US Consumer Product Safety Commission (CPSC) requirements, including connected product safety
Consumer products on the US market. Hazard analysis, mandatory and voluntary standards, certification against the rules that apply, incident monitoring and the duty to report a substantial product hazard, recall and corrective action readiness, and consumer safety communication. For connected products the CPSC also expects network security, software and firmware integrity, remote update safety and vulnerability disclosure.
licensed text The requirement text and the evidence an inspector accepts sit behind this regime, licensed from a human-verified corpus.
What it expects in the file
- Risk assessment
The documented hazard identification and risk assessment for the product across its lifecycle, updated when the design, the use or the field data changes. - Test reports
Test reports from an accredited or accepted laboratory against the standards the technical file names, tied to the exact model and revision tested. - Labelling and instructions
Markings on the product and packaging (conformity mark, identification, warnings, manufacturer and importer details) and the instructions and safety information in the language of the market. - Traceability records
Batch, lot or serial identification on the product, the records that tie a unit to its production and supply chain, and UDI where the device rules require it.
Duties that continue after sale
- Incident reporting
Notify the authority when a product has caused, or could cause, an accident, injury or serious incident, through the channel the regime names (the Safety Business Gateway, the MHRA, the FDA, SaferProducts.gov) and within its clock. - Recall readiness
Be able to identify affected units, reach the customers who hold them, issue a notice in the required form, offer the remedy the rules require, and show the authority the effectiveness of the action. - Market surveillance cooperation
Answer an authority's request for the technical file, the declaration and the supply chain within the time it sets, in a language it accepts, and cooperate with any corrective measure it requires. - Security updates and vulnerability handling
Provide security updates for the stated support period, run a coordinated vulnerability disclosure process, and report actively exploited vulnerabilities and severe incidents within the reporting clock.
Every control, with the requirement text
23 controls. Requirement text and evidence artefacts from a human-verified corpus. Data licensed to Conformity Sheet by The Art of Service Pty Ltd, revocable, non-transferable. Framework page: compliance.theartofservice.com/frameworks/us-consumer-product-safety-commission-cpsc-connected-product-safety.
CPSC: 23 controls
CPSC CS.1 Network Security for Connected ProductsConnected products must implement security measures to prevent network-based attacks that could cause physical harm.
Common gap: Vulnerability disclosure programme absent
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC CS.2 Authentication and Access ControlsConnected products must implement authentication mechanisms to prevent unauthorised control of safety-critical functions.
Common gap: No formal cybersecurity component in product safety reviews
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC CS.3 Data Protection for Safety SystemsSafety-relevant data transmitted by connected products must be protected against tampering and interception.
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC CS.4 Vulnerability DisclosureManufacturers should establish vulnerability disclosure programmes for security issues affecting product safety.
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC PM.1 Incident Monitoring and ReportingManufacturers must monitor and report safety incidents related to connected product cyber vulnerabilities.
Common gap: End-of-life policy missing for safety-relevant firmware
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC PM.2 Product Recall ProceduresProcedures must be in place for issuing recalls when connected product vulnerabilities create imminent safety hazards.
Common gap: No formal cybersecurity component in product safety reviews
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC PM.3 End-of-Life Safety PlanningManufacturers must plan for safe product behaviour when connected features are discontinued or support ends.
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC PM.4 Consumer Safety CommunicationManufacturers must provide clear safety information to consumers about connected product risks and mitigations.
Common gap: OTA update integrity controls insufficient
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC RA.1 Hazard Analysis for Connected ProductsManufacturers must analyse the likelihood and severity of injury for each expected function a connected product performs.
Common gap: End-of-life policy missing for safety-relevant firmware
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC RA.2 Failure Modes and Effects AnalysisManufacturers must conduct FMEA covering safety-critical functions including software and firmware components.
Common gap: End-of-life policy missing for safety-relevant firmware
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC RA.3 Lifecycle Risk AssessmentRisk analysis must cover every stage of the product lifecycle including software updates and end-of-life scenarios.
Common gap: OTA update integrity controls insufficient
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC RA.4 Critical Component IdentificationManufacturers must identify components critical to safe operation including power supplies, sensors, software, and electronics.
Common gap: End-of-life policy missing for safety-relevant firmware
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC STD.1 UL 2900-1 Cybersecurity ComplianceConnected products should meet UL 2900-1 requirements for software cybersecurity of network-connectable devices.
Common gap: OTA update integrity controls insufficient
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC STD.2 UL 5500 Remote Update ComplianceProducts with remote software update capability should comply with UL 5500 for safe update processes.
Common gap: No formal cybersecurity component in product safety reviews
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC STD.3 Voluntary Standards ParticipationManufacturers should participate in development of voluntary safety standards with UL, ASTM, and other bodies.
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC STD.4 Interoperability SafetySafety implications of product interoperability with other connected devices must be evaluated and mitigated.
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC SW.1 Secure Software DevelopmentConnected product software must be developed following secure coding practices to prevent safety-related failures.
Common gap: OTA update integrity controls insufficient
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC SW.2 Software Update Safety VerificationEvery software update must be assessed for its impact on the safe operation of the connected product.
Common gap: Vulnerability disclosure programme absent
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC SW.3 Remote Update SecurityRemote software update mechanisms must ensure integrity and authenticity of updates per UL 5500 guidance.
Common gap: Vulnerability disclosure programme absent
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC SW.4 Firmware IntegrityFirmware must maintain integrity controls to prevent unauthorised modification that could create safety hazards.
Common gap: End-of-life policy missing for safety-relevant firmware
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 1 Section 15(b) Substantial Product Hazard ReportingPer US Consumer Product Safety Act Section 15(b): Substantial Product Hazard Reporting to CPSC within 24 hours of obtaining information including cybersecurity hazards.
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 2 Connected Product Cybersecurity Hazard IdentificationPer CPSC + NIST IR 8425: Connected Product Cybersecurity Hazard Identification + risk assessment + alignment with NIST + secure default configuration.
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 3 Recall, Corrective Action, SaferProducts.govPer CPSC: Voluntary Recall Notice + Corrective Action Plan + SaferProducts.gov Complaint Monitoring.
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
Product categories that engage it
See which of your products engage it
Paste the list and every product that engages CPSC in the markets you sell to shows it as a chip, with the documents it expects ticked against what you hold. Five products free, no account.
Build my conformity sheet