The short answer: transitional mode is the practical starting point

WPA3 is the stronger Wi-Fi security choice, but a setting is useful only when the household's required devices can join it. Apple recommends WPA3 Personal for better security and WPA2/WPA3 Transitional for compatibility. The NSA gives the same broad direction: use WPA3, or WPA2/WPA3 when older devices require it.

Transitional mode lets a capable device connect with WPA3 while an older device uses WPA2 Personal. It is not the same as the old WPA/WPA2 option. That older option can allow the outdated WPA protocol or TKIP encryption and should stay off. On a WPA2 fallback, choose AES, the current encryption label shown beside WPA2 in many router menus.

There is one frustrating exception: some legacy devices fail even when transitional mode is supposed to accommodate them. Google's current Nest Wifi guidance explicitly warns that older WPA2 devices can have connection trouble while WPA3 transitional mode is enabled. If that happens, confirm the cause with a short WPA2-AES test rather than guessing that the Wi-Fi signal or 2.4 GHz band is broken.

Router setting Use it when What to know
WPA3 Personal Every required device has been tested and works Strongest normal home setting; an older WPA2-only device cannot join
WPA2/WPA3 Transitional The home contains a mixture of new and older devices Best starting point for most mixed homes; a few legacy devices still fail when WPA3 is advertised
WPA2 Personal (AES) A required device cannot use either setting above Reasonable compatibility fallback with a long unique Wi-Fi password and current router software; prefer a limited fallback network over downgrading every device
WPA, WPA/WPA2, WEP, TKIP, or open Never for an ordinary home network Outdated or unprotected choices; replace the router or device instead of keeping them

2.4 GHz and WPA3 answer different questions

A smart plug can be 2.4 GHz only and still support WPA3. Another 2.4 GHz plug may support only WPA2. The band describes which radio frequency the device uses; WPA describes how the device proves it knows the Wi-Fi password and protects traffic to the router.

That distinction matters during setup. Changing from WPA3 to WPA2 may fix the security-mode problem, while turning off 5 GHz may only help a setup app that handles a combined network badly. Do not leave bands split or disabled merely because a security-mode test worked. Tara's mesh Wi-Fi guide for smart-home devices explains combined network names, temporary setup modes, and coverage separately.

Read the full router label. “WPA2/WPA3” is a current transitional choice. “WPA/WPA2” is an older weak choice. One character changes the recommendation.

Choose the setting by the devices you must keep

  1. Use WPA3 Personal for a new or carefully tested network where every required device supports it.
  2. Use WPA2/WPA3 Transitional when the household mixes newer phones and computers with older smart-home devices. This is the sensible first setting for most existing homes.
  3. Use a separate WPA2 Personal (AES) network for the few essential devices that still fail transitional mode, if the router can provide it without using WEP, WPA, or TKIP.
  4. Replace the holdout when the only compatible router setting is obsolete, the device no longer receives updates, or the fallback network cannot be limited safely.

Do not judge compatibility from a brand name alone. Model, region, hardware revision, and firmware—the software stored inside the device—can change the answer. Community reports are useful warnings, not a promise that every unit with the same logo behaves identically.

Concrete examples show why model-level checking matters

The examples below separate the Wi-Fi claim from the control path. WPA2 or WPA3 protects the radio link to the router. Local control means commands travel inside the home's own network, also called its LAN. Cloud control sends commands through the vendor's internet service. Neither is guaranteed by the WPA setting. Matter—the cross-brand smart-home standard—and Apple Home are separate connection paths too.

Example Official Wi-Fi support Local control and cloud dependency Matter, Apple Home, and caveat
Google Nest Wifi Pro Google provides a WPA3 setting and describes the compatibility behavior as transitional mode The network is managed in the Google Home app; that says nothing about whether each accessory itself is local or cloud-controlled Nest Wifi Pro is a Matter-enabled hub and a Thread border router for Google Home. Thread is a low-power mesh used by some Matter devices. Google still warns that some legacy WPA2 devices fail in transition mode
TP-Link Tapo P110M (US) The current US product page says 2.4 GHz Wi-Fi but does not list a WPA mode, so the band alone is not proof of WPA3 support TP-Link says the Tapo app can control it on the home network when the internet is down and also offers remote app control. Home Assistant's TP-Link integration asks supported P110M devices for status locally after initial setup, while newer devices require TP-Link account credentials to prove local access is allowed It is Matter-certified and lists Apple Home, Alexa, Google Assistant, and SmartThings. Check the exact regional page, hardware version, and device software before changing the router
TP-Link Kasa EP25 The current product page lists 2.4 GHz and Apple HomeKit. TP-Link's current setup guidance tells users to leave WPA3-only for Auto or WPA2/WPA3 when HomeKit onboarding times out Home Assistant lists EP25 for direct local status and control, although newer revisions use TP-Link account credentials to prove access is allowed. The Kasa app can use TP-Link cloud services EP25 can join Apple Home directly. Hardware versions vary, and TP-Link's broader Kasa troubleshooting guide uses WPA2-AES as a diagnostic fallback rather than promising WPA3 for every Kasa model
ESPHome on ESP32 or ESP8266 Current ESPHome documentation allows an ESP32 to require WPA3; ESP8266 can require WPA2 or newer but cannot use the WPA3-only minimum setting ESPHome, open-source software for small smart-device boards, can communicate directly with Home Assistant and does not require a vendor cloud for normal local control A WPA setting does not add Matter or HomeKit. The merged ESPHome security-mode work also shows why chip and software version matter more than the case around the device

Reddit reports reinforce the caution. One r/homeassistant test found different results among Kasa plugs and device-software versions, a Zemismart Matter bulb, and a Sonoff plug running ESPHome. Treat that as evidence that mixed households need testing—not as an official compatibility list.

Change Wi-Fi security without taking the whole house down

  1. Record the current state. Save the router configuration if it supports backups, and note the network name, security setting, band setting, and any separate guest or IoT network.
  2. Update first. Install current router software and available device software before changing the Wi-Fi security mode.
  3. List the devices that matter. Include locks, thermostats, cameras, smoke-alarm bridges, voice speakers, hubs, printers, robot vacuums, and the phones or tablets used for setup.
  4. Choose a quiet test window. Changing WPA mode restarts many routers and disconnects every wireless device for a short time.
  5. Try WPA2/WPA3 Transitional first. Keep the same network name and password so compatible devices can reconnect without being reconfigured.
  6. Test behavior, not just a green Wi-Fi icon. Operate each critical device from its physical control, local platform, routine, and remote app where relevant. Check live camera video rather than only its online badge.
  7. Keep the rollback simple. If essential devices fail, restore the previous mode, then isolate one failing model for diagnosis.

If you are changing the router itself as well as its security, preserve only one variable at a time. Tara's router-change checklist for Matter and Thread homes covers names, credentials, controllers, and resets without confusing them with the WPA decision.

When a device will not join transitional mode

  1. Confirm the exact failure. If the device cannot see the network, suspect bands, signal, or the network name. If it sees the network but rejects the password or loops during joining, the security mode is more likely.
  2. Check the exact model and revision. Look at the device label and the vendor's regional support page. Do not rely on another model in the same family.
  3. Update both ends. Install current router and device software, then restart the router and the failing device once.
  4. Temporarily test WPA2 Personal with AES. If the device joins immediately, the problem is likely WPA3-only or transitional-mode compatibility. Return the main network to its intended setting after the test.
  5. Check setup isolation. The setup phone and device may need to discover each other locally. A guest network, device-to-device isolation (often called client isolation), VPN, or blocked local-network permission can stop setup even when the password is correct.
  6. Create the smallest safe exception. Move only confirmed holdouts to a WPA2-AES fallback network or replace them. Do not turn on WPA, TKIP, WEP, or an open network to rescue one plug.

TP-Link's April 2026 Kasa troubleshooting page is a good example of careful diagnosis: it recommends checking the exact model, local-network permission, signal, and setup state, then trying WPA2-AES when the device still cannot join. It does not say every failure is WPA3.

A separate WPA2 network needs two different decisions

First choose its Wi-Fi security mode: WPA2 Personal with AES, a long unique Wi-Fi password, and current router software. Then choose its network access: what the device may reach locally and on the internet. These are related security choices, but they are not the same setting.

  • Cloud-only accessory: it may need internet access but no access to personal computers. A limited IoT network can reduce what it can reach.
  • Locally controlled accessory: it must reach, or be reachable by, the local controller. Home Assistant's TP-Link integration, for example, connects to supported devices locally; automatic discovery can fail when the controller and device sit on separate network sections.
  • Matter over Wi-Fi accessory: it needs local communication with its Matter controller. The Connectivity Standards Alliance warns that ordinary guest isolation can block first-time setup and control.
  • Matter over Thread accessory: the accessory does not join the Wi-Fi SSID. Its Thread border router and Matter controller still connect through the home network, so isolating those supporting devices can still break control.
  • Apple Home accessory: local accessory communication must remain available, while remote access uses a home hub. A vendor cloud path, if the accessory also has one, is a separate choice.

A consumer router's guest-network switch often isolates devices with no fine control. An advanced firewall or VLAN—a separately controlled part of the home network—can be more precise, but it is also easier to misconfigure. Read Tara's main network versus IoT network guide before placing local devices on different network sections. If you want one stable local controller at the center of that design, the local smart-home hub guide explains that role without tying it to a cloud subscription.

Five mistakes to avoid

  • Choosing WPA3-only because the router is new: the router's support does not upgrade every device in the home.
  • Assuming transitional mode is perfect: it is the right first compromise, but some old WPA2 devices still mishandle it.
  • Confusing WPA2/WPA3 with WPA/WPA2: the former is a current transition; the latter can enable an obsolete protocol.
  • Putting local devices on an isolated guest network: they may reach the cloud yet become invisible to Matter, Apple Home, or Home Assistant.
  • Weakening the whole home for one abandoned device: use the smallest WPA2-AES exception that works, then plan to replace the holdout.

WPA mode is only one layer. Keep the router updated, use a long unique Wi-Fi password, remove devices that no longer receive security updates, and review Tara's plain-English smart-home security basics for accounts, remote access, and device lifecycle.

Tara's practical default

Start an existing mixed smart home on WPA2/WPA3 Transitional. Test every device that affects access, safety, comfort, or household routines. Move to WPA3-only only when the complete required list works—not when most devices work.

If one necessary device fails transitional mode, confirm it on WPA2 Personal with AES. Then give only the holdout a separate WPA2-AES path, preserve the local communication it genuinely needs, limit everything else, and record why the exception exists. Never solve the problem with WEP, WPA, TKIP, or an open network.

Frequently asked questions

Should smart home devices use WPA2 or WPA3?

Use WPA3 Personal when every required device connects reliably. For a home with a mixture of old and new devices, use WPA2/WPA3 Transitional. If a legacy device still fails, put only that device on a separate WPA2 Personal network using AES while preserving any local communication it needs.

Is WPA2 still safe for smart devices?

WPA2 Personal with AES remains a practical compatibility setting when WPA3 cannot be used, especially with a long unique Wi-Fi password and current router software. Avoid WPA, WPA/WPA2 mixed mode, WEP, TKIP, and open networks.

Why will a WPA2 device not connect to transitional mode?

Some older devices mishandle the extra security information broadcast by a transitional network. Update the software inside both the router and device, then test WPA2 Personal with AES briefly to confirm that the security mode is the cause.

Does a 2.4 GHz smart device support WPA3?

Not necessarily. 2.4 GHz describes the radio band; WPA2 and WPA3 describe connection security. A device can use 2.4 GHz yet support only WPA2, so check the exact model and hardware version.

Can Matter and Home Assistant devices use a separate WPA2 network?

They can only if that network still allows the local communication their controllers need. Guest or device-to-device isolation can block Matter setup, discovery, and local Home Assistant integrations. A Thread accessory does not join Wi-Fi itself, but its Thread border router and controller still need appropriate network access.