Artifact GuideUKDeadlines and Compliance Calendar

UK PSTI Product Security Deadlines and Compliance Calendar

Track the 29 April 2024 commencement, the 2025 amendments, product-specific support periods, record retention, and OPSS response and appeal windows.

Each clock has a different trigger. Record the product, responsible economic actor, source, start date, due date, and evidence rather than applying one deadline to every duty.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The UK PSTI product-security regime has applied since 29 April 2024. There was no general grace period for stock first made available after that date. Use this calendar to separate fixed legal dates from product-specific support commitments, record-retention periods, and deadlines triggered by an notice. Scope still depends on the product and whether the business acts as manufacturer, importer, distributor, or authorised representative.

Section 1

Fixed dates: commencement and the 2025 amendments

Part 1 of the Product Security and Telecommunications Infrastructure Act 2022 and the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 came fully into force on 29 April 2024. From that date, in-scope products made available to UK consumers had to meet the applicable product-security duties.

The first 2025 amendment came into force on 25 February 2025. It changed the 2023 Regulations and added exceptions for specified vehicle categories already governed by the listed sector legislation. The second amendment came into force on 4 December 2025 and added further conditions for deemed compliance, including conditions connected with Japan's JC-STAR STAR-1 and Singapore's Cybersecurity Labelling Scheme and a Schedule 2A route for the accompaniment duty. These are conditional routes, not blanket exemptions, and they do not retrospectively cure a failure before their commencement.

  • For a product first supplied after 29 April 2024, record why it is a relevant connectable product or why an exception applies.
  • For vehicle exceptions, match the product to the exact vehicle legislation listed in the amended Regulations; a connection to a vehicle is not enough by itself.
  • For a deemed-compliance route, retain the scheme, version, product coverage, conditions met, and evidence that the route applies to the particular duty.
  • Reassess the decision after a change to connectivity, intended purpose, branding, product composition, firmware, certification status, or supply-chain role.
Section 2

Product-specific dates and records

The Regulations do not set one minimum security-update period for every product. The manufacturer must publish the minimum period for which security updates will be provided and state an end date. Treat that published period as a product commitment and keep the customer-facing information aligned with the shipped model and firmware.

Manufacturers and importers must retain a copy of the statement of compliance for the longer of 10 years from the statement's issue date and the stated in the statement. Compare the date 10 years after issue with the support-period end date and use the later date. Chapter 2 also requires specified records of investigations and action on compliance failures to be kept for 10 years from the date each record is made. Check the Act and Regulations for the exact record duty that applies to the actor.

  • Record the statement issue date, the published support end date, and the later resulting destruction date for the retained statement copy.
  • Keep the support-period publication, release identifier, affected product models, approval record, and change history together.
  • Start each 10-year investigation-record clock from the date that record was made, not from product launch or discovery of a later failure.
  • Before shortening a support commitment for a later product version, check whether the customer-facing information remains clear and whether earlier products retain a different end date.
Section 3

Deadlines triggered by OPSS action

Start an enforcement clock from the event named in the notice or guidance, and preserve proof of service. A notice of intent for a Compliance Notice allows 10 days for written representations. Stop and Recall Notices normally use the same 10-day period, but may omit the notice of intent where the stated urgency conditions apply.

A notice of intent for a Monetary Penalty allows 28 days for written representations. A statutory First-tier Tribunal appeal against a Compliance, Stop, Recall, or Monetary Penalty Notice, its variation, or a compensation decision must generally be made within 28 days beginning with the event identified in the guidance. says it will give a written decision on an eligible Stop or Recall Notice compensation claim within 45 days. Read the served document and current tribunal rules for the exact trigger and filing method.

  • On receipt, record the service date, notice type, statutory basis, affected products, representation or appeal deadline, owner, and external-advice decision.
  • Do not assume that making representations suspends a proposed action or that every communication carries a statutory appeal right.
  • An appeal against a Compliance, Stop, Recall, or Monetary Penalty Notice suspends that notice pending the outcome; an appeal against a variation leaves the original notice in effect.
  • A payment date in a Monetary Penalty Notice is notice-specific. guidance says the payment period will usually be 28 days, but it may be longer and a separate daily-penalty period may apply.
Section 4

Build and maintain the calendar

Maintain one entry per product and legal trigger. A useful entry identifies the product and version, economic actor, applicable duty, trigger event, start date, due date, evidence owner, reviewer, source provision, and status. Keep fixed legal dates separate from recurring reviews and notice-driven deadlines.

Use reminders for internal preparation, but retain the statutory due date unchanged. Store the source time zone, calculation rule, weekends or holidays treatment, proof of service, and reviewer with the entry. If receipt time, service, product scope, or a deemed-compliance condition is disputed, record the assumption and obtain case-specific advice rather than silently moving the deadline.

  • Before UK supply: confirm scope, actor, security requirements, statement route, accompaniment method, support end date, and retained evidence.
  • After a suspected failure: open an investigation record, identify notification duties, document remedial action, and start the applicable retention clock.
  • On an notice: preserve the notice and proof of service, calculate the deadline from the stated trigger, and obtain legal review promptly.
  • At each product or regulatory change: review exceptions, deemed-compliance conditions, published support information, statements, and calendar entries.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Schedules 1 and 4 and regulations 7 to 9 establish the support-period information, statement content, and manufacturer and importer retention requirements.
Related guides

Explore more topics

UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a UK PSTI statement is required, the Schedule 4 fields, supply-chain checks, retention, digital accompaniment, and the December 2025 label route.
UK PSTI Act: vulnerability disclosure policy requirements and template
Publish a free, clear, accessible English reporting route plus expected acknowledgement and status-update times, and retain evidence that the information remained available.
UK PSTI applicability test: product, market, and actor scope
Apply the UK PSTI tests in order: connectivity, current exceptions, UK consumer availability, supply facts, and the manufacturer, importer, or distributor trigger.
UK PSTI compliance checklist for product release
Use a release checklist with scope, role, security-control, statement, records, and compliance-failure evidence for UK consumer connectable products.
UK PSTI compliance: duties, evidence, and response
Build a UK PSTI compliance process covering product scope, supply-chain roles, the three security requirements, statements, records, and post-market failures.
UK PSTI default password requirements
Apply the UK PSTI password rule to each relevant password, test unique-per-product generation, and keep reset and release evidence for the shipped model.
UK PSTI Default Password Rules
PSTI requires each covered password to be user-defined or unique per product. Unique credentials must not use prohibited predictable generation methods.
UK PSTI ETSI Evidence and Deemed Compliance
ETSI EN 303 645 and TS 103 701 can structure technical evidence, but the standards-based PSTI route depends on the exact mapped provisions and additional Schedule 2 conditions.
UK PSTI Excepted Products and Boundaries
An internet- or network-connectable product is outside the relevant-product definition only when a current Schedule 3 exception applies; record the exact category and facts rather than relying on a broad sector label.
UK PSTI Importer and Distributor Duties
Importers and distributors have their own statement, stop-supply, remediation, and notification duties; importers also have statutory investigation and 10-year investigation-record duties.
UK PSTI Manufacturer, Importer and Distributor Roles
Distinguish manufacturer, importer, distributor, and authorised-representative duties per product and supply route, including rebranding, imports, statement checks, stop-supply decisions, and compliance failures.
UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties
OPSS can use compliance, stop, and recall notices alongside monetary and other measures; notice recipients should preserve the notice, product scope, supply records, corrective actions, representations, and appeal dates.
UK PSTI password and security update policy requirements
Implement the UK PSTI password rule and publish a defined security support period with the required end date, access conditions, and change controls.
UK PSTI Product Security FAQ
Get direct, sourced answers on product scope, exceptions, roles, passwords, vulnerability reporting, update-period information, statements, records, and OPSS enforcement.
UK PSTI Product Security Importer and Distributor Duties Guide
Identify the pre-supply checks, statement or deemed-compliance evidence, stop-supply decisions, notification and remediation duties required of UK importers and distributors, plus importer-specific investigation and record duties.
UK PSTI Product Security Minimum Support Period and Update Transparency Guide
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in clear language, without implying that PSTI sets one duration for every product.
UK PSTI Product Security OPSS Enforcement and Penalties Guide
Understand OPSS investigations, compliance, stop and recall notices, monetary penalties, forfeiture, court orders, representations, appeals, and evidence needed to respond.
UK PSTI Product Security OPSS Notices Guide
Prepare for compliance, stop, and recall notices by understanding their effects, representation and appeal routes, product records, and corrective-action evidence.
UK PSTI Product Security Penalties and Fines Guide
Understand the maximum fixed and daily PSTI penalties, how OPSS sets an amount, representation and appeal rights, and separate court-ordered sanctions.
UK PSTI product security requirements
Read the three Schedule 1 security requirements and the surrounding manufacturer, importer, distributor, statement, record, and failure-response duties.
UK PSTI Relevant Connectable Product Scope
A product is relevant when it is internet-connectable or network-connectable and not excepted, then the UK consumer-use and supply facts determine whether the Part 1 duties engage.
UK PSTI relevant connectable product scope test
Decide whether one product meets the UK PSTI connectivity definition, falls within a current exception, and reaches the separate UK-consumer duty tests.
UK PSTI relevant connectable products: categories and exceptions
Understand which connected product categories can enter UK PSTI scope, how the statutory tests work, and why examples never replace the current exception schedule.
UK PSTI Scope Classifier Workflow
Decide whether a product falls within the UK PSTI product-security regime by checking connectivity, consumer supply, exceptions, actor roles, and product-specific evidence.
UK PSTI security requirements in practice
Implement the three UK PSTI security requirements through product specifications, release tests, public information, approvals, and post-release evidence.
UK PSTI Security Update Support Periods
PSTI does not prescribe a universal minimum number of support years. The manufacturer sets and publishes a product-specific minimum period and end date; preserve the published commitment and assess any later change against the current Regulations.
UK PSTI Security Update Transparency
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in language understandable without technical knowledge.
UK PSTI Statement of Compliance Evidence Pack
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
UK PSTI Statement of Compliance Template
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
UK PSTI Statement of Compliance Workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
UK PSTI Statement of Compliance: Contents, Delivery, and Records
A statement must contain the prescribed information and accompany the product unless a current deemed-compliance route applies; a digital method is possible, but each business must ensure that it meets the Act.
UK PSTI Support Period Evidence Workflow
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
UK PSTI to ETSI Evidence Mapping
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
UK PSTI vs Australia Smart Device Rules
Compare UK PSTI with Australia's Cyber Security Act smart-device rules by scope, duties, statements, security controls, retention, dates, and enforcement.
UK PSTI vs ETSI EN 303 645
See how binding UK PSTI duties relate to ETSI EN 303 645, which edition the UK Regulations name, what the standard adds, and what evidence to retain.
UK PSTI vs EU Cyber Resilience Act
Decide whether UK PSTI, the EU Cyber Resilience Act, or both apply, then compare actors, exclusions, security work, documents, reporting, and dates.
UK PSTI vs EU Cyber Resilience Act (CRA)
Compare UK PSTI and the EU Cyber Resilience Act by scope, security duties, support periods, conformity assessment, reporting, evidence, and application dates.
UK PSTI Vulnerability Disclosure Requirements
Publish a clear reporting route plus expected acknowledgement and status-update times. PSTI requires the information and timescales to be available; it does not prescribe one universal response deadline for every report.
UK PSTI Vulnerability Disclosure Workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.