
On February 1, 2026, a lot of people woke up to a coffee maker that was just a coffee maker again.
Belkin’s Wemo shutdown had landed the night before, and with it went the app, the cloud service, the Alexa routines, the “start the coffee when my alarm goes off” automation that someone had spent an afternoon getting right. The hardware was fine. The plastic was fine. The Wi-Fi radio inside was fine. It just had nothing left to talk to.
This is the part of the smart home nobody puts on the box: every connected device you own has an expiry date, and until very recently, no manufacturer was obliged to tell you what it was. That changes — slowly, unevenly, and starting this week in Europe.
What actually happens on September 11
On September 11, 2026, the reporting obligations in the EU’s Cyber Resilience Act (CRA) come into force. From that date, any manufacturer selling a product with digital elements into the EU must report actively exploited vulnerabilities and severe security incidents through the CRA Single Reporting Platform, on a clock that is genuinely aggressive: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report within 14 days of a fix being available (or a month, for severe incidents). Reports go to a national CSIRT and are made available to ENISA at the same time.
Two details matter more than the rest.
First, this applies to products already on the market. The CRA’s full compliance regime doesn’t land until December 11, 2027, but the reporting duty covers devices sold before that date. The smart plug already in your wall is in scope.
Second, the penalties are not symbolic. Non-compliance with the reporting obligations can draw administrative fines of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher. That is the number that gets a smart home brand’s legal department to return calls.
You can read the European Commission’s own summary of the CRA reporting obligations if you want the primary source. It is short, and it is unusually readable for an EU document.
Here’s the honest caveat, though: none of this tells you when your device dies. It tells you that when a vulnerability is being actively exploited, somebody official finds out fast. That’s real, and it’s overdue. But it is not the expiry date.
The clause that actually matters comes in December 2027
The CRA provision that will change how you shop hasn’t kicked in yet. When the regulation fully applies on December 11, 2027, manufacturers must define a support period for each product — and it must be at least five years, unless the product is genuinely expected to be used for less time than that. Manufacturers have to document why they picked the number they picked.
And critically: the end of the support period has to be communicated to the buyer at the time of purchase, specifying at least the month and the year.
Read that again, because it’s the single most consumer-friendly sentence in modern smart home regulation. Not “we support it for a while.” Not “as long as commercially reasonable.” A month and a year, on the product page, before you pay.
If you’ve ever tried to work out whether a four-year-old smart lock is still getting firmware, you know exactly how much work that one line removes.
The UK got there first — and left the loophole open
Britain’s Product Security and Telecommunications Infrastructure Act (PSTI) has been in force since April 2024, and it already requires manufacturers to publish a “defined support period” — expressed as a period of time with an end date, in language a non-technical buyer can understand. If a manufacturer’s website invites you to buy the product, the support period has to be published there too.
It’s a genuinely good rule with one enormous gap: PSTI sets no minimum. There is no stipulation about how long the support period has to be, or how many updates it has to include. A manufacturer can be fully compliant by declaring a support period of two years and honouring it exactly.
That is why the CRA’s five-year floor matters so much. The UK made vendors say the number. The EU is about to make the number mean something.
Note also what PSTI does not do: it doesn’t require a product to be capable of receiving security updates at all. If the hardware can’t be patched, the support period rules simply don’t apply to it. That is not a hypothetical — plenty of cheap Zigbee sensors ship with firmware that is never going to change.
Meanwhile, in America: a sticker, and it’s optional
The US approach is the Cyber Trust Mark, an FCC-run labelling programme for wireless consumer IoT products. Certified devices carry a shield logo plus a QR code that pulls up plain-English security information — including, in principle, how long the thing will be supported.
It is voluntary, and it has had a bumpy 2026. UL Solutions, originally picked to run the programme, withdrew as lead administrator in December 2025, and the FCC selected the nonprofit ioXt Alliance to take over on April 14, 2026. Government-approved labs test voluntarily submitted products; nobody is compelled to submit anything.
That voluntariness is the whole problem. A label that only appears on devices from manufacturers confident enough to seek it out tells you something useful about the ones that have it, and nothing at all about the ones that don’t — which is most of the market.
So the state of play globally: the EU is writing rules, the UK is enforcing disclosure without a floor, and the US is offering a badge that manufacturers can decline. If you buy internationally — and most of us do — you get the union of all three, which in practice means you should assume nothing and check manually.
What the big platforms actually promise right now
Here is where it gets uncomfortable, because the published commitments are shorter than most people assume.
Google Nest is the clearest and the most generous of the major platforms. Google’s published policy states that Nest connected home devices “will receive automatic security updates for at least 5 years from the date we start selling them on the US Google Store.” Note the start of that clock — it runs from launch, not from your purchase. Buy a Nest device three years into its life and you have inherited a two-year guarantee, not a five-year one. Google publishes its security update commitments and validation results publicly, which is more than most of its competitors do.
Amazon Echo devices are covered by a shorter but more buyer-friendly clock. Amazon’s Echo software security updates policy commits to updates until at least four years from when you bought the device new from Amazon as the seller. Four years is less than five, but running the clock from purchase rather than launch is arguably the fairer construction. Amazon is also blunt that the update period “is not a guarantee as to how long your device will last,” which is at least honest.
Almost everyone else publishes a PSTI statement of compliance because they must, buries it in a PDF, and says nothing anywhere a shopper would look. If you want to know the support period for a mid-market smart lock or a Zigbee sensor, you will be downloading a compliance document. That is the current reality, and it’s exactly what the CRA’s December 2027 disclosure rule is designed to end.
The uncomfortable truth: support periods don’t stop shutdowns
Now for the part that most coverage of these regulations gets wrong.
A support period is a promise about security patches. It is not a promise that the cloud service stays online. Those are completely different commitments, and only one of them is being regulated.
The proof is Google’s own thermostat. The Nest Learning Thermostat (1st and 2nd gen) stopped connecting to the Nest and Google Home apps on October 25, 2025. No remote control, no notifications, no Home/Away Assist, no third-party assistant integration. The hardware still works — you can walk up to it, turn the ring, change modes, run its stored schedule — but the smart half is gone.
And here’s the thing: Google didn’t break its five-year promise. The 1st gen launched in 2011. It got roughly fourteen years. The commitment was honoured several times over, and the device still ended up as a well-designed manual thermostat.
That’s the gap no regulation currently closes. Five years of guaranteed patches means nothing if the servers the device depends on get switched off in year six. Until “service continuity” becomes a regulated disclosure the way “support period” is about to be, the only defence is architectural.
Which is why local control is the actual insurance policy
Look again at the Wemo shutdown, because it ran a controlled experiment for us.
When Belkin’s cloud went dark on January 31, 2026, the app died, remote access died, and the Alexa and Google Assistant integrations died. But Wemo devices that had already been paired to Apple HomeKit before that date kept working — locally, in the Home app, with no cloud involved. Thread-enabled Wemo hardware kept running the same way. Belkin’s own end-of-support notice spells this out, including the trap: after January 31, you could no longer set up a Wemo device with HomeKit. If you hadn’t paired it, you’d missed the window. (Belkin also offered partial refunds for devices still under warranty on or after that date, with proof of purchase — worth knowing if you have a drawer full of them.)
Two functionally identical smart plugs, same shutdown, completely different outcomes. The difference wasn’t the brand or the price. It was whether the control path ran through a company’s server or through a protocol on your own network.
This is the strongest practical argument for Matter and Thread that exists, and it has nothing to do with setup convenience. A Matter device that has been commissioned into your home is controlled locally by your hub. When the manufacturer’s cloud goes away, the device keeps taking commands, because the commands were never going through the manufacturer in the first place. It is worth understanding what Matter 1.6 changed here — Joint Fabric in particular makes it easier to have a device answer to more than one ecosystem, which is a hedge against any single platform walking away.
The same logic is why serious camera owners have moved to local NVR setups like Frigate and Scrypted rather than trusting a subscription to outlive the hardware. A hub that runs your automations on-device — an Aqara M3 or similar local-first controller — turns a vendor shutdown from a catastrophe into an inconvenience.
A buying checklist that takes four minutes
Before you add anything connected to a cart:
1. Find the support period. Search "<brand> <model>" PSTI support period or "<brand>" security update policy. If the manufacturer sells into the UK, that document legally exists. If you genuinely cannot find it, treat that as an answer.
2. Check when the product launched, not when you’re buying. If the vendor’s clock runs from first sale (Google’s does), a device that’s been on shelves for three years has already burned most of its guarantee. Clearance pricing on old smart home stock is usually clearance pricing for a reason.
3. Ask what breaks if the company disappears. Does the device work over Matter, Thread, Zigbee, or Z-Wave to a hub you own? Or is the app the only way in? Wi-Fi-plus-proprietary-cloud is the single riskiest architecture in the smart home, and it’s still the most common one in the budget tier.
4. Prefer devices that can be adopted by a hub you control. Home Assistant, a Matter controller, a Zigbee coordinator — anything that means the automation logic lives in your house.
5. Treat a bridge or hub as a dependency, not a feature. Every proprietary bridge in your setup is another company whose business decisions can brick your gear.
What to do about the devices you already own
You don’t need to rip anything out. But it’s worth spending an evening doing three things.
Inventory what’s cloud-only. Walk your automations and note which ones would stop if a specific app disappeared. That list is your actual risk exposure, and it’s usually shorter and more concentrated than people expect — typically one or two brands doing a lot of work.
Pair things locally now, while you still can. The Wemo lesson is that the local pairing window closes with the cloud, not after it. If a device supports Matter, HomeKit, or a local hub and you haven’t set that up because the vendor app was easier, do it before you need to.
Segment the old stuff. Devices past their support period will not get patched again, and unpatched IoT on your main network is a genuine problem rather than a theoretical one. Putting them on a separate SSID or VLAN is the standard mitigation — we covered how to structure a smart home network in detail, and it’s the highest-value hour you can spend on smart home security.
The bottom line
September 11 is not the day your smart home changes. It’s the day manufacturers lose the ability to sit quietly on an actively exploited vulnerability in a product they sold you, which is a real improvement that you will mostly never see.
The date to actually circle is December 11, 2027, when a support period with a month and a year has to appear at the point of sale across the EU. That single disclosure will do more for smart home buyers than any feature shipped this year, because it converts a question you currently can’t answer into a number printed next to the price.
Until then, the rule hasn’t changed: buy devices that work without their manufacturer. Every regulation described above is trying to give you information. Local control gives you independence — and independence is the only thing that survives a shutdown notice.


