CalendarImplementation Milestones

Deadlines and Compliance Calendar

Use the legal timeline as an operating calendar, not as background history.

The commencement and review dates should drive statement, release, and record-retention planning.

Author
Sorena AI
Published
Feb 22, 2026
Updated
Feb 22, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Feb 22, 2026
Updated Feb 22, 2026
Overview

The PSTI regime has fewer implementation phases than some broader platform laws, but the dates still matter. The Act received Royal Assent in 2022, commencement moved in stages, the security requirements came into force on 29 April 2024, the first 2025 amendment came into force on 25 February 2025, the second 2025 amendment came into force on 4 December 2025, and the regulations require a first review report within five years of the 29 April 2024 commencement date.

Recommended next step

Turn Deadlines and Compliance Calendar into an operational assessment

Assessment Autopilot can take Deadlines and Compliance Calendar from planning deadlines, owners, and milestones from this page to a reusable workflow inside Sorena. Teams working on Deadlines and can keep owners, evidence, and next steps aligned without copying this guide into separate documents.

Section 2

Standards, amendments, and policy updates to watch

The original regulations reference ETSI EN 303 645 V2.1.1 for one deemed-compliance route, while the current law also preserves an ISO/IEC 29147 route for vulnerability disclosure and, since 4 December 2025, recognizes current JC-STAR STAR-1 and Singapore Cybersecurity Labelling Scheme labels in Schedules 2 and 2A. OPSS enforcement policy updates also matter because they show how the authority frames risk, proportionality, and escalating intervention.

These updates should be reflected in assurance and governance review, even if they do not automatically change the three statutory duties.

  • 19 June 2020: referenced ETSI V2.1.1 adoption date
  • 11 September 2024: ETSI V3.1.3 adoption date
  • 25 February 2025 and 4 December 2025: current amendment dates that change scope and deemed-compliance analysis
  • 27 January 2025 and 26 January 2026: later OPSS policy update points
Section 3

Review and retention planning dates

Regulation 10 requires the first review report before the end of five years beginning with the date the regulations came into force. That puts the first review deadline by 28 April 2029. Statement retention also runs beyond standard document periods where the defined support period is longer, but only where the statement route is being used.

These dates should be visible in the compliance calendar, not hidden in legal notes.

  • By 28 April 2029: first review report due
  • Statement retention: 10 years or the support period, whichever is longer, where a statement is required
  • Schedule support-period review before any product support commitment changes
Primary sources

References and citations

gov.uk
Referenced sections
  • Risk-based, proportionate, transparent, and escalating enforcement approach used by OPSS.
Related guides

Explore more topics

UK PSTI Act Applicability Test | Relevant Connectable Product Scope and Exclusions
Grounded UK PSTI applicability test covering section 4 relevant connectable product logic, internet-connectable and network-connectable products.
UK PSTI Act Checklist | Scope, Statements, Security Controls, and Records
Audit-ready UK PSTI checklist covering product scope, role allocation, the three mandatory security requirements, statement of compliance handling, retention.
UK PSTI Act Compliance Program | Product Security Governance and OPSS Readiness
Program design guide for UK PSTI compliance covering product scope, engineering controls, statement governance, supply-chain checks.
UK PSTI Act FAQ | Scope, Statements, Support Periods, and OPSS Questions
Practical FAQ on the UK PSTI regime covering product scope, the three mandatory requirements, statement of compliance issues, role duties, retention.
UK PSTI Act Requirements | Mandatory Security Duties, Statements, and Records
Detailed UK PSTI requirements guide covering the three mandatory security requirements, statement and deemed-compliance rules, and retention periods where the statement route applies.
UK PSTI OPSS Enforcement and Penalties | Risk Based Intervention and Escalation
Grounded OPSS enforcement guide for the UK PSTI regime covering risk-based and proportionate intervention, escalating enforcement, evidence expectations.
UK PSTI Password and Update Policy Requirements | Default Passwords, Disclosure, and Support Period
Grounded guide to UK PSTI password and update obligations covering unique or user-defined credentials, public vulnerability disclosure information.
UK PSTI Penalties and Fines | Financial and Operational Exposure
Practical guide to UK PSTI penalties and enforcement exposure covering why statement defects, support-period mismatches.
UK PSTI Relevant Connectable Products Scope | Internet Connectable, Network Connectable, and Exclusions
Detailed scope guide for UK PSTI relevant connectable products covering section 4 and 5 definitions, internet-connectable products.
UK PSTI Security Requirements in Practice | Engineering and Support Implementation
Operational guide for implementing UK PSTI security requirements in practice across engineering, firmware, support, vulnerability handling.
UK PSTI Statement of Compliance and Evidence | Statements, Summaries, and Retention
Grounded guide to UK PSTI statement-of-compliance obligations covering section 9, Schedule 2A alternatives, minimum information, and retention where the statement route applies.
UK PSTI Statement of Compliance Template | Drafting Pattern and Evidence Inputs
Practical UK PSTI statement of compliance template guide covering product identification, applicable requirements, defined support period, drafting controls.
UK PSTI Supply Chain Roles | Manufacturer, Importer, and Distributor Duties
Grounded guide to UK PSTI supply-chain roles covering manufacturer, importer, and distributor duties, statement handling, compliance-failure escalation.
UK PSTI vs EU Cyber Resilience Act | Product Scope, Duties, and Evidence Differences
Practical comparison of the UK PSTI regime and the EU Cyber Resilience Act covering product scope, baseline security duties, vulnerability handling.