FS Register FRN 1029698

54 Five Star Google Reviews

13+ years specialist broking experience

General information, not advice. Written for general guidance and drawing on external sources as well as our own experience. It isn't a personal recommendation and doesn't take account of your circumstances — full disclaimer and sources.

A man checks a home for smart technology

Smart Home Manufacturer Insurance UK: IoT, Lithium & PSTI

April 12, 2026

Published: 21 May 2026 | Reading time: 24 minutes | Category: Manufacturing | Author: John Miller, Miller & Partner

Last reviewed by John Miller — 12 August 2026
FS Register FRN 1029698 13+ years specialist commercial broking Direct access to Lloyd's Market & specialist MGAs UK-based independent broker

Why does UK smart home manufacturing need specialist insurance treatment in 2026?

Smart home manufacturing sits at the most regulated edge of UK consumer manufacturing. A connected door lock isn't just a lock — it's a hardware product subject to strict product liability under the Consumer Protection Act 1987, a connectable product subject to mandatory cybersecurity requirements under the Product Security and Telecommunications Infrastructure Act 2022, a lithium-battery-powered device subject to fire safety scrutiny by the Office for Product Safety and Standards (OPSS), a data-collecting device subject to UK GDPR, and a piece of intellectual property in a market crowded with patent assertions. None of these regulatory layers existed in their current form a decade ago. All of them are tightening through 2026.

The risk profile is fundamentally different from generic electronics or hardware manufacturing. When a kettle fails, the worst-case scenario is property damage and a fire. When a smart lock fails, the worst-case scenario is the same — plus a data breach exposing the user's location history, plus an unauthorised remote access incident, plus a cybersecurity prosecution under PSTI, plus a UK GDPR enforcement action, plus a recall obligation flowing through online marketplaces that themselves now carry statutory duties under the Product Regulation and Metrology Act 2025. The legal cause of action stacks vertically in a way generic consumer products don't.

For UK smart home manufacturers in 2026, insurance is no longer a single-policy decision. It's a programme of interlocking covers — Public Liability with broad product scope, Product Liability with explicit IoT and software-failure scope, Product Recall, Professional Indemnity for design and consultancy work, Cyber with first-party and third-party liability scope, Directors and Officers, and increasingly Environmental Impairment Liability for lithium fire scenarios. The cover decisions made at the proposal stage now have a direct relationship to whether a fire claim, a cyber breach, or a PSTI prosecution becomes a recoverable loss or a business-ending uninsured event.

This guide is the definitive 2026 reference for UK smart home and connected-product manufacturers. It complements our sister articles on 3D printing company insurance, electronics design business insurance, and robotics startup insurance, and sits alongside our broader AI and tech and cyber insurance product lines. For the production side of the business, including machinery breakdown and business interruption, see our manufacturing insurance page.

Key facts at a glance

  1. The PSTI Act regime came into force on 29 April 2024 — mandatory minimum cybersecurity requirements for UK consumer connectable products, with enforcement by the Office for Product Safety and Standards. Maximum penalties are £10 million or 4% of global revenue (whichever is higher), with daily penalties of up to £20,000 for continuing breaches.
  2. The Product Regulation and Metrology Act 2025 received Royal Assent on 21 July 2025 — for the first time, UK product safety law explicitly covers intangible components including software, AI algorithms, and digital services. Online marketplaces are inside the regulatory perimeter.
  3. UK lithium-ion battery fires reached 1,760 incidents in 2025 — a 147% rise over three years, equivalent to 4.8 fires per day across UK fire and rescue services. Smart home devices with rechargeable batteries (smart locks, doorbells, sensors, hubs) carry the same thermal runaway exposure as larger consumer devices.
  4. Sedgwick recorded 14,484 product recall events across the UK and EU in 2024 — the highest annual total on record, up from 12,503 in 2023. Smart home and connected products are the fastest-growing category.
  5. The Consumer Protection Act 1987 imposes strict liability on producers, importers, and own-branders of defective products. Strict liability means the claimant does not need to prove negligence — only that the product was defective and caused harm. The 10-year long-stop applies from the date of supply.
  6. The UK government currently accepts both CE and UKCA marking indefinitely for most consumer electronics categories under the Product Safety and Metrology etc (Amendment) Regulations 2024 — but Northern Ireland requires CE, and manufacturers must still complete the underlying conformity assessment.
  7. Smart home manufacturer insurance premiums typically run £3,500–£12,000 for small operators and £15,000–£60,000+ for mid-sized firms with international distribution — pricing depends on product mix, lithium exposure, software architecture, recall history, and turnover.
£10m Maximum PSTI Act penalty per breach — or 4% of global revenue, whichever is higher, plus £20k daily for continuing breaches
14,484 UK and EU product recall events in 2024 — Sedgwick Brand Protection's highest annual total on record
1,760 UK lithium-ion battery fires in 2025 — 147% rise over three years per QBE FOI data from UK fire services
10 years CPA 1987 long-stop period from date of supply — strict liability defective product claims can surface a decade post-sale

1. The 8 biggest smart home manufacturing risks: summary table

The risks below are ranked by combined frequency, severity, and regulatory consequence under the 2026 framework. Some — product liability, lithium fire — are catastrophic-tail. Others — cyber, recall — are operational realities for most growing IoT firms. Several overlap a single incident (a lithium fire in a smart speaker can engage product liability, recall, cyber if linked to firmware, regulatory enforcement under PSTI, and reputational damage simultaneously). The intelligent operator manages all eight simultaneously rather than treating them as discrete buckets.

Risk Frequency Severity Primary Cover
Product liability — defective product personal injury / property damage Occasional High (£25k–£500k+) Product Liability with IoT scope
Lithium-ion battery fire (thermal runaway) Rising sharply High-Catastrophic (£15k–£2m+) Product Liability, EIL, BI
Product recall and post-launch defect management Routine for established product lines Medium-High (£50k–£500k+ direct costs) Product Recall
Cyber breach, IoT botnet, firmware compromise Common High (£50k–£500k typical, £2m+ outliers) Cyber with IoT first-party scope
PSTI Act non-compliance and OPSS enforcement Rising — regime new since April 2024 Catastrophic (£10m fines, prosecution) Legal Expenses, D&O
Supply chain, component failure, counterfeit risk Common during scale-up Medium-High (£20k–£300k typical) Stock, Product Liability, Trade Credit
IP infringement and patent assertion Rising in connected products Medium-High (£30k–£500k+ defence) IP Liability, Legal Expenses
Insurance non-disclosure under Insurance Act 2015 Common (often unnoticed) Catastrophic (cover voided) No insurance response — preventable at proposal

2. How has the PSTI Act 2022 changed the IoT manufacturer risk profile?

The Product Security and Telecommunications Infrastructure Act 2022 — known as the PSTI Act — is the single most important regulatory development for UK smart home manufacturers in the last decade. Part 1 of the Act, supported by the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, came into force on 29 April 2024. From that date, every UK consumer connectable product placed on the UK market — every smart speaker, smart lock, smart camera, smart hub, smart appliance, wearable, baby monitor, connected toy — has been legally required to meet three minimum cybersecurity requirements:

  • No universal default passwords — devices must ship with unique-per-device passwords or force users to set a password at first configuration.
  • A published means to manage vulnerabilities — at minimum, a contact point where security researchers and the public can report vulnerabilities, with stated acknowledgement and update timeframes.
  • A published defined support period — the minimum length of time the manufacturer will provide security updates, declared at point of sale and visible on online listings.

Each in-scope product must be accompanied by a statement of compliance containing the prescribed information in Schedule 4 of the PSTI Regulations. Enforcement sits with the Office for Product Safety and Standards (OPSS). Penalties for non-compliance can reach £10 million or 4% of global revenue, with daily penalties of up to £20,000 for continuing breaches, plus product bans, stop-sale notices, and mandatory recalls.

This created four distinct insurance exposure shifts that didn't exist before April 2024:

Exposure shift 1: Regulatory enforcement is no longer theoretical

Before PSTI, UK IoT cybersecurity was governed by voluntary codes of practice. From April 2024 onward, non-compliance is a statutory breach with criminal-equivalent penalties. The legal defence cost profile of an OPSS investigation now resembles HSE prosecution defence — £75k–£250k of legal cost for a contested matter, which Legal Expenses insurance can pick up but only where the policy is specifically scoped to include OPSS/PSTI investigation. Generic Legal Expenses with HMRC and employment scope typically isn't sufficient.

Exposure shift 2: Product Liability scope must include software

The PSTI duties extend not just to hardware but to firmware, companion apps, and supporting cloud services. A product liability claim where the cause is a software vulnerability rather than hardware failure (e.g. a smart lock that could be unlocked remotely due to a firmware bug, leading to a burglary) now has a clearer route to liability — and Product Liability cover must contemplate software-cause defects, not just manufacturing defects. Generic Public Liability with vanilla product extension may exclude these scenarios.

Exposure shift 3: Recall exposure expanded materially

OPSS now has explicit power to require recalls or stop-sales for PSTI non-compliance independent of any safety defect. A product that's perfectly safe but ships with a default password can be ordered off the market. The direct cost of a smart home product recall — customer communications, return logistics, replacement product, brand damage, retailer relationships — routinely runs £100k–£500k for an established product line. Specialist Product Recall cover is now mainstream rather than optional.

Exposure shift 4: Online marketplace obligations cascading down to manufacturers

The Product Regulation and Metrology Act 2025 brings online marketplaces (Amazon, eBay, Etsy, TikTok Shop, others) inside the UK product safety perimeter. Marketplaces are increasingly required to demand evidence of conformity from manufacturers selling through their platforms. Manufacturers without robust technical files, statements of compliance, and recall response capability face delisting — a commercial death sentence for a small or mid-sized smart home firm relying on marketplace distribution.

What this means for your insurance programme Smart home manufacturer insurance bought before April 2024 — and not reviewed since — is almost certainly inadequate for the 2026 regulatory landscape. The cover gaps are: software-cause defects within Product Liability scope; OPSS/PSTI investigation within Legal Expenses; first-party recall costs within Product Recall scope; firmware compromise within Cyber scope. A specialist broker review is the right starting point. Coverage built for traditional consumer hardware isn't built for connected products with the layered statutory framework above them.

3. Risk 1: Product liability under the Consumer Protection Act 1987

Product Liability — The Strict Liability Backbone

High severity Frequency: occasional but rising Consumer Protection Act 1987 Strict liability — no proof of fault needed

The Consumer Protection Act 1987 implements strict liability for defective products. A claimant injured by — or whose property is damaged by — a defective consumer product does not need to prove the manufacturer was negligent. They only need to prove: (a) the product was defective; (b) the defect caused harm; (c) the defendant is a producer, own-brander, or importer into the UK. The 10-year long-stop runs from the date the specific product was supplied. For smart home manufacturers, this means a product sold in 2026 can still generate a claim in 2036.

What counts as "defective"? Section 3 of the CPA defines defect as the product not providing the safety persons generally are entitled to expect, considering its presentation, intended use, and the time of supply. For smart home products in 2026, consumer expectations include not just physical safety but cybersecurity reasonableness — a smart lock that a competent attacker can defeat with a known exploit may be defective even if it physically functions. The Law Commission's 14th Programme of Law Reform is actively reviewing the regime to confirm and codify how software defects, cyber vulnerabilities, and AI failures map into the CPA framework.

Operational mitigations

Documented design control process with risk assessment per product; ISO 9001 quality management system or equivalent; competent third-party testing aligned to relevant harmonised standards (EN 18031 for IoT cybersecurity, EN 62368-1 for AV/IT equipment safety, EN 60335 for household appliances, EN 50663 for radio equipment); CE/UKCA conformity assessment with retained technical file; clear instructions and warnings in plain English at appropriate reading level; post-market surveillance system with vulnerability reporting and incident tracking; supply chain quality audits including component traceability.

Insurance response

Product Liability is the primary response — typically structured within a Public Liability + Products Liability combined limit (£5m–£25m for small to mid-sized manufacturers). Critical scope considerations: software-cause defects explicitly included; cyber-related defects not excluded; financial loss following physical injury or damage included; worldwide territorial scope where exporting; USA/Canada extension where applicable (premium typically 1.5–3× UK-only). The CPA's strict liability framework means even competent manufacturers face claims they cannot defend on negligence grounds — Product Liability is the only meaningful financial protection. Claim values £25k–£500k for typical personal injury or property damage; catastrophic claims (e.g. house fire from a defective smart device) can reach £1m–£2m+.

4. Risk 2: Lithium-ion battery fire and thermal runaway

Lithium-Ion Fire — The Catastrophic Tail Risk

High-Catastrophic severity Frequency: rising sharply across sector OPSS PFN reporting regime EN IEC 62133-2 battery safety

UK fire and rescue services attended 1,760 lithium-ion battery fires in 2025, according to QBE's analysis of fire service data — a 147% increase over three years, with e-bikes accounting for 520 of them. While e-bikes and e-scooters dominate the visible statistics, the same thermal runaway mechanism applies to smart home products: smart locks, video doorbells, security cameras, smart sensors, smart hubs, robot vacuums, and any cordless device with a rechargeable lithium cell. When a lithium battery enters thermal runaway, the cell can release flammable gases at temperatures exceeding 600°C — sufficient to ignite surrounding building materials. For a smart home product positioned permanently in a domestic environment, the worst-case scenario is a whole-home fire with multiple occupants.

The claim consequence is the most severe in the smart home sector. A single product-cause house fire can generate: a CPA 1987 strict liability claim for property damage (the home and contents); personal injury claims including the most severe (smoke inhalation, burns, fatality); subrogated claims from the homeowner's insurer; consequential business interruption claims if the property contained a home business; and regulatory engagement with OPSS through the product-related fire notification (PFN) system that may trigger mandatory recall.

Operational mitigations

Specification of lithium cells from established manufacturers with documented quality systems; testing to EN IEC 62133-2 for portable lithium batteries; testing to UN 38.3 for transport; battery management system (BMS) design with cell-level temperature monitoring and protection circuits; thermal runaway containment design (cell spacing, vent paths); charging circuit conformity with relevant standards; documented incoming inspection and lot acceptance testing; serial-number traceability from cell supplier through finished product; clear consumer information on safe charging, storage temperature limits, and end-of-life disposal; pro-active OPSS PFN reporting and engagement on any field incident.

Insurance response

Product Liability is the primary response but lithium-specific scope matters — some markets impose battery sub-limits or apply fire exclusions to cordless/rechargeable categories. Environmental Impairment Liability provides the often-overlooked second layer covering chemical contamination from lithium fire residues and firefighting water runoff. Business Interruption with extended period cover responds to recall-triggered loss of sales. Specialist placement is materially different from generic manufacturer's PL — the difference between a £15k premium with a £100k battery sub-limit and a £25k premium with full battery scope can mean the difference between a recoverable £800k claim and a part-uninsured one.

5. Risk 3: Product recall and post-launch defect management

Product Recall — The Operational Reality

Medium-High severity Frequency: routine for established lines GPSR Regulations 2005 PRMA 2025

Sedgwick Brand Protection recorded 14,484 product recall events across the UK and Europe in 2024 — the highest annual total on record. Recalls happen for safety defects (the typical case), regulatory non-compliance (e.g. PSTI default password violation), labelling errors, or supplier-component issues discovered post-launch. For smart home manufacturers, a recall is a near-certainty over a 5–7 year product lifecycle on any successful line — and the direct cost of a recall is the single biggest predictable operational exposure outside of catastrophic product liability claims.

The direct cost profile of a typical UK smart home recall: customer notification (£8k–£40k depending on channel mix); return logistics including pre-paid return postage and warehouse intake (£15k–£80k); replacement product or refund value (depends on units sold and product price); destruction or disposal costs (£5k–£30k); brand communications and PR support (£10k–£60k); legal advice and OPSS engagement (£15k–£60k); retailer relationships including shelf-pull cost compensation (£10k–£100k). Total: £100k–£500k for a mid-sized recall, £500k+ for major lines.

Operational mitigations

Documented recall plan rehearsed at least annually; serial-number traceability with real-time stock locator; customer database with current contact information at point of sale; established relationships with return logistics providers; pre-drafted customer communication templates including multilingual options where applicable; trained recall response team with defined roles; clear escalation criteria from incident report to formal recall; pre-engagement with OPSS so the regulator is a known contact at point of need; financial reserve or insurance funding for recall direct costs at typical scale.

Insurance response

Specialist product recall insurance is the primary response. Cover should include: first-party recall direct costs (notification, logistics, replacement, destruction); third-party recall costs where flowing through distributors; crisis management and PR; extra expenses to maintain delivery commitments; loss of profit during recall period; legal advice and regulatory engagement. Specialist policies typically run £50k–£500k limits for small to mid-sized manufacturers at £4k–£15k premium. Generic Product Liability does not normally include first-party recall costs — the assumption that "my PL will cover recall" is one of the most expensive misconceptions in IoT manufacturing.

6. Risk 4: Cyber, data breach, and IoT botnet exposure

Cyber and Data Breach — The IoT-Specific Exposure

High severity Frequency: common UK GDPR / DPA 2018 PSTI Act vulnerability disclosure

Smart home manufacturers carry three distinct cyber exposures that traditional consumer manufacturers don't: (1) the manufacturer's own corporate IT and customer database, in common with all businesses; (2) the cloud infrastructure supporting deployed devices, which if breached can expose live device telemetry from thousands of customers' homes; (3) the deployed device estate itself, which if compromised can be conscripted into botnets (the Mirai botnet incident remains the canonical example) or used as an attack vector into the customer's home network. Each generates a different claim profile.

The 2026 claim driver mix for smart home manufacturers: corporate ransomware (typical £40k–£200k recovery cost plus business interruption); cloud platform breach exposing customer telemetry (£75k–£500k including UK GDPR enforcement, customer notification, credit monitoring, regulatory investigation); firmware vulnerability requiring emergency over-the-air patch deployment (£30k–£150k engineering response plus reputational); third-party class-action style claims following large breaches (rising under group litigation order trends). The Information Commissioner's Office (ICO) can impose UK GDPR penalties up to £17.5m or 4% of global turnover.

Operational mitigations

Secure development lifecycle aligned to ETSI EN 303 645 (consumer IoT cybersecurity baseline); penetration testing of finished devices and cloud platform; published vulnerability disclosure policy aligned to ISO/IEC 29147; security patch deployment infrastructure with confirmed update mechanism; UK GDPR-compliant data minimisation with documented lawful basis per data category; encrypted device-to-cloud communication; UK GDPR data processor agreements with cloud providers; cyber insurance with adequate first-party and third-party scope; incident response plan rehearsed annually including ICO notification within 72 hours.

Insurance response

Cyber insurance with explicit IoT manufacturer scope. Critical components: first-party costs (incident response, forensics, ransomware including ransom payment where lawful, business interruption); third-party liability (customer privacy claims, regulatory investigation defence, class-action defence); device-specific cover (cost of OTA patch deployment, device replacement where remediation impossible, bricked device replacement); cloud platform cover where the manufacturer operates or contracts the cloud infrastructure. See our cyber insurance product page for cover principles. Generic Cyber for an office-based business doesn't contemplate IoT device exposure; specialist placement is essential. Limits typically £500k–£5m for small to mid-sized smart home manufacturers.

From recent placement conversations The single most common cover gap I see across smart home manufacturers is the assumption that Public Liability with a product extension is the same as proper Product Liability with IoT-specific scope. It isn't. A PL policy bought through a generic broker for an "electronics manufacturer" almost always carries software and cyber exclusions that aren't immediately obvious — and at claim stage, when a customer brings a CPA 1987 claim alleging a firmware vulnerability caused the harm, the policy doesn't respond as the manufacturer expected. The fix is at proposal stage: specifically declare IoT products, declare software-cause defect cover, declare cyber overlap with product liability, and get written broker confirmation that all of this is within scope. The premium uplift is real but modest. The claim certainty difference is dramatic.

7. Smart home manufacturer insurance cover checker

Select your business profile below to see the cover matched to your specific risk profile. For Miller & Partner's main product pages relevant to smart home manufacturers see AI and tech and cyber insurance.

Smart Home Manufacturer Insurance Cover Checker

Select your business profile to see the recommended insurance programme matched to the 8 main smart home manufacturing risks

Pre-Launch Startup / Prototyping

  • ESSENTIAL Public Liability £2m–£5m with product extension scope for prototype demonstrations and pilot deployments
  • ESSENTIAL Professional Indemnity £250k–£500k for design consultancy and pre-launch IP / specification advice
  • ESSENTIAL Cyber insurance — even pre-launch, customer prospect data and IP carry breach exposure
  • ESSENTIAL Office contents / tools and equipment cover (lab equipment, test rigs, prototypes)
  • RECOMMENDED Directors and Officers liability — investor due diligence requirement at later funding rounds
  • RECOMMENDED IP protection cover (some markets offer pre-launch IP defence cover)
  • CONSIDER Employers' Liability immediately when first employee or paid intern engaged — legal requirement
  • CRITICAL Do not launch to market without Product Liability — see "small manufacturer" tier

Small Manufacturer (Post-Launch, <£500k Turnover)

  • LEGAL Employers' Liability £10m where staff engaged
  • ESSENTIAL Public Liability + Product Liability £5m–£10m combined — explicit IoT and software-cause defect scope
  • ESSENTIAL Product Recall £100k–£250k specialist cover with first-party recall direct costs
  • ESSENTIAL Professional Indemnity £500k for design and consultancy work
  • ESSENTIAL Cyber insurance £500k–£1m with IoT scope and UK GDPR enforcement defence
  • ESSENTIAL Stock cover for finished goods including in-transit and at fulfilment partners
  • ESSENTIAL Office and warehouse / workshop property and contents
  • ESSENTIAL Business Interruption — extended period scope
  • RECOMMENDED Legal Expenses with OPSS/PSTI investigation and HMRC scope

Growth-Stage Manufacturer (£500k–£2m Turnover)

  • LEGAL Employers' Liability £10m comprehensive
  • ESSENTIAL Product Liability £10m with explicit IoT, software, and cyber-related defect scope
  • ESSENTIAL Product Recall £250k–£500k including third-party costs and crisis management
  • ESSENTIAL Professional Indemnity £1m
  • ESSENTIAL Cyber insurance £1m–£2m with full IoT scope including OTA patch deployment costs
  • ESSENTIAL Directors and Officers liability — investor requirement and PSTI/OPSS director exposure
  • ESSENTIAL Environmental Impairment Liability — lithium fire residue and contamination exposure
  • ESSENTIAL Stock, premises, BI comprehensive
  • ESSENTIAL Legal Expenses with OPSS/PSTI/ICO scope
  • RECOMMENDED Trade Credit insurance where significant B2B receivables

Exporting to EU / US Markets

  • CRITICAL Territorial scope extension required — UK-only Product Liability does NOT respond to claims brought in EU or US courts
  • ESSENTIAL Product Liability £10m+ with worldwide territorial scope including USA/Canada extension
  • ESSENTIAL Awareness of EU Cyber Resilience Act (CRA) and General Product Safety Regulation (GPSR) compliance for EU sales
  • ESSENTIAL Product Recall with extra-territorial scope
  • ESSENTIAL Cyber insurance worldwide territorial scope including US class action defence
  • ESSENTIAL Marine cargo insurance for international shipments
  • ESSENTIAL US-distributor agreement review — distributor indemnity clauses can transfer significant risk onto the manufacturer
  • ESSENTIAL Trade Credit covering international receivables
  • RECOMMENDED Legal Expenses with extra-territorial regulatory scope

Lithium-Battery-Powered Products

  • CRITICAL Lithium-specific cover scope — many markets sub-limit or exclude lithium fire scenarios
  • ESSENTIAL Product Liability £10m+ with explicit confirmation that lithium fire is within scope and not sub-limited
  • ESSENTIAL Environmental Impairment Liability — lithium fire residue, firefighting water runoff, contamination
  • ESSENTIAL Product Recall with battery-specific scope
  • ESSENTIAL Documented EN IEC 62133-2 testing evidence for battery cells
  • ESSENTIAL UN 38.3 transport testing for international shipping
  • ESSENTIAL Marine cargo with hazmat lithium battery declarations
  • ESSENTIAL Stock storage cover — lithium battery storage may attract property insurance loadings or specific protection requirements
  • ESSENTIAL Legal Expenses with OPSS PFN engagement scope

Mid-Sized Manufacturer (£2m–£10m+ Turnover)

  • LEGAL Employers' Liability £10m comprehensive
  • ESSENTIAL Product Liability £15m–£25m worldwide scope
  • ESSENTIAL Product Recall £500k–£2m with full cost categories including third-party
  • ESSENTIAL Professional Indemnity £2m
  • ESSENTIAL Cyber insurance £2m–£5m with comprehensive IoT scope
  • ESSENTIAL Directors and Officers liability £5m+ including PSTI/OPSS prosecution defence
  • ESSENTIAL Environmental Impairment Liability comprehensive
  • ESSENTIAL Stock, premises, BI with extended indemnity period
  • ESSENTIAL Marine cargo, goods in transit, in-transit stock cover
  • ESSENTIAL Trade Credit comprehensive — see trade credit insurance
  • ESSENTIAL Legal Expenses comprehensive regulatory scope
  • ESSENTIAL Intellectual Property liability and defence cover

8. PSTI Act readiness self-check

The PSTI Act has reset the documentation and operational expectations for any UK consumer connectable product manufacturer. Tick each compliance discipline your operation has in place. The unchecked items are your priority compliance and insurance gaps.

PSTI Act Readiness Self-Check

Click each compliance discipline you have in place. The more ticked, the lower your PSTI / OPSS enforcement exposure.

  • Unique-per-device passwords or first-use forced password setup — no universal default passwords shipped
  • Published vulnerability disclosure policy — including contact point and acknowledgement / update timeframes
  • Defined support period declared and published — minimum length of time security updates will be provided, visible at point of sale
  • Statement of compliance accompanying each product — content as specified in Schedule 4 of PSTI Regulations
  • Technical file retained and available to OPSS on request — including conformity assessment evidence and product specification
  • Companion app and cloud services included within PSTI scope — security requirements applied across the full product including digital elements
  • Operational vulnerability response capability — security reports actioned within stated timeframes, with patch deployment infrastructure
  • ETSI EN 303 645 alignment for IoT cybersecurity baseline — the working standard for consumer IoT security
  • Online listings show defined support period — distributors and marketplaces display the information consumers see before purchase
  • Importer / distributor agreements include PSTI compliance pass-through — supply chain participants verify and pass compliance evidence
  • Pre-2024 stock review completed — products manufactured before PSTI came into force have been confirmed compliant or withdrawn from sale
  • Insurance specifically declared for IoT and software-cause defect scope — written broker confirmation that Product Liability contemplates connected-product defects
If you ticked 9 or more: Your operation is broadly PSTI-ready and the documentation supports both regulatory compliance and insurance claim defence. Continue refining as OPSS enforcement patterns develop through 2026 and the EU Cyber Resilience Act adds further requirements for EU-distributed products. If you ticked 5–8: Significant gaps exist that need addressing immediately. The PSTI regime has been in force for over two years; OPSS enforcement is no longer hypothetical. Priority: implement missing compliance disciplines and review insurance cover scope simultaneously. If you ticked 4 or fewer: Your operation is materially exposed. The combination of PSTI non-compliance and inadequate insurance scope creates the worst-case scenario where regulatory penalties are uncovered and product liability claims arising from cyber vulnerabilities cannot be defended. Specialist broker review and operational compliance remediation should both happen immediately.

9. Smart home manufacturer risk assessor

Two factors drive smart home manufacturer risk above all others: product category complexity and operational maturity. Use the tool below for your specific risk profile.

Smart Home Manufacturer Risk Assessor

Select your product category and your operational maturity to see your specific risk profile and indicative insurance package

10. Risk 5: Product Regulation and Metrology Act 2025 reform

PRMA 2025 — The Expanding Regulatory Perimeter

High severity Frequency: emerging PRMA 2025 (Royal Assent 21 July 2025) OPSS enforcement

The Product Regulation and Metrology Act 2025 received Royal Assent on 21 July 2025 and represents the most significant restructuring of UK product safety law since the Consumer Protection Act 1987. While the Act itself is enabling legislation — meaning specific duties will be introduced through secondary regulations — its scope sets the direction of travel: for the first time, UK product safety law explicitly covers "intangible components" including software, AI algorithms, and digital services. Online marketplaces are inside the regulatory perimeter and increasingly carry statutory product safety duties of their own. The framework allows selective alignment with EU product safety standards including the EU Cyber Resilience Act and General Product Safety Regulation.

For smart home manufacturers, the practical implications are emerging through 2026 but the direction is clear. Manufacturers will need to maintain documentary evidence that software components meet UK safety expectations — a duty that overlaps with PSTI but extends beyond cybersecurity to broader product safety considerations including AI behaviour, software-driven physical risk, and emergent properties of connected systems. Online marketplaces will demand more rigorous compliance evidence before listing products; manufacturers without robust technical files face delisting from major channels.

Operational mitigations

Technical file maintained per product including software architecture, AI components if any, conformity assessment evidence, and post-market surveillance data; ongoing monitoring of secondary regulations as they are introduced; engagement with OPSS published guidance; marketplace compliance documentation maintained and current; clear assignment of responsibility within the company for product regulatory compliance; competent regulatory affairs support (in-house or external) for complex product categories; awareness of how UK PRMA may diverge from or converge with EU CRA / GPSR for export operations.

Insurance response

Legal Expenses with OPSS investigation and PRMA prosecution scope provides defence cost cover. Directors and Officers liability protects individual directors where prosecution is brought against them personally. The Act preserves the framework of strict liability under the CPA 1987 for civil claims, so Product Liability remains the primary financial protection. Specialist broker placement makes a material difference — the secondary regulations are emerging through 2026/2027 and a broker actively tracking the regime provides better contemporary cover than a generic broker working from a 2023 template.

11. Risk 6: Supply chain, component failure, and counterfeit risk

Supply Chain — The Hidden Liability Multiplier

Medium-High severity Frequency: common during scale-up CPA 1987 producer / importer liability Supply chain quality

Most UK smart home manufacturers operate hybrid supply chains — design and assembly in the UK, with electronic components, PCBs, lithium cells, plastics, and packaging sourced from East Asia. This creates two layers of exposure. First, the manufacturer carries strict liability under the CPA 1987 for defective components even where the underlying defect was a supplier's. The manufacturer's right of indemnity against the supplier is theoretical without enforceable contracts and viable counterparties. Second, the counterfeit component risk in IoT specifically is acute — counterfeit ICs, fake-spec capacitors, sub-standard lithium cells, and clone-spec memory chips routinely enter Western supply chains via lower-tier distributors. A counterfeit component is functionally a defective product from the consumer's standpoint, with full CPA 1987 implications.

The 2024–2025 lithium fire data is particularly relevant here: the QBE FOI analysis identified that the e-bikes involved in fires are often uncertified products retrofitted with faulty or counterfeit components bought through online marketplaces rather than from reputable retailers. The same dynamic applies to lithium-powered smart home products that incorporate sub-standard cells in cost-pressured supply chains. The cell quality is the dominant variable in lithium fire incidence.

Operational mitigations

Supplier qualification process with documented quality requirements; component-level traceability with serial numbers from cell supplier through finished product; periodic supplier audits including unannounced visits where feasible; incoming inspection and lot acceptance testing with documented criteria; sourcing of critical components (especially lithium cells and ICs) directly from authorised distributors rather than online marketplaces or grey-market sources; supplier contracts including warranty pass-through, indemnification, and product liability insurance requirements on the supplier; counterfeit detection awareness training for purchasing and incoming inspection staff; engagement with industry counterfeit databases.

Insurance response

Product Liability provides the primary cover for downstream consumer claims regardless of supply chain cause — but the insurer's subrogation rights against the underlying supplier are only as good as the contracts and counterparty viability behind them. Stock insurance covers finished goods through scrapping if defective batches are identified pre-distribution. Trade Credit insurance covers receivables where B2B distributor relationships are material. The hidden gap is often Marine Cargo for in-transit stock from offshore suppliers — small manufacturers commonly under-insure the in-transit value, leaving a stranded loss exposure if shipments are damaged or lost. See our 3D printing company insurance guide for parallel supply chain considerations.

12. Risk 7: Intellectual property, design rights, and patent disputes

IP Disputes — The Litigation-Heavy Exposure

Medium-High severity Frequency: rising in connected products Patents Act 1977 Registered designs

The smart home category is patent-dense. Established players (Amazon, Google, Apple, Samsung, Honeywell, Resideo, and others) hold extensive portfolios covering wireless protocols, mesh networking, voice processing, sensor fusion, and user interface design. Non-practising entities (NPEs) — frequently described as "patent trolls" in commentary — actively assert older portfolios against new entrants. A UK smart home manufacturer with even modest commercial success becomes a credible target for patent assertion within 24–36 months of market launch. The defence cost profile is acute: even a non-meritorious assertion will incur £30k–£150k in legal cost to dispose of through settlement or summary judgment; a contested trial can reach £500k+.

Registered design rights add a parallel layer. Smart home product design — particularly enclosures, button layouts, and screen interfaces — is increasingly registered. Inadvertent infringement of registered design rights is a routine cause of legal disputes for new entrants. Less frequently but more severely, deliberate copyright infringement claims arise over firmware code, AI training data, and protocol implementations.

Operational mitigations

Pre-launch freedom-to-operate (FTO) search by a qualified patent attorney covering the manufacturer's product category; documented design provenance demonstrating independent development; competent patent attorney relationship maintained for ongoing advice; defensive patent portfolio where commercially justified; engagement with relevant trade associations and standards bodies (cross-licensing relationships often emerge through standards work); insurance proposal at the IP cover stage with clear declaration of pending or threatened IP matters; clear assignment of IP in employment contracts and contractor agreements.

Insurance response

Specialist IP liability and defence cover is the relevant insurance product — typically structured separately from general commercial cover. Cover should include defence of third-party IP infringement claims brought against the manufacturer, and offensive enforcement support where the manufacturer needs to assert its own IP. Limits typically £250k–£2m for small to mid-sized manufacturers. Legal Expenses with IP scope provides a lower-cost partial alternative for smaller operators. See our professional indemnity insurance product page for adjacent cover principles. Generic Public Liability does not cover IP infringement — this is the most common cover assumption gap.

13. Risk 8: Insurance non-disclosure under the Insurance Act 2015

Insurance Non-Disclosure — The Most Preventable Catastrophe

Catastrophic severity Frequency: common (often unnoticed) Insurance Act 2015

The single most common reason UK insurance claims are reduced or declined isn't underwriting fraud or bad luck — it's non-disclosure at the proposal or renewal stage. Smart home manufacturers routinely buy generic manufacturer's or electronics package policies without specifically declaring IoT operations, software-cause defect cover, lithium battery cells, cloud platform operations, or international distribution. The Insurance Act 2015 requires businesses to make a "fair presentation of the risk" — proactively disclosing every material fact the insurer would want to know. Failure to do so allows the insurer to: avoid the policy (treating it as never having existed); reduce the claim proportionally; impose terms that would have applied with proper disclosure.

Operational mitigations

Annual review of declared activities against actual operations; written confirmation from broker that all current activities are within scope; specific declaration of each material exposure at proposal (IoT, software-cause defects, lithium battery cells used, cloud platform operations, territorial distribution, USA/Canada sales, AI features, recall history); mid-term notifications to broker when new product categories, new export markets, or new corporate developments arise; documented response to broker enquiries at renewal; retention of policy documents and broker correspondence as evidence; clear delegation of authority for who can answer insurance questions on behalf of the company.

Insurance response

There is no insurance response to insurance non-disclosure — that's the whole point. The cover that should have responded doesn't. The only mitigation is at the proposal stage: detailed declaration, broker discipline, and renewal review. Specialist smart home manufacturer broker placement makes a material difference here — generic brokers often miss the specific declarations that IoT work requires, while specialist brokers know exactly what each insurer expects to see at proposal.

From recent placement conversations The most common reason a smart home manufacturer's claim doesn't pay the way they expected isn't policy wording — it's what was declared at proposal. I had a placement conversation last quarter with a founder of a connected security device firm whose previous insurer had quietly reduced a £180k product liability claim by 60% because the proposal had described the operation as "electronics design and assembly" rather than "IoT consumer product manufacturing with cloud-connected device portfolio". The broker who placed the original cover hadn't asked the questions that would have led to proper declaration; the founder didn't know the questions hadn't been asked. The fix going forward was specific declaration of every material exposure, written broker confirmation of scope, and a documented annual review. The Insurance Act 2015 is unforgiving but it's also entirely manageable — the catastrophe is preventable at proposal.

14. What drives the cost of smart home manufacturing insurance in 2026?

Smart home manufacturer insurance pricing in 2026 reflects the genuine claim exposure differential vs generic electronics manufacturing — PSTI compliance overhead, lithium fire severity, recall predictability, cyber overlap with product liability, and the international claims environment. Indicative annual programme ranges:

Business Profile Indicative Annual Programme 2026
Pre-launch startup — prototyping, <£50k turnover £1,800–£4,500
Small manufacturer — post-launch, <£500k turnover £3,500–£8,500
Growth-stage — £500k–£2m turnover, UK + EU distribution £7,000–£18,000
Exporting to US — adds USA/Canada PL extension +50% to +150% on PL line
Lithium-battery-powered — adds battery-specific scope +20% to +50% on PL and EIL lines
Mid-sized manufacturer — £2m–£10m turnover, multi-channel £15,000–£45,000+
Large smart home brand — £10m+ turnover, international £35,000–£100,000+

The factors below drive both insurance premium and overall risk management investment. The rating impact within each profile band is typically larger than the differential between profile bands — meaning a small manufacturer with poor PSTI compliance can pay more than a growth-stage firm with excellent compliance and a clean claim record.

Rating FactorImpact on PremiumWhat You Can Do
Product category complexity Passive sensors lowest; security devices and large battery products highest Declare every product category specifically; misdeclaration is the #1 claim dispute
Annual turnover and forecasted growth Primary scaling factor across PL, Product Recall, Cyber Declare accurately including planned growth — under-declaration creates non-disclosure risk
Lithium battery scope Substantial loading on PL and EIL; some markets sub-limit EN IEC 62133-2 testing evidence; BMS design documentation; quality cell sourcing
PSTI Act compliance maturity Mature compliance reduces premium 10–20% across programme Implement, document, evidence at every renewal
ISO 9001 / ISO 27001 certification Recognised certifications reduce premium 5–15% Pursue where commercially justified; document scope and maintenance
Territorial scope (USA/Canada extension) 50–150% loading on Product Liability line Specific declaration; consider whether US distributor structure can absorb some risk
Software-cause defect PL scope Modest premium uplift; essential cover Don't try to save here — the £500–£1,500 saving creates £100k+ claim exposure
Recall history 3–5 year impact on Product Recall and PL lines Documented root cause analysis and remedial action after any recall
Cyber scope and IoT cover Specialist IoT cyber 1.5–2× generic cyber for same limit Match scope to deployed device estate; OTA patch deployment cover essential
Limits selected across programme £5m vs £10m vs £25m PL meaningful differential Match to contract requirements; distributor agreements often specify minimums
Online marketplace distribution Marketplace exposure now a specific underwriting factor Declare marketplace channels; maintain compliance documentation
Broker placement Specialist IoT brokers access better terms than generic placement Use a broker with specialist electronics and IoT underwriting experience
Continuity with insurer 3+ years with same insurer typically reduces renewal premium 5–10% Strategic continuity decision; don't chase £200 savings at the cost of relationship

15. Example claims and how to manage them

The three examples below are illustrative composites, based on the kinds of claim seen in connected-product manufacturing. They are not accounts of identifiable clients, and the figures are indicative rather than settlements we have handled.

Claim — Lithium Fire Product Liability, £620,000 Settlement

A small UK smart home manufacturer launched a video doorbell with integrated rechargeable lithium battery and cloud-connected motion alerts. The product sold strongly via Amazon and direct-to-consumer channels for 18 months, reaching approximately 28,000 deployed units. A customer's installed unit entered thermal runaway during charging in the porch of a Victorian terraced house. The fire spread to the property exterior and into the loft via the eaves. Three properties (the original and two adjoining terrace units) suffered fire damage; one occupant was hospitalised with smoke inhalation. The home insurers paid out and brought subrogated claims against the manufacturer under CPA 1987 strict liability.

Investigation identified the cell supplier as a lower-tier distributor in East Asia; subsequent testing of unsold stock found a sub-population of cells with manufacturing defects in the separator material. The manufacturer's documentation review showed: cell supplier had been added 14 months earlier without re-qualification; no incoming lot acceptance testing was performed on lithium cells; the BMS design relied on cell-level temperature monitoring that didn't trigger before thermal runaway.

The manufacturer's £10m Product Liability responded. Settlement: £620,000 (three property losses including subrogated home insurer claims, personal injury settlement, loss of contents). Defence costs: £78,000. Total claim: £698,000. A separate Environmental Impairment Liability claim covering firefighting water runoff contamination of the front garden of one adjoining property settled at a further £24,000.

Post-claim renewal: Product Liability premium increased 65%; battery cells re-classified as elevated risk in underwriting. Insurer required: documented EN IEC 62133-2 testing per cell supplier; incoming lot acceptance testing; BMS re-design with cell-level protection; supplier requalification protocol. The manufacturer implemented these, reduced cell suppliers to authorised distributors only, and at the following renewal premium returned to a 28% loading over original baseline.

The lesson: lithium fire is the catastrophic-tail exposure for any battery-powered smart home product. The supply chain decisions made for cost optimisation directly drive worst-case claim severity. The documentation discipline that defends these claims — cell supplier qualification, incoming inspection, BMS design records — is the same discipline that prevents them.

Claim — Cyber / Product Liability Overlap, £215,000 Settlement

A growth-stage UK smart lock manufacturer (approximately £1.4m turnover) experienced a coordinated security disclosure from a security research consultancy. The disclosure identified a vulnerability in the device firmware that allowed remote unauthorised unlocking under specific network conditions. Before the manufacturer could deploy a patch, one customer's home was burgled in circumstances suggesting the vulnerability had been exploited. The customer brought a CPA 1987 strict liability claim against the manufacturer alleging the device was defective and caused property loss.

Concurrently, the ICO opened an enquiry following customer notifications about the vulnerability disclosure. The OPSS was notified through the security researcher's coordinated disclosure process and required documented response evidence.

Three separate claim threads opened: Product Liability for the customer's burglary loss; Cyber liability for the engineering response and customer notification programme; Legal Expenses for ICO and OPSS engagement. The manufacturer's specialist IoT-scoped Product Liability responded to the customer claim (£68,000 — contents loss plus consequential). Cyber responded to the engineering response (£94,000 — emergency firmware development, OTA deployment infrastructure, third-party security audit, customer communication) and the ICO defence (£28,000). Legal Expenses covered the OPSS engagement (£25,000).

Total claim: £215,000. ICO ultimately issued no monetary penalty but required documented evidence of remediation. OPSS engagement closed without enforcement action conditional on the documented patch deployment evidence.

Post-claim renewal: Cyber premium increased 35%; Product Liability premium increased 20%. Insurer required: documented secure development lifecycle aligned to ETSI EN 303 645; published vulnerability disclosure policy; OTA patch deployment infrastructure with response timeframes; ISO 27001 implementation roadmap. The manufacturer implemented these and the following renewal saw premiums return to a 12–15% loading over baseline.

The lesson: cyber and product liability are no longer separate categories for smart home manufacturers. A single firmware vulnerability can trigger CPA 1987 strict liability claims for downstream consumer harm, regulatory engagement under PSTI and UK GDPR, and direct cyber response costs. A specialist Cyber policy with IoT scope, plus Product Liability with software-cause defect scope, together provide the only complete response. Generic Cyber for office IT plus generic PL for hardware will leave material gaps.

Claim — Product Recall Direct Costs, £340,000

A mid-sized UK smart home manufacturer producing connected thermostat hubs identified a defect in deployed firmware during routine post-market surveillance: under specific network conditions, the device could fail to switch off heating systems, creating a risk of overheating in the customer's home. The defect was confirmed through laboratory replication. The manufacturer's risk assessment concluded that voluntary recall was required; the OPSS was notified through the PFN process and confirmed agreement with the recall decision.

The recall covered approximately 47,000 deployed units across UK and EU distribution. Direct costs broke down as: customer notification across multiple channels including direct mail to registered users and online communications for unregistered users (£32,000); return logistics with prepaid postage and warehouse intake (£68,000); replacement product manufacturing and shipping (£94,000 net of normal margin); destruction of returned units (£12,000); crisis management and PR support (£38,000); legal advice including OPSS and EU equivalent engagement (£42,000); retailer relationships including shelf-pull compensation (£54,000).

Total recall direct costs: £340,000. Specialist Product Recall insurance responded with £250k of cover; the £90k balance was self-funded. No third-party personal injury or property damage claims arose during the recall — the issue was identified and remediated before any consumer harm occurred.

Post-claim renewal: Product Recall limit increased to £500k at the manufacturer's request and a modest 18% premium uplift. Insurer reviewed and confirmed: documented recall plan including rehearsal evidence; serial-number traceability; post-market surveillance system; pre-engagement with OPSS. The manufacturer's quality team reported that the recall was completed within OPSS-expected timeframes and the absence of consumer harm was treated by regulators as evidence of mature post-market surveillance.

The lesson: a well-executed recall is dramatically cheaper than a recall that drifts. The £340k direct cost would have been substantially higher without rehearsed processes, mature traceability, and pre-existing OPSS engagement. Product Recall insurance at sensible limits funds the predictable operational cost; the documentation and process discipline that defends a recall is what keeps it from spiralling. Generic PL does not cover first-party recall costs — manufacturers without specialist Product Recall cover absorb these costs entirely from working capital.

Claims Management Steps

How to respond to a smart home product incident or regulatory engagement — the steps below are critical given the multi-policy and multi-regulator exposure typical of 2026 connected-product operations:

  1. Make affected products safe and protect persons first. If there is a deployed device population creating ongoing risk, deploy interim mitigations (firmware-level kill switches where available, customer alerts, stop-sale notice) before administrative steps. Medical response takes priority over administrative steps for any personal injury incident.
  2. Notify your insurer immediately for any potential claim. Smart home incidents typically engage multiple policies (PL, Product Recall, Cyber, EIL, Legal Expenses). Single notification triggers coordinated response. Threshold is "may give rise to a claim" — much lower than "formal claim received".
  3. Preserve all documentation rigorously. Design records, test reports, supplier qualification evidence, BMS architecture documentation, firmware version history, vulnerability disclosure records, customer notification chain. The documentation pack is the defence across all coverage layers.
  4. Do not admit liability or fault. Provide factual information about what happened, what the product did, what action you are taking. Do not accept fault, apologise in writing, or commit to remediation costs that could be interpreted as admission. Customer-facing communications need legal and insurer sign-off where the incident may generate a claim.
  5. Manage OPSS / ICO / regulatory engagement carefully. If regulators engage or notify, engage your Legal Expenses insurer immediately. Cooperate factually with inspectors but do not provide written statements without legal representation. Regulatory investigation can become formal enforcement action including PSTI penalties.
  6. Activate recall plan if the incident pattern indicates field defect. Recall decisions should be made on documented evidence with insurer notification. OPSS engagement through the PFN process is increasingly expected before voluntary recall announcement to maintain regulatory cooperation.
  7. Conduct root cause analysis and document remedial action. Identify underlying cause and implement remedial action across design, supply chain, manufacturing, or post-market surveillance. Insurers reviewing renewal will ask what's changed since the incident; regulators will require evidence of remedial action.
  8. Update operational documentation to address gap. Where the incident identified a documentation gap (no supplier qualification, no incoming inspection, no vulnerability disclosure policy, no recall plan), update the standard operating procedure to close the gap going forward. This is both insurance and regulatory defence.
John Miller — Director, Miller & Partner — commercial insurance broker specialising in smart home manufacturers, IoT and connected product firms, electronics design, 3D printing, robotics, and specialist tech manufacturer risk placements
Written and reviewed by John Miller Director & Principal Broker, Miller & Partner Over 13 years of specialist commercial insurance experience. Former #1 Account Executive at Brown & Brown and #1 Salesperson at AXA. Miller & Partner Limited is an Appointed Representative of Gauntlet Risk Management Ltd, which is authorised and regulated by the Financial Conduct Authority. Direct access to Lloyd's Market and specialist MGA schemes. Active placements include UK smart home and IoT manufacturers, connected consumer products, electronics design firms, 3D printing companies, robotics startups, automation engineers, and specialist tech manufacturer programmes for operators ranging from pre-launch startups to mid-sized regional firms with international distribution and PSTI-compliance-led product portfolios.

Glossary of smart home manufacturing insurance terms

PSTI Act (Product Security and Telecommunications Infrastructure Act 2022)
UK legislation requiring mandatory cybersecurity requirements for consumer connectable products. Part 1 came into force on 29 April 2024. Enforcement by the Office for Product Safety and Standards with penalties up to £10m or 4% of global revenue.
PRMA 2025 (Product Regulation and Metrology Act 2025)
UK enabling legislation that received Royal Assent on 21 July 2025, restructuring the post-Brexit product safety framework. For the first time, UK product safety law explicitly covers intangible components including software, AI, and digital services. Online marketplaces are inside the regulatory perimeter.
CPA 1987 (Consumer Protection Act 1987)
UK legislation imposing strict liability on producers, importers, and own-branders of defective products. Claimants do not need to prove negligence. 10-year long-stop from date of supply. Section 3 defines defect as the product not providing the safety persons generally are entitled to expect.
OPSS (Office for Product Safety and Standards)
UK national product regulator, part of the Department for Business and Trade. Enforces PSTI, oversees product recalls, operates the product-related fire notification (PFN) reporting regime, and is the lead authority for product safety enforcement under the emerging PRMA framework.
ETSI EN 303 645
European standard establishing baseline cybersecurity provisions for consumer Internet of Things. The working international standard against which PSTI compliance is typically measured. Covers passwords, vulnerability disclosure, update mechanisms, secure storage of credentials, and other foundational IoT cybersecurity controls.
EN IEC 62133-2
International safety standard for secondary lithium cells and batteries intended for portable applications. The working safety standard for consumer rechargeable lithium products. Testing evidence is typically required by insurers for any lithium-powered consumer product.
Thermal Runaway
The chain reaction in lithium battery cells where elevated temperature causes further heat generation, leading to rapid temperature rise and potential release of flammable gases. The primary failure mode for lithium-ion battery fires. Cell-level temperature monitoring and battery management system design are key mitigations.
Product Liability Insurance
Commercial insurance covering claims arising from defective products causing injury or property damage. For smart home manufacturers in 2026, scope must explicitly include software-cause defects, cyber-related defects, and territorial coverage matching distribution. Generic Public Liability with "product extension" may not adequately cover IoT-specific scenarios.
Product Recall Insurance
Specialist insurance covering first-party recall direct costs (notification, logistics, replacement, destruction, crisis management) and increasingly third-party costs. Generic Product Liability does not normally include first-party recall costs. Essential for any manufacturer with deployed product population.
UKCA (UK Conformity Assessed)
UK product marking introduced post-Brexit. Currently UK government accepts both CE and UKCA marking indefinitely for most consumer electronics categories under the Product Safety and Metrology etc (Amendment) Regulations 2024. Northern Ireland requires CE marking.
CE Marking
European Union conformity marking indicating compliance with applicable EU directives and regulations. Required for sale in the EU and Northern Ireland; currently accepted in Great Britain under indefinite recognition for most consumer electronics categories.
EU CRA (Cyber Resilience Act)
EU regulation establishing cybersecurity requirements for products with digital elements sold in the EU. Provides the EU equivalent of UK PSTI but with broader scope and more detailed obligations. Relevant for UK manufacturers exporting to the EU.
GPSR (General Product Safety Regulation)
EU regulation establishing general product safety duties including specific obligations for online marketplaces. In force since December 2024. Relevant for UK manufacturers selling into the EU through marketplace channels.
Statement of Compliance
Document required under PSTI accompanying each in-scope consumer connectable product. Content specified in Schedule 4 of the PSTI Regulations. Includes manufacturer details, product identification, declaration of compliance with security requirements, and defined support period information.
PFN (Product-Related Fire Notification)
The voluntary OPSS reporting mechanism through which UK fire and rescue service investigators notify product safety regulators of fires where consumer products were the most probable cause. Increasingly important in identifying lithium battery and smart home device fire patterns.
OTA (Over-The-Air) Update
The mechanism by which connected device firmware is updated remotely without physical access. Essential infrastructure for PSTI vulnerability response. Cyber insurance for IoT manufacturers increasingly includes OTA deployment cost cover.
BMS (Battery Management System)
The electronic system managing a lithium battery pack — including cell-level voltage monitoring, temperature monitoring, charge/discharge control, and protection circuits. BMS design quality is a primary determinant of lithium fire incidence.

Frequently asked questions

Smart home manufacturing business insurance is specialist commercial insurance designed for IoT and connected consumer product manufacturers. The core covers in 2026 are: Product Liability with IoT and software-cause defect scope; Public Liability; Employers' Liability where staff engaged; Product Recall covering first-party direct costs; Cyber insurance with IoT scope including OTA patch deployment; Professional Indemnity for design and consultancy work; Environmental Impairment Liability particularly for lithium-powered products; Directors and Officers liability; Legal Expenses with OPSS/PSTI/ICO scope; stock, premises, and Business Interruption. The cover differs fundamentally from generic electronics manufacturer policies which typically don't contemplate software-cause defects, IoT-specific cyber exposure, or PSTI compliance scope.

The PSTI Act fundamentally changed the manufacturer risk profile from April 2024. Every UK consumer connectable product must meet three minimum cybersecurity requirements: no universal default passwords, published vulnerability disclosure policy, and published defined support period. Each product must carry a statement of compliance per Schedule 4 of the Regulations. Enforcement sits with the Office for Product Safety and Standards with penalties up to £10m or 4% of global revenue. Insurance implications: Legal Expenses must include OPSS/PSTI investigation scope; Product Liability must contemplate software-cause defects; Directors and Officers cover protects against personal prosecution. Manufacturers without robust compliance evidence face delisting from major marketplaces and acute regulatory exposure.

Indicative 2026 annual programme costs: pre-launch startups £1,800–£4,500; small manufacturers (post-launch, <£500k) £3,500–£8,500; growth-stage firms (£500k–£2m) £7,000–£18,000; mid-sized manufacturers (£2m–£10m) £15,000–£45,000+; large smart home brands (£10m+) £35,000–£100,000+. USA/Canada Product Liability extension adds 50–150%. Lithium battery scope adds 20–50%. Pricing depends on product mix, lithium exposure, PSTI compliance maturity (mature compliance reduces premium 10–20%), claims history, limits, and broker placement. For broader pricing principles see our 3D printing company insurance guide.

Employers' Liability is legally required if you have staff under the Employers' Liability (Compulsory Insurance) Act 1969 — fines of £2,500 per day for non-compliance. Other covers are not legally required but are commercially essential. Product Liability is functionally essential under CPA 1987 strict liability — without it, any defective product personal injury or property damage claim is uninsured. Distributor and marketplace agreements typically require minimum cover levels; major retailers commonly specify Product Liability of £5m–£10m minimum.

Both are manufacturer policies but the risk profiles differ materially. Generic electronics manufacturing primarily engages Consumer Protection Act 1987 strict liability and typical product safety standards. Smart home manufacturing additionally engages: PSTI Act mandatory cybersecurity requirements; ICO/UK GDPR data processing duties; OPSS PFN reporting on field fire incidents; software-cause defect liability that doesn't apply to passive electronics; cyber breach exposure on cloud platforms supporting deployed devices; and recall exposure driven by OPSS or marketplace stop-sale orders. Generic electronics PL with vanilla product extension typically misses IoT-specific scope. Specialist placement is materially different. See our electronics design business insurance guide for adjacent coverage principles.

Only if specifically scoped. Generic Product Liability may carry battery-specific sub-limits, fire exclusions for rechargeable products, or unfavourable territorial scope. Specialist placement should explicitly confirm: lithium fire is within scope and not sub-limited; battery-related Environmental Impairment Liability is in place; recall exposure for battery-cell-related defects is covered. Get written broker confirmation that lithium scope is explicit. UK fire services attended 1,760 lithium-ion battery fires in 2025, and the underwriting environment is tightening. The £500–£2,000 premium uplift for explicit battery scope is dramatically cheaper than the £20k–£2m+ claim exposure on a typical battery fire incident.

Yes — particularly under the 2026 framework. Product Recall was historically optional for smaller manufacturers; under the combined PSTI regime and Sedgwick-recorded recall volumes (14,484 UK/EU events in 2024), it has become functionally essential. Direct cost drivers: customer notification, return logistics, replacement, destruction, crisis management, legal advice. Total: £100k–£500k typical, £500k+ for major lines. Generic Product Liability does not normally include first-party recall costs — the assumption that "my PL will cover recall" is a common and expensive misconception. Specialist Product Recall policies typically run £50k–£500k limits at £4k–£15k premium. Limits should match likely recall scale — a manufacturer with 50,000 deployed units cannot recover meaningfully with £50k of recall cover.

Insurance non-disclosure under the Insurance Act 2015. The pattern: manufacturer buys an electronics manufacturer's package with "electronics manufacturing" declared, undertakes IoT consumer product manufacturing with cloud-connected device portfolio, doesn't specifically declare it. At claim stage, the insurer points to the proposal documentation showing the declared activity was generic electronics manufacturing, and a claim involving software-cause defect, cyber breach, or PSTI non-compliance becomes uninsured or proportionally reduced. This isn't fraud; it's the normal operation of UK insurance law requiring "fair presentation of the risk". The fix at proposal stage is minimal cost; the retrospective cost is potentially every uninsured claim across multiple policy years. Get written confirmation from your broker that IoT operations, software-cause defects, lithium batteries, cloud platforms, and territorial distribution are all within scope.

The single biggest premium reduction lever is documented PSTI compliance and operational maturity: full statement of compliance discipline, secure development lifecycle aligned to ETSI EN 303 645, ISO 9001 quality management, post-market surveillance system, rehearsed recall plan, BMS testing evidence for battery products. Mature documentation typically reduces premium 10–20% across the programme. Other levers: ISO 27001 certification (5–10% on Cyber); EN IEC 62133-2 testing evidence for batteries; accurate product mix declaration; limits matched to actual contract requirements; 3+ years continuity with same insurer; annual payment vs monthly; specialist broker placement. Stack the levers; don't choose between them. Avoid the trap of buying the cheapest generic manufacturer's package — the saving is dwarfed by uninsured claim exposure.

Yes, where scoped correctly. Specialist Cyber insurance with IoT scope responds to: corporate IT ransomware and data breach; cloud platform breach exposing customer telemetry; firmware vulnerability requiring OTA patch deployment; UK GDPR enforcement defence; third-party class-action-style claims following large breaches; potentially first-party costs of remediation including replacement of bricked devices. The ICO can impose UK GDPR penalties up to £17.5m or 4% of global turnover. Generic Cyber for office IT typically doesn't contemplate IoT device exposure; specialist placement is essential. Limits typically £500k–£5m for small to mid-sized smart home manufacturers. See our cyber insurance product page for coverage principles.

Territorial scope extension is critical — UK-only Product Liability does NOT respond to claims brought in EU or US courts. For EU sales: Product Liability with EU territorial scope, awareness of EU Cyber Resilience Act and General Product Safety Regulation, importer of record arrangements where required. For US sales: Product Liability with USA/Canada extension (typically 50–150% premium loading), aware of FTC and state-level enforcement environment, US distributor agreement review to understand indemnity flows, marine cargo insurance for international shipments, Cyber insurance with worldwide scope including US class action defence. Major US retailers typically require £10m+ Product Liability with USA scope. Many smaller UK manufacturers under-insure for export risk; specialist placement is essential.

Look for brokers with specific experience in electronics manufacturing, IoT, and connected products evidenced by: specialist articles or guides on PSTI, product liability, and IoT cyber cover; willingness to discuss specific exposures (software-cause defects, lithium fire, recall, OPSS engagement, ICO enforcement) in detail; access to Lloyd's market and specialist MGAs rather than just mainstream commercial markets; a listing on the FCA Financial Services Register and a documented track record. Avoid brokers offering generic "electronics manufacturer package" without discussing IoT specifics; brokers who can only quote one or two markets; brokers who don't ask about lithium scope or PSTI compliance at proposal. Miller & Partner specialise in this sector — see our AI and tech product page and our manufacturing insurance page.

Related guides from Miller & Partner

Smart Home Manufacturing InsuranceSmart Home InsuranceBusiness Insurance
Back to Blog
About this article General information, not advice. Published for general guidance and drawing on external sources as well as our own experience. It is not a personal recommendation, a quotation, or an offer of cover, and it doesn't take account of your circumstances. Read more + Close −

Where the information comes from

Our articles are compiled from a range of sources: regulators and public bodies such as the FCA, the Civil Aviation Authority, the Health and Safety Executive and Companies House; government publications and legislation; industry and trade bodies; insurer and market documentation; and published research and news reporting. Not everything stated originates from Miller & Partner. Where information comes from a third party we believe it to be accurate at the date of publication, but we haven't independently verified every external source and we don't warrant its accuracy or completeness. Where a point matters to a decision you're making, go to the original source and check it.

Figures, examples and case studies

Premium ranges, cost figures, limits and worked examples are illustrative only. They are not quotations, not offers of cover, and no cover is provided or implied on the basis of them. What you're actually charged depends on underwriting, and what you're actually covered for depends on the policy wording issued to you. Where an article includes a claim example, scenario or case study, it is illustrative unless we say otherwise — such examples are typically composites written to show how a policy section responds, and they don't describe an identifiable client, claim or settlement.

Interactive tools

Any calculators, cover checkers, risk assessors or similar tools on our site produce general guidance from the small number of answers you give them. They can't see your business, and their output is not a personal recommendation, an assessment of your actual risk, or a quotation.

Rules and market conditions change

Law, regulation, tax treatment, insurer appetite and policy wordings all change, sometimes at short notice. Content is accurate to the best of our knowledge on the date shown on the article and we don't undertake to update it as things move. An article you're reading some time after publication may be out of date.

Third parties and external links

References to insurers, underwriters, trade bodies, software, training providers or other organisations are for information only. They don't imply endorsement, recommendation, partnership or affiliation in either direction unless stated. We're not responsible for the content of external websites we link to.

Not legal, tax or accounting advice

Nothing here is legal, tax, accounting or regulatory advice. Where an article discusses statutory duties, contract terms or compliance obligations, take advice from an appropriately qualified professional on your own position before acting.

How we write these

We use AI tools in researching and drafting our published content. Every article is reviewed and signed off by a named, accountable person at Miller & Partner before it is published, and responsibility for what appears here rests with us.

Our regulatory status

Miller & Partner Ltd is an Appointed Representative of Gauntlet Risk Management Ltd, which is authorised and regulated by the Financial Conduct Authority (FRN 308081). Miller & Partner Ltd is entered on the FCA Register under reference 1029698. Registered in England and Wales, company number 16206282. Registered office: Vivian House, Roman Bridge Close, Mumbles, Swansea, SA3 5BG.

Spotted something wrong?

We'd rather know. Email [email protected] or call 01792 001350 and we'll review and correct it.

For advice on your own insurance arrangements, speak to us directly — that's when we can take your circumstances into account and give you a recommendation.

Ready to protect your business?
Get expert advice and a tailored commercial insurance quote today.

✔ Independent broker
✔ Access to leading UK insurers
✔ Fast turnaround

[Request a quote]

[[email protected]]
[Call 01792 001350]

Exclusive Offer

Free Insurance Review
& Zero Broker Fee

Let us review your current insurance and see if we can improve your cover while reducing the cost.

✓
Free no-obligation insurance review tailored to your business
£
Zero broker fee on all new policies
⚡
Fast response from a real insurance specialist

You're in 🎉

Thanks for requesting your free review. We'll be in touch shortly.

🔒 No spam, ever. Your details are safe with us.

We're an Appointed Representative of Gauntlet Risk Management Ltd, which is authorised and regulated by the FCA. You can check our entry on the FCA Register.

MEET THE Director

Hey, I'm John!

I started Miller & Partner with the aim to bring back personable, approachable broking to UK businesses who were tired of large corporate brokers and feeling like they were just another number.

I have built this brokerage up with no pushy sales techniques or big business tactics, just honest, approachable and professional relationships with my clients.

Over 13 years experience in business insurance

Client first approach

5* rated broker on Google

Office: Vivian House, Roman Bridge Close, Mumbles, Swansea, SA3 5BG

Miller & Partner Ltd is an Appointed Representative of Gauntlet Risk Management Ltd, which is authorised and regulated by the Financial Conduct Authority (FRN 308081). Miller & Partner Ltd is entered on the Financial Services Register under firm reference number 1029698. You may check this on the Financial Services Register by visiting the FCA website at https://www.fca.org.uk/firms/financial-services-register or by contacting the FCA on 0800 111 6768. Miller & Partner Ltd is registered in England & Wales, company number 16206282. Registered office: 20 Vivian House, Roman Bridge Close, Swansea, SA3 5BG.