What should teams do about ETSI Evidence under UK PSTI Product Security?
Teams should treat ETSI Evidence under UK PSTI Act as a source-linked operating decision: confirm whether the product is a relevant connectable product and which manufacturer, importer, distributor, statement-of-compliance, vulnerability-disclosure, password, support-period, or OPSS enforcement duty is triggered, assign the team that can change the process, and keep evidence showing the action and review trigger.
The safest first step is to classify the product and supply-chain role before deciding whether the duty belongs to the manufacturer, importer, distributor, or all of them.
- Write the ETSI Evidence decision in one sentence before drafting controls.
- Attach the external source URL and a short source quote to the evidence record.
- Route unclear cases to legal, privacy, security, or compliance review before launch.
OPSS enforcement guidance supports the PSTI evidence point by tying enforcement action to duties under the Product Security and Telecommunications Infrastructure Act 2022.
Direct support for the FAQ answer on ETSI Evidence.
Direct support for the FAQ answer on ETSI Evidence.