Which passwords does the PSTI rule cover?
The rule has applied since 29 April 2024 when a manufacturer makes a relevant connectable product available to UK consumers and no product exception applies. Typical examples can include connected cameras, speakers, toys, appliances, hubs, and wearables, but classification depends on the product's internet or network connectivity, intended consumer availability, supply facts, and Schedule 3 exceptions. Excepted products include specified medical, smart-meter, electric-vehicle charging, computer, and vehicle categories only when their exact conditions are met.
Schedule 1 applies the password rule to the product's hardware and pre-installed software when the product is not in the factory default state. It also covers software that is not pre-installed at supply but must be installed on the product for every manufacturer-intended purpose that uses the product's hardware, pre-installed software, or installable software. Cryptographic keys, API keys, and pairing PINs for protocols outside the Internet Protocol suite are excluded from this password definition. The manufacturer is the duty-holder for this security requirement.
A covered password must either be capable of being defined by the user or be unique per product. If it is unique per product, it must not use an incremental counter, public information, or a unique product identifier unless that identifier is protected with an encryption method or keyed hashing algorithm accepted as good industry practice. It must not otherwise be easily guessable.
- Inventory setup, local administration, recovery, service, diagnostic, companion-app, cloud-service, and factory-reset states.
- Record whether each authentication path uses a password. The rule does not require a product to use passwords when it uses another authentication mechanism.
- Test the credential behavior of the released product and associated services, not only the intended design.
Sets the password scope, the user-defined-or-unique rule, and the restrictions on unique-per-product passwords.
Places the applicable security-requirement duty on manufacturers when the UK consumer-product conditions are met.
Lists the product exceptions whose exact conditions must be checked before applying the password requirement.