US Consumer Product Safety Commission (CPSC) - Connected Product Safety
Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Connected Product Cybersecurity
Connected products must implement security measures to prevent network-based attacks that could cause physical harm.
- Software update and remote update security plan
- Section 15(b) incident reporting procedure
- Recall plan for connected products
- End-of-life and end-of-support safety communications
- Vulnerability disclosure programme absent
- OTA update integrity controls insufficient
- Section 15(b) report triage not aligned to connected hazards
- No formal cybersecurity component in product safety reviews
Connected products must implement authentication mechanisms to prevent unauthorised control of safety-critical functions.
- Connected product hazard analysis and FMEA
- Section 15(b) incident reporting procedure
- Cybersecurity assessment against UL 2900-1
- Software update and remote update security plan
- No formal cybersecurity component in product safety reviews
- Vulnerability disclosure programme absent
- OTA update integrity controls insufficient
- End-of-life policy missing for safety-relevant firmware
Safety-relevant data transmitted by connected products must be protected against tampering and interception.
- Recall plan for connected products
- Cybersecurity assessment against UL 2900-1
- Section 15(b) incident reporting procedure
- Software update and remote update security plan
- Section 15(b) report triage not aligned to connected hazards
- OTA update integrity controls insufficient
- End-of-life policy missing for safety-relevant firmware
- Vulnerability disclosure programme absent
Manufacturers should establish vulnerability disclosure programmes for security issues affecting product safety.
- End-of-life and end-of-support safety communications
- Recall plan for connected products
- Cybersecurity assessment against UL 2900-1
- Section 15(b) incident reporting procedure
- Section 15(b) report triage not aligned to connected hazards
- No formal cybersecurity component in product safety reviews
- Vulnerability disclosure programme absent
- OTA update integrity controls insufficient
Cybersecurity Hazard
Per CPSC + NIST IR 8425: Connected Product Cybersecurity Hazard Identification + risk assessment + alignment with NIST + secure default configuration.
- CPSC evidence for USCPSC-2
- Sec 15(b) + connected product partial
Hazard and Risk Assessment
Manufacturers must analyse the likelihood and severity of injury for each expected function a connected product performs.
- Connected product hazard analysis and FMEA
- Software update and remote update security plan
- Recall plan for connected products
- Cybersecurity assessment against UL 2900-1
- End-of-life policy missing for safety-relevant firmware
- OTA update integrity controls insufficient
- Section 15(b) report triage not aligned to connected hazards
- No formal cybersecurity component in product safety reviews
Manufacturers must conduct FMEA covering safety-critical functions including software and firmware components.
- Cybersecurity assessment against UL 2900-1
- Recall plan for connected products
- Software update and remote update security plan
- Section 15(b) incident reporting procedure
- End-of-life policy missing for safety-relevant firmware
- No formal cybersecurity component in product safety reviews
- OTA update integrity controls insufficient
- Section 15(b) report triage not aligned to connected hazards
Risk analysis must cover every stage of the product lifecycle including software updates and end-of-life scenarios.
- Software update and remote update security plan
- Recall plan for connected products
- Section 15(b) incident reporting procedure
- End-of-life and end-of-support safety communications
- OTA update integrity controls insufficient
- No formal cybersecurity component in product safety reviews
- Section 15(b) report triage not aligned to connected hazards
- End-of-life policy missing for safety-relevant firmware
Manufacturers must identify components critical to safe operation including power supplies, sensors, software, and electronics.
- End-of-life and end-of-support safety communications
- Recall plan for connected products
- Cybersecurity assessment against UL 2900-1
- Section 15(b) incident reporting procedure
- End-of-life policy missing for safety-relevant firmware
- No formal cybersecurity component in product safety reviews
- OTA update integrity controls insufficient
- Section 15(b) report triage not aligned to connected hazards
Post-Market Monitoring and Recall
Manufacturers must monitor and report safety incidents related to connected product cyber vulnerabilities.
- Recall plan for connected products
- Software update and remote update security plan
- Section 15(b) incident reporting procedure
- Cybersecurity assessment against UL 2900-1
- End-of-life policy missing for safety-relevant firmware
- Vulnerability disclosure programme absent
- No formal cybersecurity component in product safety reviews
- OTA update integrity controls insufficient
Procedures must be in place for issuing recalls when connected product vulnerabilities create imminent safety hazards.
- Cybersecurity assessment against UL 2900-1
- Software update and remote update security plan
- Section 15(b) incident reporting procedure
- Recall plan for connected products
- No formal cybersecurity component in product safety reviews
- End-of-life policy missing for safety-relevant firmware
- OTA update integrity controls insufficient
- Section 15(b) report triage not aligned to connected hazards
Manufacturers must plan for safe product behaviour when connected features are discontinued or support ends.
- Software update and remote update security plan
- Recall plan for connected products
- Connected product hazard analysis and FMEA
- End-of-life and end-of-support safety communications
- Section 15(b) report triage not aligned to connected hazards
- End-of-life policy missing for safety-relevant firmware
- OTA update integrity controls insufficient
- No formal cybersecurity component in product safety reviews
Manufacturers must provide clear safety information to consumers about connected product risks and mitigations.
- Software update and remote update security plan
- Recall plan for connected products
- Connected product hazard analysis and FMEA
- End-of-life and end-of-support safety communications
- OTA update integrity controls insufficient
- Section 15(b) report triage not aligned to connected hazards
- End-of-life policy missing for safety-relevant firmware
- Vulnerability disclosure programme absent
Recall
Per CPSC: Voluntary Recall Notice + Corrective Action Plan + SaferProducts.gov Complaint Monitoring.
- CPSC evidence for USCPSC-3
- Sec 15(b) + connected product partial
Reporting
Per US Consumer Product Safety Act Section 15(b): Substantial Product Hazard Reporting to CPSC within 24 hours of obtaining information including cybersecurity hazards.
- CPSC evidence for USCPSC-1
- Sec 15(b) + connected product partial
Software and Firmware Integrity
Connected product software must be developed following secure coding practices to prevent safety-related failures.
- Software update and remote update security plan
- Recall plan for connected products
- Section 15(b) incident reporting procedure
- End-of-life and end-of-support safety communications
- OTA update integrity controls insufficient
- Section 15(b) report triage not aligned to connected hazards
- No formal cybersecurity component in product safety reviews
- Vulnerability disclosure programme absent
Every software update must be assessed for its impact on the safe operation of the connected product.
- Recall plan for connected products
- End-of-life and end-of-support safety communications
- Connected product hazard analysis and FMEA
- Software update and remote update security plan
- Vulnerability disclosure programme absent
- OTA update integrity controls insufficient
- Section 15(b) report triage not aligned to connected hazards
- No formal cybersecurity component in product safety reviews
Remote software update mechanisms must ensure integrity and authenticity of updates per UL 5500 guidance.
- Recall plan for connected products
- Connected product hazard analysis and FMEA
- Section 15(b) incident reporting procedure
- Software update and remote update security plan
- Vulnerability disclosure programme absent
- OTA update integrity controls insufficient
- End-of-life policy missing for safety-relevant firmware
- No formal cybersecurity component in product safety reviews
Firmware must maintain integrity controls to prevent unauthorised modification that could create safety hazards.
- Section 15(b) incident reporting procedure
- Software update and remote update security plan
- Cybersecurity assessment against UL 2900-1
- Connected product hazard analysis and FMEA
- End-of-life policy missing for safety-relevant firmware
- No formal cybersecurity component in product safety reviews
- Vulnerability disclosure programme absent
- Section 15(b) report triage not aligned to connected hazards
Voluntary Standards Conformance
Connected products should meet UL 2900-1 requirements for software cybersecurity of network-connectable devices.
- Software update and remote update security plan
- Recall plan for connected products
- Connected product hazard analysis and FMEA
- End-of-life and end-of-support safety communications
- OTA update integrity controls insufficient
- Section 15(b) report triage not aligned to connected hazards
- Vulnerability disclosure programme absent
- End-of-life policy missing for safety-relevant firmware
Products with remote software update capability should comply with UL 5500 for safe update processes.
- Software update and remote update security plan
- End-of-life and end-of-support safety communications
- Section 15(b) incident reporting procedure
- Recall plan for connected products
- No formal cybersecurity component in product safety reviews
- Vulnerability disclosure programme absent
- OTA update integrity controls insufficient
- End-of-life policy missing for safety-relevant firmware
Manufacturers should participate in development of voluntary safety standards with UL, ASTM, and other bodies.
- Recall plan for connected products
- Connected product hazard analysis and FMEA
- Section 15(b) incident reporting procedure
- Software update and remote update security plan
- Section 15(b) report triage not aligned to connected hazards
- No formal cybersecurity component in product safety reviews
- Vulnerability disclosure programme absent
- OTA update integrity controls insufficient
Safety implications of product interoperability with other connected devices must be evaluated and mitigated.
- Connected product hazard analysis and FMEA
- End-of-life and end-of-support safety communications
- Section 15(b) incident reporting procedure
- Cybersecurity assessment against UL 2900-1
- Section 15(b) report triage not aligned to connected hazards
- Vulnerability disclosure programme absent
- No formal cybersecurity component in product safety reviews
- End-of-life policy missing for safety-relevant firmware
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US Consumer Product Safety Commission (CPSC) - Connected Product Safety framework page.