Conformity Sheet
Every regime ยท United States

US Consumer Product Safety Commission (CPSC) requirements, including connected product safety

Consumer products on the US market. Hazard analysis, mandatory and voluntary standards, certification against the rules that apply, incident monitoring and the duty to report a substantial product hazard, recall and corrective action readiness, and consumer safety communication. For connected products the CPSC also expects network security, software and firmware integrity, remote update safety and vulnerability disclosure.

licensed text The requirement text and the evidence an inspector accepts sit behind this regime, licensed from a human-verified corpus.

Documents

What it expects in the file

After sale

Duties that continue after sale

Licensed text

Every control, with the requirement text

23 controls. Requirement text and evidence artefacts from a human-verified corpus. Data licensed to Conformity Sheet by The Art of Service Pty Ltd, revocable, non-transferable. Framework page: compliance.theartofservice.com/frameworks/us-consumer-product-safety-commission-cpsc-connected-product-safety.

CPSC: 23 controls
CPSC CS.1 Network Security for Connected Products

Connected products must implement security measures to prevent network-based attacks that could cause physical harm.

Evidence an inspector accepts: Software update and remote update security plan; Section 15(b) incident reporting procedure; Recall plan for connected products
Common gap: Vulnerability disclosure programme absent
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC CS.2 Authentication and Access Controls

Connected products must implement authentication mechanisms to prevent unauthorised control of safety-critical functions.

Evidence an inspector accepts: Connected product hazard analysis and FMEA; Section 15(b) incident reporting procedure; Cybersecurity assessment against UL 2900-1
Common gap: No formal cybersecurity component in product safety reviews
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC CS.3 Data Protection for Safety Systems

Safety-relevant data transmitted by connected products must be protected against tampering and interception.

Evidence an inspector accepts: Recall plan for connected products; Cybersecurity assessment against UL 2900-1; Section 15(b) incident reporting procedure
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC CS.4 Vulnerability Disclosure

Manufacturers should establish vulnerability disclosure programmes for security issues affecting product safety.

Evidence an inspector accepts: End-of-life and end-of-support safety communications; Recall plan for connected products; Cybersecurity assessment against UL 2900-1
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC PM.1 Incident Monitoring and Reporting

Manufacturers must monitor and report safety incidents related to connected product cyber vulnerabilities.

Evidence an inspector accepts: Recall plan for connected products; Software update and remote update security plan; Section 15(b) incident reporting procedure
Common gap: End-of-life policy missing for safety-relevant firmware
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC PM.2 Product Recall Procedures

Procedures must be in place for issuing recalls when connected product vulnerabilities create imminent safety hazards.

Evidence an inspector accepts: Cybersecurity assessment against UL 2900-1; Software update and remote update security plan; Section 15(b) incident reporting procedure
Common gap: No formal cybersecurity component in product safety reviews
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC PM.3 End-of-Life Safety Planning

Manufacturers must plan for safe product behaviour when connected features are discontinued or support ends.

Evidence an inspector accepts: Software update and remote update security plan; Recall plan for connected products; Connected product hazard analysis and FMEA
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC PM.4 Consumer Safety Communication

Manufacturers must provide clear safety information to consumers about connected product risks and mitigations.

Evidence an inspector accepts: Software update and remote update security plan; Recall plan for connected products; Connected product hazard analysis and FMEA
Common gap: OTA update integrity controls insufficient
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC RA.1 Hazard Analysis for Connected Products

Manufacturers must analyse the likelihood and severity of injury for each expected function a connected product performs.

Evidence an inspector accepts: Connected product hazard analysis and FMEA; Software update and remote update security plan; Recall plan for connected products
Common gap: End-of-life policy missing for safety-relevant firmware
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC RA.2 Failure Modes and Effects Analysis

Manufacturers must conduct FMEA covering safety-critical functions including software and firmware components.

Evidence an inspector accepts: Cybersecurity assessment against UL 2900-1; Recall plan for connected products; Software update and remote update security plan
Common gap: End-of-life policy missing for safety-relevant firmware
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC RA.3 Lifecycle Risk Assessment

Risk analysis must cover every stage of the product lifecycle including software updates and end-of-life scenarios.

Evidence an inspector accepts: Software update and remote update security plan; Recall plan for connected products; Section 15(b) incident reporting procedure
Common gap: OTA update integrity controls insufficient
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC RA.4 Critical Component Identification

Manufacturers must identify components critical to safe operation including power supplies, sensors, software, and electronics.

Evidence an inspector accepts: End-of-life and end-of-support safety communications; Recall plan for connected products; Cybersecurity assessment against UL 2900-1
Common gap: End-of-life policy missing for safety-relevant firmware
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC STD.1 UL 2900-1 Cybersecurity Compliance

Connected products should meet UL 2900-1 requirements for software cybersecurity of network-connectable devices.

Evidence an inspector accepts: Software update and remote update security plan; Recall plan for connected products; Connected product hazard analysis and FMEA
Common gap: OTA update integrity controls insufficient
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC STD.2 UL 5500 Remote Update Compliance

Products with remote software update capability should comply with UL 5500 for safe update processes.

Evidence an inspector accepts: Software update and remote update security plan; End-of-life and end-of-support safety communications; Section 15(b) incident reporting procedure
Common gap: No formal cybersecurity component in product safety reviews
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC STD.3 Voluntary Standards Participation

Manufacturers should participate in development of voluntary safety standards with UL, ASTM, and other bodies.

Evidence an inspector accepts: Recall plan for connected products; Connected product hazard analysis and FMEA; Section 15(b) incident reporting procedure
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC STD.4 Interoperability Safety

Safety implications of product interoperability with other connected devices must be evaluated and mitigated.

Evidence an inspector accepts: Connected product hazard analysis and FMEA; End-of-life and end-of-support safety communications; Section 15(b) incident reporting procedure
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC SW.1 Secure Software Development

Connected product software must be developed following secure coding practices to prevent safety-related failures.

Evidence an inspector accepts: Software update and remote update security plan; Recall plan for connected products; Section 15(b) incident reporting procedure
Common gap: OTA update integrity controls insufficient
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC SW.2 Software Update Safety Verification

Every software update must be assessed for its impact on the safe operation of the connected product.

Evidence an inspector accepts: Recall plan for connected products; End-of-life and end-of-support safety communications; Connected product hazard analysis and FMEA
Common gap: Vulnerability disclosure programme absent
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC SW.3 Remote Update Security

Remote software update mechanisms must ensure integrity and authenticity of updates per UL 5500 guidance.

Evidence an inspector accepts: Recall plan for connected products; Connected product hazard analysis and FMEA; Section 15(b) incident reporting procedure
Common gap: Vulnerability disclosure programme absent
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC SW.4 Firmware Integrity

Firmware must maintain integrity controls to prevent unauthorised modification that could create safety hazards.

Evidence an inspector accepts: Section 15(b) incident reporting procedure; Software update and remote update security plan; Cybersecurity assessment against UL 2900-1
Common gap: End-of-life policy missing for safety-relevant firmware
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 1 Section 15(b) Substantial Product Hazard Reporting

Per US Consumer Product Safety Act Section 15(b): Substantial Product Hazard Reporting to CPSC within 24 hours of obtaining information including cybersecurity hazards.

Evidence an inspector accepts: CPSC evidence for USCPSC-1
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 2 Connected Product Cybersecurity Hazard Identification

Per CPSC + NIST IR 8425: Connected Product Cybersecurity Hazard Identification + risk assessment + alignment with NIST + secure default configuration.

Evidence an inspector accepts: CPSC evidence for USCPSC-2
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 3 Recall, Corrective Action, SaferProducts.gov

Per CPSC: Voluntary Recall Notice + Corrective Action Plan + SaferProducts.gov Complaint Monitoring.

Evidence an inspector accepts: CPSC evidence for USCPSC-3
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
Categories

Product categories that engage it

Cable or connectorCamera or action cameraConsumer droneE-reader or portable media playerGames console or controllerLaptop, desktop or tablet computerMobile phonePower adapter or chargerPrinter or scannerSpeaker, soundbar or headphonesTelevision or monitorBaby monitorConnected home deviceIP camera or video doorbellRouter, gateway or hubSmart lockSmart plug or smart socketSmart speaker or voice assistantSmart thermostat or heating controllerSmartwatch or fitness trackerBoard game, puzzle or craft kitConnected or app-controlled toyConstruction set or building blocksCot, crib or bassinetElectronic or battery toyHigh chair or booster seatOutdoor or water toyPacifier, teether or feeding articlePlush or soft toyPushchair, stroller or pramRide-on toyAir compressorAngle grinder or cutting toolChainsaw or hedge trimmerCordless drill or driverLawnmower or garden machinePortable generatorPressure washerTable saw, mitre saw or bench toolFall arrest harness or lanyardHearing protectionHigh-visibility clothingLife jacket or buoyancy aidProtective glovesSafety footwearSafety glasses or face shieldSafety helmet or hard hatElectric blanket or heated padHair dryer, straightener or personal care applianceIron or garment steamerKettle or coffee machineMicrowave oven or cookerRefrigerator or freezerSpace heater, fan or air conditionerToaster, grill or small cooking applianceVacuum cleanerWashing machine, dryer or dishwasherDesk lamp or portable lightLED lamp or bulbLuminaire or ceiling lightOutdoor or garden lightString or decorative lightsBattery chargerEV charging pointElectric bicycleElectric scooter or hoverboardLithium battery pack or cellPortable power stationPower bankBedding, duvet or pillowBunk bed or children's furnitureChildren's clothing or sleepwearClothing or apparelCurtains, blinds or home textilesMattressOffice chair or deskSofa or upholstered furnitureCandle or home fragranceHousehold cleaner or detergentPaint, coating or adhesiveCookware or bakewareCutting board or kitchen utensilDrinking bottle or travel mugFood packaging materialFood storage containerKitchen knife or cutleryBicycleBicycle or sports helmetCamping stove or gas heaterClimbing or mountaineering equipmentPool, spa or water treatmentTent or camping furnitureTrampoline or play equipmentTreadmill or fitness equipment

See which of your products engage it

Paste the list and every product that engages CPSC in the markets you sell to shows it as a chip, with the documents it expects ticked against what you hold. Five products free, no account.

Build my conformity sheet