PSTICompliance Hub

UK PSTI Act Scope, Security, and Supply Chain Duties

Decide whether a product supplied to UK consumers is a , identify the manufacturer, importer, and distributor duties, then implement the three security requirements and the statement-of-compliance process.

By Sorena AIBased on PSTI legislation, OPSS, and ETSI materialsUpdated July 2026
Implementation focus
UK PSTI
Scope and categories
Start with sections 4-6 and 54-55 of the Act, Schedule 3 to the 2023 Regulations as amended, intended consumer use, UK supply history, and role allocation.
Mandatory controls
Implement the three mandatory requirements: no universal default or easily guessable passwords, vulnerability disclosure information, and published information.
Statements and enforcement
Use the ordinary and accompaniment route or document every condition of an applicable Schedule 2A route. Retain statements for the longer of 10 years from issue or the , and keep an OPSS response file ready.

Use the timeline and guides to move into the role, statement, and control pages for execution.

Key dates
6 Dec 2022
Royal Assent
29 Apr 2024
In force
3 duties
Mandatory controls
10 years or support period
Statement retention, whichever is longer
Core PSTI decisions
Product scope
Test internet or network connectivity and the current exceptions. Then apply section 54: the product must meet the UK consumer route or the identical-product business-supply route, including the prior-supply, return, reconditioning, and installation rules.
Role and evidence
Classify each legal entity as manufacturer, importer, distributor, or authorised representative for the exact product and route. Own-brand and white-label supply can change the role.
Security implementation
Build release evidence for covered password behavior, a public security-reporting route with acknowledgement and status-update timing, and a published minimum update period with an end date.
Scope first
3 UK PSTI requirements
Statement evidence
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Feb 22, 2026
Updated
Jul 16, 2026

The Act creates the product-security framework; the 2023 Regulations specify the current password, vulnerability-reporting, support-period, exception, and statement requirements. The 2025 amendments changed vehicle exceptions and added limited deemed-compliance routes, so use the current rules rather than treating the 2022 Act alone as the complete duty set.

PSTI Timeline

Key dates for UK product security implementation

Track PSTI milestones and commencement timing so product, legal, and compliance teams can stage controls and documentation with clear ownership.

Loading timeline...
Recommended PSTI path

Move from product scope to documented UK evidence

New to the regime? Start with product scope and your supply-chain role. If scope is already settled, jump to the three security requirements, statement evidence, enforcement, dates, or comparisons.

1

Start here: scope and roles

Decide whether the product and UK supply route are covered before applying controls.

2

The three security requirements

Implement the binding password, vulnerability-reporting, and minimum-update-period rules without confusing the wider ETSI baseline with UK law.

3

Implementation and evidence

Build release gates, statements, records, disclosure operations, and standards mappings that match the shipped product.

UK PSTI compliance checklist for product release
Use a release checklist with scope, role, security-control, statement, records, and compliance-failure evidence for UK consumer connectable products.
Read guide
UK PSTI compliance: duties, evidence, and response
Build a UK PSTI compliance process covering product scope, supply-chain roles, the three security requirements, statements, records, and post-market failures.
Read guide
UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a UK PSTI statement is required, the Schedule 4 fields, supply-chain checks, retention, digital accompaniment, and the December 2025 label route.
Read guide
UK PSTI Statement of Compliance Evidence Pack
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
Read guide
UK PSTI Statement of Compliance Workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
Read guide
UK PSTI Statement of Compliance Template
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
Read guide
UK PSTI Vulnerability Disclosure Workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.
Read guide
UK PSTI Support Period Evidence Workflow
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
Read guide
UK PSTI to ETSI Evidence Mapping
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
Read guide
4

Supply-chain checks and enforcement

Understand stop-supply decisions, compliance-failure escalation, OPSS notices, appeals, and penalties.

5

Dates and continuing obligations

Separate fixed commencement and amendment dates from product-specific support commitments and enforcement-response deadlines.

6

Comparisons

See what PSTI shares with ETSI, the EU CRA, and Australia, and which UK duties still need separate evidence.

Next step

Turn the UK PSTI guidance into an assessment

Use the hub as the shared starting point for product scope, actor duties, control evidence, statements, and post-release response.

What this unlocks
  • Assign the assessment to the legal entity, product model, release, and UK route to market.
  • Map each applicable duty to an owned task, evidence request, and review checkpoint.
  • Use cited research for unresolved scope, timing, and interpretation questions.
  • Keep the decision, released-product evidence, statement, and follow-up actions together.
UK PSTI Act compliance hub preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.