Almost everyone asks this question the same way, and the way it is asked is the problem. A lock does two jobs. It resists someone trying to force it, and it controls who is allowed through. Traditional locks are good at the first and have essentially no answer to the second. Smart locks change the second job completely and, in most cases, barely touch the first.
So the useful question is not which is more secure. It is which of those two jobs your door is currently failing at.
What actually happens in a break-in
Burglary in England and Wales is falling. Police recorded 223,456 burglary offences in the year ending March 2026, down 9% on the year before, according to the Office for National Statistics.
Two patterns matter for this question. The front or back door is how most burglars get in — not windows, and not upstairs. And a substantial minority of break-ins involve no force at all: a door or window that was simply left unlocked. Nothing was defeated, because nothing was engaged.
Where force is used on a uPVC or composite door, the classic attack is lock snapping — breaking the euro cylinder in two and manipulating the mechanism behind it. The Master Locksmiths Association put snapping at 8.32% of burglaries in 2019, down from 15.26% in 2010, a fall it credits to anti-snap cylinders becoming normal rather than specialist.
On force, the smart part is not the part being attacked
Retrofit smart locks — the common kind in the UK — fit to the inside of the door and turn the existing cylinder for you. From the street, the lock is unchanged. A burglar snapping the cylinder is attacking exactly the same piece of metal they would have attacked before, and the electronics on the other side are irrelevant to whether it holds.
Which means the security question for a retrofit is not about the smart lock at all. It is: what is the cylinder rated to? TS007 3-star (a BSI Kitemark) and Sold Secure Diamond (SS312) are the two ratings to look for; both are tested against snapping, drilling, picking and bumping, and both are recognised by Secured by Design. A 3-star cylinder with a smart drive on the back is a well-protected door. The same smart drive on an unrated cylinder is not, and the app will not tell you the difference.
Products exist that do both properly. The Ultion Nuki pairs a 3-star Ultion cylinder with Nuki's smart drive, keeps a manual thumbturn and a mechanical key override, and carries TS007 3-star and Sold Secure Diamond as a unit. We mention it as an example of the shape, not as a recommendation over anything else — we have not tested it against its rivals.
The upgrade that actually resists force is a rated cylinder. The smart lock is what you fit behind it.
There is a version of this that goes the wrong way. Replacing a certified 3-star cylinder and handle with an all-in-one smart handle set that carries no rating at all is a downgrade dressed as an upgrade. It happens, it is usually a price decision, and it is the single most common way a smart lock makes a door less secure than it was.
The break-ins where nothing was forced
Here the comparison stops being close. A traditional lock has no opinion about whether you locked it. If you pulled the door to and did not lift the handle and turn the key, a multipoint door is latched, not locked, and it will open to a firm push.
Auto-lock changes that. The lock throws its own bolts a set number of seconds after the door closes, every time, whether or not anyone remembered. Against the category of burglary where no force was used at all, that is not a marginal gain — it removes the opening entirely. It is the least discussed smart lock feature and, on the numbers, probably the most valuable one.
The key you cannot take back
Think about who has been given a key to your property over the years. A previous tenant. A cleaner. Whoever fitted the kitchen. An ex-partner. In each case you either got the key back or you did not, and in none of those cases do you know whether a copy was cut first. Copying a key takes minutes, costs a few pounds, and leaves no trace on the original.
The only real remedy a traditional lock offers is to change the cylinder, which costs money, takes a visit, and invalidates every other key at the same time. So most people do not do it, and access quietly accumulates.
A code or a phone credential is different in kind. It can be issued to one person, limited to particular hours or dates, and withdrawn in seconds from anywhere without touching the door. Most systems keep a log of which credential opened the lock and when, which settles the question of whether the contractor came on Tuesday rather than leaving it to recollection.
For a landlord between tenancies, this is the whole argument. The changeover stops being a locksmith visit and becomes an admin task.
The counterweight is worth stating plainly, because it rarely is. An access log is a record of a person's comings and goings from their own home, and that is personal data with an obvious potential for misuse. Digital rights groups have argued, reasonably, that tenants should not have to accept being logged as a condition of getting through their own front door. If you are the landlord holding that log, the question of what you keep, for how long and who can see it is one you should have an answer to before a tenant asks.
Alarms and notifications: useful, and often oversold
Many smart locks watch for being attacked. A vibration or shock sensor picks up impact on the door or lock body, a tamper switch notices the housing being opened, and the lock responds by sounding an alarm at the door and pushing an alert to your phone.
This is genuinely valuable and it is genuinely new — no mechanical lock does anything remotely like it. An alarm going off at the door mid-attempt is a real deterrent, because a burglar's working assumption is that nobody knows yet. And the difference between learning about a break-in as it happens and learning about it when you get home at seven is the difference between a phone call to the police and an insurance claim.
But be clear about what it is. It is detection, not resistance. The alert does not make the door harder to get through by one newton. If the door, frame, cylinder and bolts are weak, a tamper alarm means you will be notified promptly that they failed.
One practical point that catches people out, and which is worth checking before you buy on the strength of this feature: a notification has to have something to travel over. A Bluetooth-only lock talks to a phone within a few metres and nothing else. For an alert to reach you at work, the lock needs a bridge or gateway on your wi-fi, or its own wi-fi radio. Plenty of locks advertise tamper alerts and then sell the gateway that makes them work separately.
The new failure modes
Adding electronics to a lock adds ways for it to go wrong that a mortice lock does not have. Three are worth knowing about.
Power. Batteries go flat. In practice this is close to a solved problem — locks warn for weeks and sensible ones keep a mechanical override — but it is a real consideration and it is the thing people ask about first.
Wireless. Locks that unlock on proximity are a research target. NCC Group demonstrated the first link-layer relay attack against Bluetooth Low Energy, defeating proximity authentication of the kind used in vehicles and residential smart locks, using inexpensive hardware. Security researchers have kept finding weaknesses in Bluetooth-based locks since. This is not a reason to avoid smart locks; it is a reason to prefer a deliberate unlock — a code, a fingerprint, a tap — over one that opens whenever your phone is somewhere nearby.
The installation. Far more common than either. A lock fitted to a misaligned door, or a gateway placed where the Bluetooth cannot reach it, produces a lock that does not reliably throw its bolts. That is a security failure, and no rating on the box prevents it.
What UK law now requires of the manufacturer
This one is recent enough that most buying guides have not caught up. The Product Security and Telecommunications Infrastructure Act 2022 has applied to consumer connectable products sold in the UK since 29 April 2024. A smart lock is squarely within scope.
It bans universal default passwords, so a lock can no longer ship with the same admin credentials as every other unit. It requires the manufacturer to publish a vulnerability disclosure policy — a route for researchers to report flaws. And it requires them to state the minimum period for which the product will receive security updates.
That last one is the most useful thing on this page for a buyer. It is a published, comparable number, and a lock supported for five years is a materially different purchase from one supported for one. Look for it before you buy, not after.
Where insurance stands
In practice this is usually straightforward, and it follows directly from the point above. Most UK home insurance policies specify locks on final exit doors, and the familiar wording asks for a lock conforming to BS3621 — a mechanical standard, because that is what existed when the wording was written.
A retrofit smart lock leaves that lock in place. The certified cylinder or mortice is still there, still doing the same job, still meeting the same clause; the smart part turns it for you. That is why the retrofit approach is the one to prefer, and it is the same reason it holds up against force.
Where it is worth a phone call is a full replacement — swapping the certified lock out for an all-in-one unit. Policies vary on those, so check your own wording, and if it is ambiguous ask the insurer and keep the reply. Ten minutes, once.
Two jobs, compared
| Resisting force | Decided by the cylinder, bolts, door and frame — not by whether the lock is smart |
|---|---|
| If you forget to lock it | Traditional: it stays unlocked. Smart: auto-lock throws the bolts anyway |
| If a key or code goes astray | Traditional: change the cylinder. Smart: revoke it in seconds |
| Knowing who came in | Traditional: no record exists. Smart: a timestamped log, on most systems |
| While a break-in is happening | Traditional: nothing. Smart: door alarm and a phone alert, if a gateway is fitted |
| Power | Traditional: none needed. Smart: batteries, with a mechanical or emergency override |
| Insurance wording | Traditional: BS3621 is the familiar answer. Smart: check the policy before fitting |
Verdict
Best forAnyone who shares access — landlords, hosts, households with cleaners or carers — and anyone whose real risk is forgetting to lock up
What works
- Auto-lock removes the unforced break-in entirely
- Access can be issued, time-limited and withdrawn without changing anything on the door
- A log of who opened it and when, which no mechanical lock offers
- Tamper alarms and alerts tell you during, not after
What doesn't
- Adds nothing against force unless the cylinder is rated — and can subtract, if it replaces one that was
- Alerts need a gateway that is often sold separately
- Batteries, and Bluetooth proximity unlock has a documented weakness
- A full replacement unit, unlike a retrofit, is worth checking against your policy wording
Where these figures come from
Recorded burglary figures are the Office for National Statistics' Crime in England and Wales bulletin for the year ending March 2026. The lock snapping proportions are the Master Locksmiths Association's. The relay attack on Bluetooth Low Energy was published by NCC Group. TS007 and Sold Secure Diamond are the BSI and Sold Secure schemes respectively. The manufacturer obligations are in the Product Security and Telecommunications Infrastructure Act 2022 and its 2023 regulations, in force from 29 April 2024.
Where we have said something is common or typical rather than giving a number, that is deliberate: it is what we see on doors, and we would rather say so than dress it up as a statistic.