The Promise on the Box
A connected device ships with two lifespans that rarely match. The first is physical: how long the hardware stays functional. The second is contractual: how long the vendor commits to sending it security patches and firmware updates. The first is rarely stated at point of sale. The second, until recently, almost never was.
That second lifespan is what matters most to anyone running software that touches a network. A thermostat or a security camera left unpatched is not merely inconvenient; it is an open port. Researchers have demonstrated remote code execution on consumer routers, baby monitors, and smart locks running firmware several years out of date, exploiting vulnerabilities that were known and fixed upstream but never pushed to the device. The vendor had moved on. The hardware was still in the wall.
The pattern is consistent enough to have a name in security research: the patch gap. It describes the lag between a vulnerability being disclosed and a patch reaching an embedded device — if it reaches it at all. For devices past their stated support window, that lag is permanent.
Chronology
- 2016Revolv hub shut down by Nest with no transition period
- 2023Google announces seven-year update commitment for Pixel 8; FCC Cyber Trust Mark announced
- 2024Samsung commits to seven years for Galaxy S24; UK PSTI Act comes into force (April); EU Cyber Resilience Act agreed by European Parliament
- 2027Most EU Cyber Resilience Act obligations become enforceable
What the Numbers Actually Show
The Revolv hub, acquired by Nest and shut down in 2016, simply ceased to function when its cloud service was terminated — no patch, no transition period, no local mode.
Support commitments across consumer hardware categories have historically clustered around two to five years from the date of sale, with smartphones generally at the longer end and smart-home peripherals at the shorter. For much of the 2010s, many router manufacturers and smart-home vendors published no support commitment at all. The firmware shipped at launch was sometimes the firmware shipped at end-of-life.
The comparison that sharpens the problem is against physical durability. Consumer electronics research consistently shows median product lifetimes for household electronics extending well past a decade in actual use, while stated software support can expire in two or three years. The device continues to be used; the software support does not continue with it.
Smartphone makers provide the most documented comparison. Apple's iOS support window has stretched to roughly five to six years from device introduction, covering several major OS generations. Google extended Pixel support from three years to seven years of OS and security updates beginning with the Pixel 8 generation, announced in 2023. Samsung committed to seven years of security patches for its flagship Galaxy S24 series, also in 2024. These are among the longest commitments in the consumer market, and they are still shorter than the typical physical lifespan of a phone that is not deliberately broken.
For smart-home devices, the picture is worse. Many hubs and bridges that went dark between 2015 and 2023 had published no support window at any point in their commercial life. The Revolv hub, acquired by Nest and shut down in 2016, simply ceased to function when its cloud service was terminated — no patch, no transition period, no local mode. The hardware became inert. The question of "how long will this be patched" was answered only when it stopped being patched.
Regulation Begins to Require Disclosure
That opacity is what recent legislation targets. The European Union's Cyber Resilience Act ↗, agreed by the European Parliament in 2024, requires manufacturers of connected products sold in the EU to publish a support period and to provide security updates for at least five years — or the expected product lifetime, whichever is shorter. Products that fall below this standard cannot carry the CE mark. The Act phases in over several years, with most obligations applying from 2027.
The United Kingdom's Product Security and Telecommunications Infrastructure Act, which came into force in April 2024, imposes similar transparency requirements: manufacturers must publish the minimum period for which a product will receive security updates, and that period must be stated at the point of sale. The "defined support period" concept is now statutory, not a marketing choice.
In the United States, the FCC's voluntary Cyber Trust Mark scheme, announced in 2023 and still in early rollout as of early 2025, allows manufacturers of qualifying connected devices to display a label confirming that the product meets minimum security standards — including a published support period. Participation is not mandatory, which limits its force, but it establishes a public reference point for what a reasonable commitment looks like.
What "Support" Actually Covers
A support commitment can be structured in ways that make it sound more substantial than it is. Security patches are the narrowest and most important category: they fix known exploits. Feature updates add capabilities; they are rarely required for safety. End-of-life dates sometimes refer to the end of full OS updates, after which a device may receive only critical security patches on a degraded schedule — a distinction manufacturers have not always been forthcoming about.
The device that receives patches only for critical CVEs (Common Vulnerabilities and Exposures) after year three is not receiving the same support it received in year one. Some vendors publish both dates; many publish only the more favourable one. Reading a support commitment carefully means asking what category of update stops when, not just what year the support ends.
There is also the question of where the support window starts. Counting from date of manufacture rather than date of sale can silently shorten the effective window for devices that sit in distribution for months before reaching a buyer. The EU's Cyber Resilience Act addresses this by requiring that the five-year minimum run from the date the product is made available on the market, a formulation that at least shifts the reference point toward the consumer.
Key distinctions
- Security patch — fixes a known exploit; most critical category for a networked device
- Feature update — adds capability; not required for safety or security
- Critical-only patch period — degraded schedule some vendors offer after full support ends; often not clearly separated from headline support date
- Support start date — may be manufacture date or market-availability date; affects how long a buyer actually receives support
What This Means at Point of Purchase
For a buyer evaluating a connected device today, the relevant questions are: Is a support period published? Does it cover security patches specifically, or only general updates? Does it run from sale date or manufacture date? Is there a local-control fallback if the vendor cloud disappears — and if not, does the community around platforms like Home Assistant already support the device?
A device with a published five-year security-patch commitment, the ability to operate on the local network without phoning home, and an active open-source integration is a different purchase from a device with a two-year implied window and no local mode. Both may be sold at the same price. The difference shows up later, and it shows up all at once.
The hardware will almost certainly outlive the patch window. The only variable is how far.