I hope you’re doing ok given the circumstances. I wanted to share an update that the Secure by Design team in DCMS are now fully back after a period working on Covid-related priorities, and are working on our mission to protect consumers and the wider economy from the range of harms that can arise from vulnerable smart devices.
As announced in our response to our 2019 consultation on regulation (Jan 27), we know that, given the vast majority of smart products still do not embed good security practices, we propose to develop legislation to mandate a baseline level of cybersecurity for Consumer IoT devices sold in the UK.
Given Ministerial appetite to rapidly develop legislation and the growing threat posed by vulnerable devices at a time with an increased attack surface and reduced social resilience, we recognise the need to keep momentum going in an increasingly competitive international landscape.
We intend to publish a Call for Views on our approach in w/c 13 July to allow industry and other stakeholders to feed back on our approach. This document will follow on from our 2019 consultation and will add further detail to the security requirements we intend to mandate, the scope of the regulation, the obligations the regulation will place on the manufacturers and retailers of consumer smart devices, and the approach that will be used to enforce the regulation.
Ahead of this, we intend to share the Call for Views doc for formal Write Round with other government departments in w/c 22 June.
I recognise that teams are stretched and wish to reiterate that we do value input, but also accompany this with a need to be pragmatic with our own crash deadlines.
In advance of the formal Write Round, we would be more than happy to engage with you, your teams, or relevant stakeholders in your department to further elaborate on our plans, and answer any questions you may have. Could you please share any thoughts by EOD Thursday 11th of June?
If you would like to discuss the proposals and to feed into our ongoing work ahead of the upcoming write-round, please do get in touch with my colleague firstname.lastname@example.org.
In the meantime, please feel free to contact Jonathan with any other queries you may have on the above.