Skip to content

Evidence request lists

US Consumer Product Safety Commission (CPSC) - Connected Product Safety

Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Connected Product Cybersecurity

CPSC-CS.1
Network Security for Connected Products

Connected products must implement security measures to prevent network-based attacks that could cause physical harm.

Artefacts an auditor will ask for
  • Software update and remote update security plan
  • Section 15(b) incident reporting procedure
  • Recall plan for connected products
  • End-of-life and end-of-support safety communications
Where this commonly fails
  • Vulnerability disclosure programme absent
  • OTA update integrity controls insufficient
  • Section 15(b) report triage not aligned to connected hazards
  • No formal cybersecurity component in product safety reviews
CPSC-CS.2
Authentication and Access Controls

Connected products must implement authentication mechanisms to prevent unauthorised control of safety-critical functions.

Artefacts an auditor will ask for
  • Connected product hazard analysis and FMEA
  • Section 15(b) incident reporting procedure
  • Cybersecurity assessment against UL 2900-1
  • Software update and remote update security plan
Where this commonly fails
  • No formal cybersecurity component in product safety reviews
  • Vulnerability disclosure programme absent
  • OTA update integrity controls insufficient
  • End-of-life policy missing for safety-relevant firmware
CPSC-CS.3
Data Protection for Safety Systems

Safety-relevant data transmitted by connected products must be protected against tampering and interception.

Artefacts an auditor will ask for
  • Recall plan for connected products
  • Cybersecurity assessment against UL 2900-1
  • Section 15(b) incident reporting procedure
  • Software update and remote update security plan
Where this commonly fails
  • Section 15(b) report triage not aligned to connected hazards
  • OTA update integrity controls insufficient
  • End-of-life policy missing for safety-relevant firmware
  • Vulnerability disclosure programme absent
CPSC-CS.4
Vulnerability Disclosure

Manufacturers should establish vulnerability disclosure programmes for security issues affecting product safety.

Artefacts an auditor will ask for
  • End-of-life and end-of-support safety communications
  • Recall plan for connected products
  • Cybersecurity assessment against UL 2900-1
  • Section 15(b) incident reporting procedure
Where this commonly fails
  • Section 15(b) report triage not aligned to connected hazards
  • No formal cybersecurity component in product safety reviews
  • Vulnerability disclosure programme absent
  • OTA update integrity controls insufficient

Cybersecurity Hazard

USCPSC-2
Connected Product Cybersecurity Hazard Identification

Per CPSC + NIST IR 8425: Connected Product Cybersecurity Hazard Identification + risk assessment + alignment with NIST + secure default configuration.

Artefacts an auditor will ask for
  • CPSC evidence for USCPSC-2
Where this commonly fails
  • Sec 15(b) + connected product partial

Hazard and Risk Assessment

CPSC-RA.1
Hazard Analysis for Connected Products

Manufacturers must analyse the likelihood and severity of injury for each expected function a connected product performs.

Artefacts an auditor will ask for
  • Connected product hazard analysis and FMEA
  • Software update and remote update security plan
  • Recall plan for connected products
  • Cybersecurity assessment against UL 2900-1
Where this commonly fails
  • End-of-life policy missing for safety-relevant firmware
  • OTA update integrity controls insufficient
  • Section 15(b) report triage not aligned to connected hazards
  • No formal cybersecurity component in product safety reviews
CPSC-RA.2
Failure Modes and Effects Analysis

Manufacturers must conduct FMEA covering safety-critical functions including software and firmware components.

Artefacts an auditor will ask for
  • Cybersecurity assessment against UL 2900-1
  • Recall plan for connected products
  • Software update and remote update security plan
  • Section 15(b) incident reporting procedure
Where this commonly fails
  • End-of-life policy missing for safety-relevant firmware
  • No formal cybersecurity component in product safety reviews
  • OTA update integrity controls insufficient
  • Section 15(b) report triage not aligned to connected hazards
CPSC-RA.3
Lifecycle Risk Assessment

Risk analysis must cover every stage of the product lifecycle including software updates and end-of-life scenarios.

Artefacts an auditor will ask for
  • Software update and remote update security plan
  • Recall plan for connected products
  • Section 15(b) incident reporting procedure
  • End-of-life and end-of-support safety communications
Where this commonly fails
  • OTA update integrity controls insufficient
  • No formal cybersecurity component in product safety reviews
  • Section 15(b) report triage not aligned to connected hazards
  • End-of-life policy missing for safety-relevant firmware
CPSC-RA.4
Critical Component Identification

Manufacturers must identify components critical to safe operation including power supplies, sensors, software, and electronics.

Artefacts an auditor will ask for
  • End-of-life and end-of-support safety communications
  • Recall plan for connected products
  • Cybersecurity assessment against UL 2900-1
  • Section 15(b) incident reporting procedure
Where this commonly fails
  • End-of-life policy missing for safety-relevant firmware
  • No formal cybersecurity component in product safety reviews
  • OTA update integrity controls insufficient
  • Section 15(b) report triage not aligned to connected hazards

Post-Market Monitoring and Recall

CPSC-PM.1
Incident Monitoring and Reporting

Manufacturers must monitor and report safety incidents related to connected product cyber vulnerabilities.

Artefacts an auditor will ask for
  • Recall plan for connected products
  • Software update and remote update security plan
  • Section 15(b) incident reporting procedure
  • Cybersecurity assessment against UL 2900-1
Where this commonly fails
  • End-of-life policy missing for safety-relevant firmware
  • Vulnerability disclosure programme absent
  • No formal cybersecurity component in product safety reviews
  • OTA update integrity controls insufficient
CPSC-PM.2
Product Recall Procedures

Procedures must be in place for issuing recalls when connected product vulnerabilities create imminent safety hazards.

Artefacts an auditor will ask for
  • Cybersecurity assessment against UL 2900-1
  • Software update and remote update security plan
  • Section 15(b) incident reporting procedure
  • Recall plan for connected products
Where this commonly fails
  • No formal cybersecurity component in product safety reviews
  • End-of-life policy missing for safety-relevant firmware
  • OTA update integrity controls insufficient
  • Section 15(b) report triage not aligned to connected hazards
CPSC-PM.3
End-of-Life Safety Planning

Manufacturers must plan for safe product behaviour when connected features are discontinued or support ends.

Artefacts an auditor will ask for
  • Software update and remote update security plan
  • Recall plan for connected products
  • Connected product hazard analysis and FMEA
  • End-of-life and end-of-support safety communications
Where this commonly fails
  • Section 15(b) report triage not aligned to connected hazards
  • End-of-life policy missing for safety-relevant firmware
  • OTA update integrity controls insufficient
  • No formal cybersecurity component in product safety reviews
CPSC-PM.4
Consumer Safety Communication

Manufacturers must provide clear safety information to consumers about connected product risks and mitigations.

Artefacts an auditor will ask for
  • Software update and remote update security plan
  • Recall plan for connected products
  • Connected product hazard analysis and FMEA
  • End-of-life and end-of-support safety communications
Where this commonly fails
  • OTA update integrity controls insufficient
  • Section 15(b) report triage not aligned to connected hazards
  • End-of-life policy missing for safety-relevant firmware
  • Vulnerability disclosure programme absent

Recall

USCPSC-3
Recall, Corrective Action, SaferProducts.gov

Per CPSC: Voluntary Recall Notice + Corrective Action Plan + SaferProducts.gov Complaint Monitoring.

Artefacts an auditor will ask for
  • CPSC evidence for USCPSC-3
Where this commonly fails
  • Sec 15(b) + connected product partial

Reporting

USCPSC-1
Section 15(b) Substantial Product Hazard Reporting

Per US Consumer Product Safety Act Section 15(b): Substantial Product Hazard Reporting to CPSC within 24 hours of obtaining information including cybersecurity hazards.

Artefacts an auditor will ask for
  • CPSC evidence for USCPSC-1
Where this commonly fails
  • Sec 15(b) + connected product partial

Software and Firmware Integrity

CPSC-SW.1
Secure Software Development

Connected product software must be developed following secure coding practices to prevent safety-related failures.

Artefacts an auditor will ask for
  • Software update and remote update security plan
  • Recall plan for connected products
  • Section 15(b) incident reporting procedure
  • End-of-life and end-of-support safety communications
Where this commonly fails
  • OTA update integrity controls insufficient
  • Section 15(b) report triage not aligned to connected hazards
  • No formal cybersecurity component in product safety reviews
  • Vulnerability disclosure programme absent
CPSC-SW.2
Software Update Safety Verification

Every software update must be assessed for its impact on the safe operation of the connected product.

Artefacts an auditor will ask for
  • Recall plan for connected products
  • End-of-life and end-of-support safety communications
  • Connected product hazard analysis and FMEA
  • Software update and remote update security plan
Where this commonly fails
  • Vulnerability disclosure programme absent
  • OTA update integrity controls insufficient
  • Section 15(b) report triage not aligned to connected hazards
  • No formal cybersecurity component in product safety reviews
CPSC-SW.3
Remote Update Security

Remote software update mechanisms must ensure integrity and authenticity of updates per UL 5500 guidance.

Artefacts an auditor will ask for
  • Recall plan for connected products
  • Connected product hazard analysis and FMEA
  • Section 15(b) incident reporting procedure
  • Software update and remote update security plan
Where this commonly fails
  • Vulnerability disclosure programme absent
  • OTA update integrity controls insufficient
  • End-of-life policy missing for safety-relevant firmware
  • No formal cybersecurity component in product safety reviews
CPSC-SW.4
Firmware Integrity

Firmware must maintain integrity controls to prevent unauthorised modification that could create safety hazards.

Artefacts an auditor will ask for
  • Section 15(b) incident reporting procedure
  • Software update and remote update security plan
  • Cybersecurity assessment against UL 2900-1
  • Connected product hazard analysis and FMEA
Where this commonly fails
  • End-of-life policy missing for safety-relevant firmware
  • No formal cybersecurity component in product safety reviews
  • Vulnerability disclosure programme absent
  • Section 15(b) report triage not aligned to connected hazards

Voluntary Standards Conformance

CPSC-STD.1
UL 2900-1 Cybersecurity Compliance

Connected products should meet UL 2900-1 requirements for software cybersecurity of network-connectable devices.

Artefacts an auditor will ask for
  • Software update and remote update security plan
  • Recall plan for connected products
  • Connected product hazard analysis and FMEA
  • End-of-life and end-of-support safety communications
Where this commonly fails
  • OTA update integrity controls insufficient
  • Section 15(b) report triage not aligned to connected hazards
  • Vulnerability disclosure programme absent
  • End-of-life policy missing for safety-relevant firmware
CPSC-STD.2
UL 5500 Remote Update Compliance

Products with remote software update capability should comply with UL 5500 for safe update processes.

Artefacts an auditor will ask for
  • Software update and remote update security plan
  • End-of-life and end-of-support safety communications
  • Section 15(b) incident reporting procedure
  • Recall plan for connected products
Where this commonly fails
  • No formal cybersecurity component in product safety reviews
  • Vulnerability disclosure programme absent
  • OTA update integrity controls insufficient
  • End-of-life policy missing for safety-relevant firmware
CPSC-STD.3
Voluntary Standards Participation

Manufacturers should participate in development of voluntary safety standards with UL, ASTM, and other bodies.

Artefacts an auditor will ask for
  • Recall plan for connected products
  • Connected product hazard analysis and FMEA
  • Section 15(b) incident reporting procedure
  • Software update and remote update security plan
Where this commonly fails
  • Section 15(b) report triage not aligned to connected hazards
  • No formal cybersecurity component in product safety reviews
  • Vulnerability disclosure programme absent
  • OTA update integrity controls insufficient
CPSC-STD.4
Interoperability Safety

Safety implications of product interoperability with other connected devices must be evaluated and mitigated.

Artefacts an auditor will ask for
  • Connected product hazard analysis and FMEA
  • End-of-life and end-of-support safety communications
  • Section 15(b) incident reporting procedure
  • Cybersecurity assessment against UL 2900-1
Where this commonly fails
  • Section 15(b) report triage not aligned to connected hazards
  • Vulnerability disclosure programme absent
  • No formal cybersecurity component in product safety reviews
  • End-of-life policy missing for safety-relevant firmware
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US Consumer Product Safety Commission (CPSC) - Connected Product Safety framework page.