Artifact GuideUKFAQ

UK PSTI Product Security FAQ

Get direct, sourced answers on product scope, exceptions, roles, passwords, vulnerability reporting, update-period information, statements, records, and OPSS enforcement.

The guide separates binding duties from OPSS guidance, ETSI good practice, internal controls, and the limited deemed-compliance routes introduced in 2025.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
FAQ modules
10

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The UK PSTI product-security regime has applied since 29 April 2024. A can trigger role-specific duties for manufacturers, importers, and distributors, while the three Schedule 1 security requirements apply to manufacturers. Product scope, UK consumer status, actor knowledge, and the specific duty must each be tested.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items30
Focused FAQ modules
10
Showing 10 of 10
FAQ module

UK PSTI Default Password Rules

PSTI requires each covered password to be user-defined or unique per product. Unique credentials must not use prohibited predictable generation methods.

3 items
FAQ module

UK PSTI ETSI Evidence and Deemed Compliance

ETSI EN 303 645 and TS 103 701 can structure technical evidence, but the standards-based PSTI route depends on the exact mapped provisions and additional Schedule 2 conditions.

3 items
FAQ module

UK PSTI Excepted Products and Boundaries

An internet- or network-connectable product is outside the relevant-product definition only when a current Schedule 3 exception applies; record the exact category and facts rather than relying on a broad sector label.

3 items
FAQ module

UK PSTI Importer and Distributor Duties

Importers and distributors have their own statement, stop-supply, remediation, and notification duties; importers also have statutory investigation and 10-year investigation-record duties.

3 items
FAQ module

UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties

OPSS can use compliance, stop, and recall notices alongside monetary and other measures; notice recipients should preserve the notice, product scope, supply records, corrective actions, representations, and appeal dates.

3 items
FAQ module

UK PSTI Relevant Connectable Product Scope

A product is relevant when it is internet-connectable or network-connectable and not excepted, then the UK consumer-use and supply facts determine whether the Part 1 duties engage.

3 items
FAQ module

UK PSTI Security Update Support Periods

PSTI does not prescribe a universal minimum number of support years. The manufacturer sets and publishes a product-specific minimum period and end date; preserve the published commitment and assess any later change against the current Regulations.

3 items
FAQ module

UK PSTI Security Update Transparency

Publish the minimum security-update period and end date in English, free of charge, without prior request, and in language understandable without technical knowledge.

3 items
FAQ module

UK PSTI Statement of Compliance: Contents, Delivery, and Records

A statement must contain the prescribed information and accompany the product unless a current deemed-compliance route applies; a digital method is possible, but each business must ensure that it meets the Act.

3 items
FAQ module

UK PSTI Vulnerability Disclosure Requirements

Publish a clear reporting route plus expected acknowledgement and status-update times. PSTI requires the information and timescales to be available; it does not prescribe one universal response deadline for every report.

3 items
Question 1

Which products and businesses are covered?

Start with the Act's product tests. The product must be internet-connectable or network-connectable and not excepted. The Chapter 2 duties then use the separate definition: the product is or has been made available to UK consumers, or an identical product is or has been made available to them.

Current exceptions include specified medical-device products, smart-meter products, electric-vehicle smart charge points, desktop and laptop computers, tablet computers without cellular connectivity, and specified vehicle categories. The exact boundaries matter. For example, a tablet with cellular connectivity does not fit the conventional-computer exception, and hardware is not excepted merely because qualifying medical-device software is installed or operable on it.

  • Document connectivity protocols, direct connections, intended purpose, UK sales channels and foreseeable consumer use.
  • Apply each Schedule 3 exception to the specific product and current legislation; do not treat a sector label as a blanket exemption.
  • Identify every manufacturer, importer and distributor from the facts. Rebranding a product under a business's own name or trade mark can make that business a manufacturer.
Question 2

What are the main duties?

For in-scope products, the 2023 Regulations require manufacturers to control covered product passwords, publish a vulnerability-reporting route, and publish the minimum period for security updates. The password rule covers specified hardware and software states and excludes cryptographic keys, API keys, and certain pairing PINs. Covered passwords must be unique per product or defined by the user; the counter, public-information, product-identifier, and guessability restrictions apply to the unique-per-product branch.

Manufacturers must also ensure that a statement of compliance accompanies the product unless the narrow Schedule 2A label route applies. Importers and distributors perform their own pre-supply statement or label checks. Manufacturers and importers have investigation and record duties; all three roles have separate duties to act on compliance failures when the applicable statutory conditions are met.

  • Publish a vulnerability-reporting contact, acknowledgement timing and status-update timing without requiring reporters to submit personal data before they can access that information.
  • Publish the defined support period clearly and free of charge; there is no universal statutory minimum number of years.
  • Keep technical evidence and the signed statement tied to the shipped model, batch, software version and published customer information.
Question 3

What changed after the regime started?

The regime took effect on 29 April 2024. On 25 February 2025, specified categories of motor vehicles, two- or three-wheel vehicles and quadricycles, and agricultural or forestry vehicles became excepted through references to three retained EU type-approval regulations.

On 4 December 2025, a second amendment added two label-based routes. A manufacturer is treated as meeting the three technical requirements, and the statement-accompaniment requirement, only while the product bears a current, unexpired Japan JC-STAR STAR-1 conformance label or a current, unexpired label under any level of Singapore's Cybersecurity Labelling Scheme. The exact Schedule 2 and 2A conditions still need to be checked; other labels and standards do not create the same legal result.

  • Use consolidated legislation for current decisions and record the amendment relied on.
  • Check label validity, scheme level, model identity and expiry at the time of supply.
  • Do not confuse ETSI EN 303 645 evidence with automatic compliance: only the provisions and extra conditions named in Schedule 2 receive deemed effect.
Question 4

What records and enforcement preparation are needed?

Maintain one product file that connects scope and role decisions to password evidence, the public vulnerability route, the published support period, the statement or Schedule 2A label evidence, product versions and supply records. Manufacturers and importers must retain an ordinary statement for the longer of 10 years from issue or the defined support period stated in it. The Act separately requires 10-year records for specified compliance investigations.

OPSS enforces the regime on behalf of DSIT. The Act provides compliance, stop and recall notices, information powers and financial penalties. The maximum fixed penalty is the greater of GBP 10 million and 4% of qualifying worldwide revenue, with a possible continuing daily penalty up to GBP 20,000. These are statutory maxima, not automatic outcomes.

  • Assign owners for scope, technical controls, public security information, statements, supply-chain checks and regulator response.
  • Preserve dated screenshots or exports of public disclosures and the exact firmware or software release evidence they describe.
  • Create a stop-supply and notice-response path that can identify affected stock, customers, batches and corrective actions.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Sets technical requirements, exceptions, statement details, retention and deemed-compliance conditions.
Related guides

Explore more topics

UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a UK PSTI statement is required, the Schedule 4 fields, supply-chain checks, retention, digital accompaniment, and the December 2025 label route.
UK PSTI Act: vulnerability disclosure policy requirements and template
Publish a free, clear, accessible English reporting route plus expected acknowledgement and status-update times, and retain evidence that the information remained available.
UK PSTI applicability test: product, market, and actor scope
Apply the UK PSTI tests in order: connectivity, current exceptions, UK consumer availability, supply facts, and the manufacturer, importer, or distributor trigger.
UK PSTI compliance checklist for product release
Use a release checklist with scope, role, security-control, statement, records, and compliance-failure evidence for UK consumer connectable products.
UK PSTI compliance: duties, evidence, and response
Build a UK PSTI compliance process covering product scope, supply-chain roles, the three security requirements, statements, records, and post-market failures.
UK PSTI default password requirements
Apply the UK PSTI password rule to each relevant password, test unique-per-product generation, and keep reset and release evidence for the shipped model.
UK PSTI Manufacturer, Importer and Distributor Roles
Distinguish manufacturer, importer, distributor, and authorised-representative duties per product and supply route, including rebranding, imports, statement checks, stop-supply decisions, and compliance failures.
UK PSTI password and security update policy requirements
Implement the UK PSTI password rule and publish a defined security support period with the required end date, access conditions, and change controls.
UK PSTI Product Security Deadlines and Compliance Calendar Guide
Track the UK PSTI regime's commencement and amendment dates, product-specific support periods, record retention, and OPSS response and appeal windows.
UK PSTI Product Security Importer and Distributor Duties Guide
Identify the pre-supply checks, statement or deemed-compliance evidence, stop-supply decisions, notification and remediation duties required of UK importers and distributors, plus importer-specific investigation and record duties.
UK PSTI Product Security Minimum Support Period and Update Transparency Guide
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in clear language, without implying that PSTI sets one duration for every product.
UK PSTI Product Security OPSS Enforcement and Penalties Guide
Understand OPSS investigations, compliance, stop and recall notices, monetary penalties, forfeiture, court orders, representations, appeals, and evidence needed to respond.
UK PSTI Product Security OPSS Notices Guide
Prepare for compliance, stop, and recall notices by understanding their effects, representation and appeal routes, product records, and corrective-action evidence.
UK PSTI Product Security Penalties and Fines Guide
Understand the maximum fixed and daily PSTI penalties, how OPSS sets an amount, representation and appeal rights, and separate court-ordered sanctions.
UK PSTI product security requirements
Read the three Schedule 1 security requirements and the surrounding manufacturer, importer, distributor, statement, record, and failure-response duties.
UK PSTI relevant connectable product scope test
Decide whether one product meets the UK PSTI connectivity definition, falls within a current exception, and reaches the separate UK-consumer duty tests.
UK PSTI relevant connectable products: categories and exceptions
Understand which connected product categories can enter UK PSTI scope, how the statutory tests work, and why examples never replace the current exception schedule.
UK PSTI Scope Classifier Workflow
Decide whether a product falls within the UK PSTI product-security regime by checking connectivity, consumer supply, exceptions, actor roles, and product-specific evidence.
UK PSTI security requirements in practice
Implement the three UK PSTI security requirements through product specifications, release tests, public information, approvals, and post-release evidence.
UK PSTI Statement of Compliance Evidence Pack
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
UK PSTI Statement of Compliance Template
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
UK PSTI Statement of Compliance Workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
UK PSTI Support Period Evidence Workflow
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
UK PSTI to ETSI Evidence Mapping
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
UK PSTI vs Australia Smart Device Rules
Compare UK PSTI with Australia's Cyber Security Act smart-device rules by scope, duties, statements, security controls, retention, dates, and enforcement.
UK PSTI vs ETSI EN 303 645
See how binding UK PSTI duties relate to ETSI EN 303 645, which edition the UK Regulations name, what the standard adds, and what evidence to retain.
UK PSTI vs EU Cyber Resilience Act
Decide whether UK PSTI, the EU Cyber Resilience Act, or both apply, then compare actors, exclusions, security work, documents, reporting, and dates.
UK PSTI vs EU Cyber Resilience Act (CRA)
Compare UK PSTI and the EU Cyber Resilience Act by scope, security duties, support periods, conformity assessment, reporting, evidence, and application dates.
UK PSTI Vulnerability Disclosure Workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.