How should teams handle Default Passwords under UK PSTI Product Security?
Teams should treat Default Passwords under the UK PSTI Act as a source-linked operating decision: confirm whether the product is a relevant connectable product and which manufacturer, importer, distributor, statement-of-compliance, vulnerability-disclosure, password, support-period, or OPSS enforcement route is relevant, assign the team that can change the process, and keep evidence showing the action and review trigger.
The safest first step is to classify the product and supply-chain role before deciding whether the duty belongs to the manufacturer, importer, distributor, or all of them.
- Write the Default Passwords decision in one sentence before drafting controls.
- Attach the external source URL and a short source quote to the evidence record.
- Route unclear cases to legal, privacy, security, or compliance review before launch.
Official UK product-security regime guidance cited for the PSTI default-password requirement and duty-holder evidence expectations.
Direct support for the FAQ answer on Default Passwords.
Direct support for the FAQ answer on Default Passwords.