public measure of how well this regime is being followed, and it comes from the people enforcing it.

The three different clocks, and why it matters

Every manufacturer in the table is complying with the same rule, and yet you cannot line their promises up next to each other. That is because they start counting from different events.

From when you buy it. Only eero does this. It is the only clock that answers a shopper's actual question, because you know the date you paid.

From when the model first went on sale. Google does this. Better than nothing, but a model that has been on the shelf for three years gives you two years, and the box will not tell you which.

From a fixed calendar date. ASUS, Zyxel and Devolo publish dates per model. This is honest and checkable, but you have to look up your exact model, and ASUS publishes it in a support FAQ rather than anywhere a buyer would look.

From end of life, or end of sale. TP-Link, Tenda, Linksys and NETGEAR all count from an event that has not happened yet. A three year period from an unannounced future date is not something you can plan around. NETGEAR is the hardest of all, because you have to chain two separate documents together and its own rule is hedged: End of Service occurs "in general" three years after the last sale date.

One distinction worth holding on to

A hardware warranty and a security update support period are completely different things, and they get confused constantly. Your warranty covers the box breaking. The support period covers whether anybody is still fixing the software inside it. A router can be well within warranty and receiving no security updates at all. Linksys is the one manufacturer here that bundles both into a single sentence, promising to support "product hardware and firmware for 3 years following the product's End of Life (EOL) announcement", though that sentence opens "Unless otherwise set forth on the Product EOL page", so it is a default rather than a guarantee.

What about the hub your broadband provider sent you?

This is where we have to be honest about a gap, because most people in the UK are using a router they did not buy.

No official list of in-scope products names routers. The Act does not name them. The Regulations do not name them. The government's guidance page does not name them. The 2021 factsheet's list of examples names smartphones, cameras, televisions, speakers, toys, baby monitors, smoke detectors, door locks and "Internet of Things base stations and hubs to which multiple devices connect", which is the nearest thing to a router in any official list. That factsheet mentions routers by name only once, describing the 2016 Mirai attack, rather than as an in-scope example. The closest official statement is the Data and Digital Infrastructure Minister Julia Lopez on the day the rules came into force, welcoming an era in which "smart devices, such as phones and broadband routers, are shielded from cyber threats..."

On the wording, a router meets the test. Section 5 defines an internet-connectable product as one "capable of connecting to the internet", and the excepted products in Schedule 3, which cover Northern Ireland products, electric vehicle charge points, medical devices, smart meter products, certain computers and, since February 2025, three classes of vehicle, do not include routers. That is our reading of the words rather than an official position, but on it the manufacturer's duty under section 8 applies.

Whether your broadband provider carries any duty is a different and genuinely unresolved question. Distributors have duties under the Act, but section 55(3) says that supplying a product "does not include a reference to hiring out or lending the product" unless the lender is the manufacturer or it is a hire purchase agreement. Most UK providers loan you the hub and want it back. Whether that makes them a distributor or not is not answered anywhere in the Act, the Regulations, the explanatory memorandum or the OPSS guidance, all of which we checked.

This is not theoretical. It has already happened once

NOW told owners of its legacy broadband hub that the device "no longer receives service or security updates", and that without updates "your network and devices will still be vulnerable to hackers and to being infected by malware, ransomware and other security threats". From 31 July 2025, it added, "should your hub develop a fault, we unfortunately won't be able to provide a replacement".

That is a provider-supplied router, in people's homes, publicly declared out of support. Whatever the legal position turns out to be, the practical lesson is that a hub arriving free with your broadband is not automatically a hub that will be patched forever.

If you cannot replace the hub, this is the order to work through. Ask your provider, in writing, whether your hub model still receives firmware and security updates, and keep the answer. Ask for a replacement hub: providers routinely swap ageing hubs at no cost, and one that has declared a hub out of support has little ground to refuse. Check whether your provider allows modem mode, which lets you put your own router behind the hub and take the internet-facing role away from it. Only if all three fail is switching the answer, and check your exit fee before you start.

If you want to know what hardware your provider actually ships, what its ports do and whether it permits your own router, we have that in broadband router by provider.

How to check your own router, in six steps

  1. Find the exact model number

    It is on a label on the underside or back, and it matters: almost every manufacturer publishes support dates per model, not per range. Our router login and settings hub covers where to find it for every major brand.

  2. Search the manufacturer's site for its UK statement

    The useful search terms are the model number plus "PSTI", "statement of compliance", "support period" or "end of service". TP-Link, Zyxel, Tenda and Devolo have dedicated pages. ASUS keeps it in a support FAQ. Linksys and NETGEAR put it in PDFs.

  3. Check the date against today

    If it has passed, your router is receiving no security updates and no amount of settings will change that. If it is expressed as three years from end of life and no end of life has been announced, you cannot know, and that is worth factoring into a purchase.

  4. Check how your router updates

    A support period is only worth anything if the updates actually install. Mesh systems such as eero and Google Nest Wifi update themselves and give you no setting to change, and most provider hubs do the same. Shop-bought routers vary: look under Administration, System or Firmware and switch automatic updates on if the option exists. If there is no automatic option, note the firmware date and check the manufacturer's download page for your model twice a year.

  5. Do the three free things now

    Turn off remote administration, sometimes called remote management or WAN access, unless you know you need it. It is the setting that most often puts a router's login page on the open internet. Turn off WPS. And change the router's admin password, which on many routers is separate from the Wi-Fi password. These cost nothing and they help whether or not your model is still supported.

  6. If it is out of support, put it on the replacement list

    An unpatched router facing the internet is the weakest point in the house. If yours is past its date, that is a better reason to upgrade than a new Wi-Fi generation, and it is a reason our Wi-Fi 6 vs 6E vs 7 guide does not currently cover. Plan it rather than panic about it, with the one exception in the questions below.

If your provider's hub is the problem, you have options

Some providers let you use your own router, and some do not. See what reaches your address and what hardware comes with it.

Compare broadband at my address Or see which providers let you use your own router

Where each manufacturer stands, on what we could read on 16 August 2026
Clearest promiseeero. Five years from the date you bought it, in plain English, on a page a normal person could find, with per-model floor dates as a backstop. It is the only one that answers the question a shopper is actually asking.
Best documentedTP-Link. A dedicated UK PSTI page covering all three duties, plus per-model PDFs running to hundreds of models. The three year clock from end of life is less useful than eero's, but the documentation is thorough.
Hardest to useNETGEAR. You have to find a per-model PDF, which points you to a separate end-of-service page, which then tells you the rule holds only "in general". Two documents to answer one question, and a hedge at the end of them.
Hardest for us to readDrayTek. Its per-model statements of compliance are listed by name on each model's compliance tab and are one click from the model page. DrayTek's robots file blocks automated download, so our retrieval did not reach the contents. That is a limit on our method rather than a finding about DrayTek, and a reader with a browser can open the same files.
Nothing we could findAVM, D-Link, Ubiquiti and Huawei. We searched each company's own domains and found no published support period. That is a gap in what we could locate, not a finding that no document exists or that anyone is in breach: section 9 requires a statement of compliance to accompany the product, so it may well be in the box. If any of these four publishes one, tell us and we will add it.

How we are paid. BroadbandSwitch.uk may earn a commission if you switch through our comparison tool. No manufacturer paid for, saw or influenced this page, and the table rests only on what each manufacturer publishes.

What we could not verify

  • Whether routers are formally in scope. No official list of in-scope products names them. The wording of section 5 covers them and the Schedule 3 exceptions do not exclude them, but the closest official mentions are a ministerial press quote and, in the 2021 factsheet, "Internet of Things base stations and hubs to which multiple devices connect".
  • Whether a broadband provider carries any duty for the hub it lends you. Genuinely unresolved. Section 55(3) excludes lending from "supply" unless the lender is the manufacturer, and nothing in the guidance addresses products supplied with a service. If this matters to you, OPSS takes enquiries.
  • DrayTek's actual support period. One document is titled "5 year Security Router UK PSTI statement of compliance", but a title is not a document. Its robots file blocks automated download, so we have not read the contents and are not going to infer them. A reader with a browser can.
  • Zyxel's consumer model list. Its retail UK page loads the model table client-side and it was not present in the page we retrieved. The dates we quote come from its service provider page.
  • NETGEAR's own index of UK declarations. Closed to automated retrieval, so we could not verify the consumer entry point, only individual model PDFs.
  • Whether any manufacturer has been the subject of enforcement. OPSS publishes activity data but no named actions under this regime. Absence from a published register is not proof that nothing has happened.
  • How many of the 82 devices OPSS assessed were in scope. The 75% figure is a percentage of the in-scope subset, and OPSS does not publish how large that subset was. Do not multiply 75% by 82.

Share this with someone whose router is five years old

Free to quote and free to pass on. No permission needed.

Cite this page

This dataset is free to quote, in full or in part, with attribution. Researchers, journalists, security professionals and AI assistants are all welcome to use it. Please cite the check date, because support dates move.

BroadbandSwitch.uk. (2026, August 16). Router security updates: How long does yours actually get? https://broadbandswitch.uk/insights/router-security-uk/

In a sentence: BroadbandSwitch.uk checked fifteen router manufacturers on 16 August 2026 and found that UK product security law requires a security update support period to be published but sets no minimum length for it, with nine of the fifteen publishing a readable period, four publishing nothing we could find, and no enforcement action recorded on the OPSS registers published since the rules took effect in April 2024.

Frequently asked questions

How long does a router get security updates in the UK?

There is no legal minimum, so it depends entirely on the manufacturer. Of fifteen we checked, nine publish a period we could read. eero promises at least five years from the date you buy, though it writes that against purchases on eero.com or Amazon.com, and Google promises at least five years from when the model first went on sale. ASUS publishes four year periods as fixed calendar dates, the earliest of which has already passed. TP-Link, Tenda and Linksys promise three years but count from an end-of-life announcement that may not have happened yet. AVM, D-Link, Ubiquiti and Huawei publish nothing we could find.

Does UK law require a minimum security update period?

No. This is the most misunderstood part of the regime. Schedule 1, paragraph 3(2) of the 2023 Regulations says only "The defined support period must be published". No minimum length appears in the Act, the Regulations or the explanatory memorandum. What the law does require is that the period is published, that it is not shortened afterwards, that it is given equal prominence to the product information at the point of sale, and that it is understandable "by a reader without prior technical knowledge".

What is the PSTI Act and what does it actually do?

The Act and the Regulations do different jobs. Section 1 of the Act is headed "Power to specify security requirements" and creates the power to make regulations, and the substance of the three requirements is in Schedule 1 to the 2023 Regulations, in force since 29 April 2024. But the Act is not empty: section 8 imposes a duty on manufacturers to comply with those requirements, section 9 requires a statement of compliance to accompany the product, and sections 14 and 21 impose parallel duties on importers and distributors. The three requirements are that passwords must be unique per product or set by the user, there must be a published way to report security issues, and the support period must be published.

Does the law cover the router my broadband provider gave me?

On the wording of the Act the manufacturer's duty applies, because section 5 defines an internet-connectable product as one "capable of connecting to the internet" and routers are not among the Schedule 3 exceptions. We say that as our reading of the words rather than an official position, because no official list of in-scope products names routers. Whether your broadband provider carries any duty is unresolved. Section 55(3) of the Act says supplying a product "does not include a reference to hiring out or lending the product" unless the lender is the manufacturer, and most UK providers loan you the hub and require it back. Nothing in the Act, the Regulations or the government guidance addresses products supplied as part of a service.

How do I find out if my router is still supported?

Find the exact model number on the label, then search the manufacturer's own site for that model plus "PSTI", "statement of compliance", "support period" or "end of service". Almost every manufacturer publishes dates per model rather than per range, so the model number matters. TP-Link, Zyxel, Tenda and Devolo have dedicated pages. ASUS keeps it in a support FAQ. Linksys, NETGEAR and DrayTek publish it in PDFs.

What happens when security updates stop?

The router keeps working. eero puts it plainly: "When software security updates end, your eero device will still work and can still provide wifi." What changes is that newly discovered vulnerabilities in that model will not be fixed. Since a router sits between every device in your home and the internet and is switched on permanently, that is a risk that grows over months rather than an emergency, so plan the replacement rather than panic. There is one exception. If a specific flaw in your model is already being exploited and no fix is coming, that is urgent: check your manufacturer's security advisory page for your model, and if it lists an unpatched flaw, turn off remote administration immediately and replace the router sooner.

Is a hardware warranty the same as a security update period?

No, and they are widely confused. A warranty covers the physical device failing. A support period covers whether anyone is still fixing the software. A router can be inside its warranty and receiving no security updates at all, or out of warranty and still fully supported. Linksys is the only manufacturer in our table that bundles them into one promise, covering "product hardware and firmware for 3 years following the product's End of Life (EOL) announcement", and even that sentence opens "Unless otherwise set forth on the Product EOL page".

Has anyone been fined under these rules?

Not that has been published. We checked the OPSS enforcement registers published since the rules took effect and found no action recorded under the Act or the 2023 Regulations. The most recent, covering October 2025 to March 2026, lists actions only under construction products, general product safety and toy safety rules. OPSS does publish activity data: it assessed 82 connected home and consumer devices in 2024 to 2025 and found that "75% of those in scope were found to have varying levels of non-compliance", without saying how many of the 82 were in scope. The maximum penalty available is the greater of £10 million or 4% of worldwide revenue.

Does the law ban default passwords on routers?

Not in those words. The government describes it as "banning universal default and easily guessable passwords", but that phrase does not appear in the Regulations. What Schedule 1 paragraph 1(2) actually says is "Passwords must be, (a) unique per product; or (b) defined by the user of the product". In practice that is why modern routers arrive with a unique password printed on a label, or make you set one during setup. Whatever your router came with, change it to something of your own.

Is a second-hand router a risk?

Two risks. A used router is older than a new one, so it is closer to its published end date or already past it, and almost every manufacturer publishes those dates per model, so check before you buy. And you cannot tell what firmware a stranger installed, so factory reset it and install the latest official firmware from the manufacturer's own download page before you use it.

Does the support period cover features as well as security?

No. The published period covers security updates only. Regulation 2 defines it as "the minimum length of time, expressed as a period of time with an end date, for which security updates will be provided". A manufacturer can stop adding features, stop supporting its app or shut down a cloud service while the security clock is still running, and none of that breaches the rule.

My manufacturer is not listed. What should I ask?

Three questions, and the manufacturer is legally required to have published answers to two of them. What is the defined support period for my exact model, and on what date does it end. Where is that published. And how do I report a security problem if I find one. If you cannot get an answer, OPSS is the body responsible for this regime and takes general enquiries.

References

  1. ASUS. (2026, June 2). Duration of security update support (only for UK). https://www.asus.com/uk/support/faq/1051929/
  2. ASUS. (2026). Security advisory. https://www.asus.com/security-advisory
  3. AVM. (2026). Security information on FRITZ! updates. https://fritz.com/en/pages/security-information-about-updates
  4. D-Link. (2026). End of life policy. https://www.dlink.com/en/end-of-life-policy
  5. Department for Science, Innovation and Technology. (2024, April 29). New laws to protect consumers from cyber criminals come into force in the UK. https://www.gov.uk/government/news/new-laws-to-protect-consumers-from-cyber-criminals-come-into-force-in-the-uk
  6. Department for Science, Innovation and Technology. (2025, March 17). Regulations: consumer connectable product security. https://www.gov.uk/guidance/regulations-consumer-connectable-product-security
  7. Devolo. (2026). PSTI statement of conformity. https://www.devolo.co.uk/en/support/psti-soc
  8. DrayTek. (2026). Vigor 3910 compliance downloads. https://www.draytek.co.uk/support/downloads/vigor-3910/compliance
  9. eero. (2026). eero software security updates. https://eero.com/support/articles/4401964665243-eero-Software-Security-Updates
  10. eero. (2026). Compliance. https://eero.com/legal/compliance?lang=en-gb
  11. Google. (2024, April 29). UK PSTI statement of compliance. https://support.google.com/product-documentation/answer/14869041?hl=en
  12. Linksys. (2024, March 27). UK PSTI statement of compliance [PDF]. https://downloads.linksys.com/support/assets/others/UK_PTSI_Statement_of_Compliance_w_products.pdf
  13. National Cyber Security Centre. (2024, February 23). Smart devices: using them safely in your home. https://www.ncsc.gov.uk/guidance/smart-devices-in-the-home
  14. National Cyber Security Centre. (2024, April 29). Smart devices: new law helps citizens to choose secure products. https://www.ncsc.gov.uk/blog-post/smart-devices-law
  15. NETGEAR. (2026). End of service. https://www.netgear.com/about/eos/
  16. NETGEAR. (2025, December). Product security and vulnerability reporting. https://www.netgear.com/security/product-security/
  17. NOW. (2026). Important information about your NOW Broadband Hub. https://www.nowtv.com/gb/help/article/important-information-about-your-now-broadband-hub
  18. Office for Product Safety and Standards. (2025, July 30). OPSS delivery report 2024 to 2025. https://www.gov.uk/government/publications/opss-delivery-report-2024-2025/opss-delivery-report-2024-2025
  19. Office for Product Safety and Standards. (2026, June 29). OPSS enforcement actions: 1 October 2025 to 31 March 2026. https://www.gov.uk/government/publications/opss-enforcement-actions/opss-enforcement-actions-1-october-2025-to-31-march-2026
  20. Office for Product Safety and Standards. (2025, August 8). Consumer connectable product security regulations: enforcement. https://www.gov.uk/government/publications/opss-enforcement-enforcement-actions/consumer-connectable-product-security-regulations
  21. Huawei. (2026). HUAWEI WiFi Mesh 3, United Kingdom. https://consumer.huawei.com/uk/routers/wifi-mesh3/buy/
  22. Product Security and Telecommunications Infrastructure Act 2022, s.1. https://www.legislation.gov.uk/ukpga/2022/46/section/1
  23. Product Security and Telecommunications Infrastructure Act 2022, s.5. https://www.legislation.gov.uk/ukpga/2022/46/section/5
  24. Product Security and Telecommunications Infrastructure Act 2022, s.8. https://www.legislation.gov.uk/ukpga/2022/46/section/8
  25. Product Security and Telecommunications Infrastructure Act 2022, s.9. https://www.legislation.gov.uk/ukpga/2022/46/section/9
  26. Product Security and Telecommunications Infrastructure Act 2022, s.32. https://www.legislation.gov.uk/ukpga/2022/46/section/32
  27. Product Security and Telecommunications Infrastructure Act 2022, s.36. https://www.legislation.gov.uk/ukpga/2022/46/section/36
  28. Product Security and Telecommunications Infrastructure Act 2022, s.38. https://www.legislation.gov.uk/ukpga/2022/46/section/38
  29. Product Security and Telecommunications Infrastructure Act 2022, s.55. https://www.legislation.gov.uk/ukpga/2022/46/section/55
  30. The Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, Schedule 1. https://www.legislation.gov.uk/uksi/2023/1007/schedule/1/made
  31. The Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, Schedule 3. https://www.legislation.gov.uk/uksi/2023/1007/schedule/3/made
  32. The Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023. https://www.legislation.gov.uk/uksi/2023/1007/made
  33. Department for Business, Energy and Industrial Strategy. (2021, December 1). PSTI Bill: product security factsheet. https://www.gov.uk/guidance/the-product-security-and-telecommunications-infrastructure-psti-bill-product-security-factsheet
  34. The Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) (Amendment) Regulations 2025, SI 2025/211. https://www.legislation.gov.uk/uksi/2025/211/made
  35. Tenda. (2026). PSTI statement of compliance. https://www.tendacn.com/uk/psti/default.html
  36. TP-Link. (2026). PSTI statement of compliance. https://www.tp-link.com/uk/support/psti/
  37. Ubiquiti. (2026, August 10). Vulnerability disclosure policy [PDF]. https://dl.ui.com/compliance/vulnerability-disclosure-policy.pdf
  38. Xiaomi. (2026). Product security and telecommunications infrastructure law. https://www.mi.com/uk/support/policy/psticompliance/
  39. Zyxel. (2026, August 12). Product security and telecommunications infrastructure (PSTI) Act. https://www.zyxel.com/service-provider/emea/en/uk-psti-act
  40. Zyxel. (2024, May 1). PSTI Act compliance guide. https://www.zyxel.com/uk/en-gb/support/PSTI_ACT_COMPLIANCE_GUIDE

AJ

Adrian James, Broadband Editor. Every legal claim on this page was taken from legislation.gov.uk or gov.uk and quoted rather than summarised. Every support period was taken from the manufacturer's own published document. We used no vendor blogs, no security company marketing and no news write-ups, which matters on a topic where most coverage repeats a press release. Where a manufacturer publishes nothing we have said so rather than inferring. Reviewed by Dr Alex J. Martin-Smith. Last checked 16 August 2026. Next scheduled check 16 November 2026. If your manufacturer publishes something we have marked as missing, tell us and we will add it and log the change.

Compare deals by postcodeBack to insights hub