FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
30of30items
Across 10 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
UK PSTI Default Password Rules

Which passwords does the PSTI rule cover?

The rule has applied since 29 April 2024 when a manufacturer makes a relevant connectable product available to UK consumers and no product exception applies. Typical examples can include connected cameras, speakers, toys, appliances, hubs, and wearables, but classification depends on the product's internet or network connectivity, intended consumer availability, supply facts, and Schedule 3 exceptions. Excepted products include specified medical, smart-meter, electric-vehicle charging, computer, and vehicle categories only when their exact conditions are met.

Schedule 1 applies the password rule to the product's hardware and pre-installed software when the product is not in the factory default state. It also covers software that is not pre-installed at supply but must be installed on the product for every manufacturer-intended purpose that uses the product's hardware, pre-installed software, or installable software. Cryptographic keys, API keys, and pairing PINs for protocols outside the Internet Protocol suite are excluded from this password definition. The manufacturer is the duty-holder for this security requirement.

A covered password must either be capable of being defined by the user or be unique per product. If it is unique per product, it must not use an incremental counter, public information, or a unique product identifier unless that identifier is protected with an encryption method or keyed hashing algorithm accepted as good industry practice. It must not otherwise be easily guessable.

  • Inventory setup, local administration, recovery, service, diagnostic, companion-app, cloud-service, and factory-reset states.
  • Record whether each authentication path uses a password. The rule does not require a product to use passwords when it uses another authentication mechanism.
  • Test the credential behavior of the released product and associated services, not only the intended design.
Citations
UK PSTI Default Password Rules

How can a manufacturer evidence the password decision?

Keep a credential inventory tied to the product model, firmware, software installed or required to be installed on the product, and factory-reset behavior. For user-defined passwords, preserve the setup flow and tests showing that the user defines the credential before the relevant access is enabled. For unique passwords, preserve the generation design, unpredictability rationale, provisioning controls, and tests showing that credentials do not repeat across sampled units.

If a password is derived from a serial number, MAC address, or another unique identifier, document the accepted encryption or keyed-hashing method. Encoding, truncation, reversal, or a secret-free formula does not establish the statutory exception.

Schedule 2 can provide deemed compliance for the password requirement when the exact standards or current-label conditions are met. For the original ETSI route, preserve the V2.1.1 assessment against provisions 5.1-1 and, where relevant, 5.1-2 plus the additional statutory conditions. From 4 December 2025, verify any claimed Japan JC-STAR STAR-1 or Singapore Cybersecurity Labelling Scheme route against the amended Schedule, the covered product, and the label's current status.

  • Link each test to the exact hardware or in-scope software authentication path.
  • Retain results for production units and reset or recovery states, where credentials can change.
  • Record any reliance on deemed compliance, including the exact Schedule 2 condition, named standard or current label, version, covered product, issue date, verification record, and expiry.
  • Reassess after a credential-generation change, new administration or recovery path, factory-reset change, supplier change, label expiry, product-scope change, or an app or cloud release that changes an in-scope product password path.
Citations
UK PSTI Default Password Rules

What mistakes should teams avoid?

Do not limit the review to a shared factory password. Predictable per-unit credentials can still fail, and the product's setup, recovery, service, and factory-reset states can expose different covered passwords. A test report for ETSI EN 303 645 also does not replace the separate product-scope, statement-of-compliance, supply-chain, investigation, notification, and record duties in the Act.

When a product has more than one manufacturer for PSTI purposes, including a business selling a white-label product under its own name or trade mark, each manufacturer must meet the applicable security requirement or a deemed-compliance condition. Importers and distributors must perform their own statement and supply checks and act when the statutory knowledge or belief test for a compliance failure is met.

Citations
UK PSTI ETSI Evidence and Deemed Compliance

Which ETSI provisions map to the PSTI requirements?

The 2023 Regulations name ETSI EN 303 645 V2.1.1, dated 19 June 2020. Schedule 2 maps the password requirement to provisions 5.1-1 and, where relevant, 5.1-2; vulnerability reporting to provision 5.2-1; and support-period information to provision 5.3-13, subject to the Schedule's additional conditions.

Only those mapped conditions create the original ETSI deemed compliance route. The rest of EN 303 645 can improve product security, but it is not automatically a binding PSTI requirement. A later ETSI edition does not replace V2.1.1 in the Regulations unless the law is amended.

From 4 December 2025, the amended Regulations also provide specified routes based on current Japan JC-STAR STAR-1 and Singapore Cybersecurity Labelling Scheme labels. They also add Schedule 2A conditions for deemed compliance with the manufacturer's statement-accompaniment duty. These are condition-specific alternatives, not recognition of every foreign certificate or a waiver of all PSTI duties.

  • Record the exact EN 303 645 edition, provision, Schedule 1 requirement, and product or software scope.
  • Treat ISO/IEC 29147:2018 as an alternative deemed-compliance route only for the specified vulnerability-disclosure paragraphs and additional Schedule 2 conditions.
  • For a recognised label route, retain the scheme and specification version, product and software scope, label identifier, issue and expiry dates, and current public verification record.
  • Check the current Regulations before reusing an assessment prepared against a different edition, product configuration, label status, or legal condition.
Citations
UK PSTI ETSI Evidence and Deemed Compliance

What can ETSI TS 103 701 evidence?

ETSI TS 103 701 V1.1.1 is a conformance-assessment specification for the EN 303 645 V2.1.1 baseline. It provides implementation conformance statement fields and conceptual and functional test cases. It can structure evidence for password generation, vulnerability-policy publication, and support-period publication.

A TS 103 701 report should identify the device under test, hardware, firmware, companion applications, associated services, interfaces, applicable provisions, implementation claims, test methods, samples, evidence, deviations, and verdicts. Its value depends on matching the assessed configuration to the product and services supplied in the United Kingdom.

Use a three-step mapping. First, identify the exact Schedule 1 duty and Schedule 2 condition. Second, link it to the named EN 303 645 V2.1.1 provision and any additional statutory condition. Third, link each implementation claim and TS 103 701 verdict to dated design and test evidence for the released product.

  • Preserve the device, firmware, app, cloud-service, and test-specification versions.
  • Map each verdict to the exact PSTI condition; do not submit an undifferentiated pass statement.
  • Explain exclusions, non-applicable provisions, samples, tooling, and changes since the assessment.
  • Assign an engineering owner for the implementation evidence, an assessor for the verdict, and a legal or compliance owner for the separate PSTI scope and deemed-compliance conclusion.
  • Reassess after a credential, interface, associated-service, vulnerability process, support-period, update-delivery, product-scope, standard-edition, or recognised-label change.
Citations
ETSI TS 103 701 V1.1.1

Provides the assessment specification, test objectives, implementation information, and verdict structure for EN 303 645.

UK PSTI ETSI Evidence and Deemed Compliance

What does an ETSI assessment not replace?

An ETSI assessment does not decide whether the product is a relevant connectable product, whether it is made available as a UK consumer connectable product, or which business is a manufacturer, importer, or distributor. It also does not replace statement accompaniment, retention, supply-chain checks, or the Act's investigation, remediation, notification, and record duties.

Where an exact Schedule 2A condition applies from 4 December 2025, it can replace the manufacturer's statement-accompaniment duty for that product and condition. It does not automatically remove importer or distributor checks, retention duties attached to a statement that is still required, compliance-failure duties, or other security requirements.

The current-label routes depend on the specified scheme, product, condition, and label status. A supplier declaration, expired label, different scheme level, or assessment of a related model should not be described as a general recognition of the supplied product.

Citations
UK PSTI Excepted Products and Boundaries

Which product categories are excepted?

A connectable product is outside the relevant-product definition only if it meets an exception in the current Schedule 3. The categories cover specified products supplied in Northern Ireland, qualifying electric-vehicle smart charge points, products to which the Medical Devices Regulations 2002 apply, qualifying smart-meter products, specified computers, and three Great Britain vehicle categories added on 25 February 2025. The PSTI regime itself took effect on 29 April 2024.

A category name is not enough. Each paragraph has its own conditions, territorial limits, referenced legislation, and carve-outs. Record the exact paragraph and the product facts that meet every element.

  • Use the current Schedule 3 together with the 2025 vehicle amendment.
  • Check where the product is supplied; the vehicle exceptions apply in Great Britain, while the Northern Ireland paragraph has its own legal test.
  • Reassess separate products in a bundle instead of extending one component's exception to the whole package.
Citations
PSTI Amendment Regulations 2025

Adds specified motor, two- or three-wheel and quadricycle, and agricultural and forestry vehicle categories in Great Britain from 25 February 2025.

UK PSTI Excepted Products and Boundaries

Where do the main boundary cases arise?

The medical-device exception applies to products to which the Medical Devices Regulations 2002 apply, but Schedule 3 says a relevant connectable product is not excepted merely because software to which those Regulations apply is installed or operable on it. Classify the hardware product and the software separately.

The computer exception covers desktop and laptop computers and non-cellular tablets, but not products in those categories that the manufacturer's intended purpose designs exclusively for children under 14. For tablets, cellular capability changes the result. The smart-meter and charge-point exceptions also depend on the specific statutory conditions, not a marketing description.

The vehicle amendment applies in Great Britain to motor vehicles and trailers, and systems, components, and separate technical units intended for them, where Regulation (EU) 2018/858 applies; two- or three-wheel vehicles and quadricycles where Regulation (EU) 168/2013 applies; and agricultural and forestry vehicles where Regulation (EU) 167/2013 applies. Test an accessory against the cited sector instrument instead of assuming that everything sold for a vehicle is excepted.

  • Keep the intended-purpose evidence used for computer and children's-product decisions.
  • For medical products, identify which product the Medical Devices Regulations apply to and do not transfer the software's status to unrelated hardware.
  • For vehicles, map the product to the scope of the exact sector regulation; an accessory associated with a vehicle is not automatically excepted.
Citations
UK PSTI Excepted Products and Boundaries

What evidence should support an exception decision?

Keep the product model and configuration, connectivity analysis, market and supply route, intended purpose, category-specific evidence, cited legislation, owner, reviewer, decision date, and change triggers. If the exception depends on an assurance scheme, licence holder, sector regulation, or product label, preserve the record proving that condition.

Do not discard the scope record after deciding that a product is excepted. A firmware, connectivity, intended-purpose, product-composition, market, or legislative change can alter the result.

Citations
UK PSTI Importer and Distributor Duties

What importer and distributor duties apply under UK PSTI Product Security?

The regime took effect on 29 April 2024. The 2023 Regulations direct the password, vulnerability-disclosure and support-period security requirements at manufacturers. Importers and distributors nevertheless have their own duties under the Act: check statement accompaniment, stop supply in specified circumstances, remedy their own compliance failures, contact other actors, and notify OPSS or customers when the statutory conditions are met. Importers must also investigate possible importer or manufacturer compliance failures when section 17 applies and keep the investigation records required by section 20.

First identify the role by what the business actually does. An importer brings a product from outside the United Kingdom into the United Kingdom and is not its manufacturer. A distributor makes a product available in the United Kingdom but is neither its manufacturer nor importer. A business that applies its own name or trade mark can be a manufacturer instead, even if another company made the hardware.

  • Importer: before supply, check that the ordinary statement accompanies the product or that the Schedule 2A label conditions are met; retain an ordinary statement for the longer of 10 years from issue or its stated support period.
  • Distributor: before supply, perform the same accompaniment or Schedule 2A check, but the Regulations do not impose the statement-retention rule on distributors.
  • Both roles: do not supply when they know or believe there is a relevant manufacturer compliance failure. An importer must investigate when section 17's information and UK-consumer-product conditions are met; the Act does not impose that investigation duty on a distributor.
Citations
UK PSTI Importer and Distributor Duties

What happens when a possible failure is found?

An importer must investigate a possible importer or manufacturer compliance failure when section 17's trigger is met and take all reasonable steps to resolve the investigation. A distributor has no equivalent statutory investigation duty, but sections 24 and 25 require action once it becomes aware, or ought to be aware, of a distributor or manufacturer compliance failure. The next action depends on the actor whose duty failed, whether the product has already been supplied, whether the failure is remediable, and the applicable notification conditions.

For a manufacturer compliance failure, the importer or distributor must contact the manufacturer as soon as possible unless the statutory prior-notification exception applies. If it appears unlikely that the manufacturer will remedy the failure, the supply-chain actor must take all reasonable steps, as soon as practicable, to prevent products not yet supplied to customers from being made available to them.

Notification is not one generic mailing list. An importer can have to notify OPSS, affected distributors, and customers where specified conditions are met. A distributor can have to notify OPSS, the relevant importer or other distributors, and customers where specified conditions are met. Sections 19 and 25 remove duplicate contact or notification steps in defined cases where another relevant person has already supplied the information.

  • Quarantine affected stock while the statutory stop-supply question is resolved.
  • Record the trigger information, affected models and batches, investigation steps, findings, contacts, remediation, supply decision and notifications.
  • Preserve investigation records for 10 years from the day each record is made. This duty applies to importers. Distributors should preserve evidence of the facts, contacts, remediation, stop-supply decision, and notifications even though the Act does not impose section 20's investigation-record duty on that role.
Citations
UK PSTI Importer and Distributor Duties

What evidence supports the supply decision?

The evidence file should connect the product to the correct actor and decision at each supply stage. Keep the scope analysis, role determination, manufacturer identity, ordinary statement or current Schedule 2A label evidence, statement-retention deadline where applicable, technical assurance received, batch and shipment records, and any investigation file.

Manufacturer test evidence can inform an importer or distributor's decision, but it does not transfer the statutory duty. Conversely, importers and distributors are not required by the current Regulations to recreate the manufacturer's technical testing. They need enough reliable information to perform their own checks and respond when they know, believe or receive information suggesting a failure.

  • Map the legal entity, purchase route and branding before assigning the importer or distributor role.
  • Check label validity and product identity when relying on Schedule 2A; a foreign scheme name alone is not enough.
  • Keep dated evidence for stop-supply and restart decisions, including who authorised release and what failure was remedied.
Citations
UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties

What can an OPSS notice require?

Treat a notice served by OPSS as a formal enforcement document. OPSS enforces the PSTI product-security regime under an arrangement with the Department for Science, Innovation and Technology, while the Act states the powers in terms of the Secretary of State. Read the notice itself for the product, legal entity, alleged failure, required action, evidence, deadline and review or appeal route.

A compliance notice can require the recipient to comply with a duty, take specified steps and provide evidence. A stop notice can prohibit a specified activity, including making a product available, and may require customer risk communications. A recall notice can require steps to organise the return of products already supplied. Recall is a stronger measure: section 30 limits it to a failure to comply with a security requirement and requires the statutory conditions concerning inadequate action and insufficient alternative powers to be met.

  • Identify whether the document is a compliance notice, stop notice, recall notice, penalty notice, information request or another enforcement step.
  • Do not assume voluntary correction cancels a notice; obtain written confirmation of any variation or withdrawal.
  • Separate pre-notice representations from a formal appeal. Compliance, stop, and recall notices ordinarily follow notice of the proposed action and a 10-day representation period; the urgent-need exception applies to stop and recall notices, not compliance notices. An appeal against an enforcement notice must normally be brought to the First-tier Tribunal within 28 days; under section 33, the notice or appealed variation has no effect until that appeal is determined or withdrawn.
Citations
UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties

What should the recipient do first?

Preserve the notice and its delivery details, then create a response record without changing or deleting the underlying product evidence. Confirm the named legal entity and supply-chain role, the affected models, batches and software versions, where stock is held, which customers received it, and whether supply must stop immediately.

Assign one response owner and involve legal counsel where necessary to protect deadlines and procedural rights. The factual work should run in parallel: secure relevant logs and documents, reproduce the alleged failure, trace units through the supply chain, assess remediation and customer risk, and document every communication with OPSS. Answer information requests accurately and within their stated scope.

  • Keep the notice, envelope or electronic receipt, service date, deadlines, correspondence and decision log.
  • Preserve product-scope records, statements of compliance, security tests, vulnerability reports, support commitments, sales and shipment data, customer contacts and corrective-action evidence.
  • Track each required action to an owner, completion date and proof submitted; retain the exact version sent to OPSS.
Citations
UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties

How do penalties and challenges fit?

A penalty notice is separate from a compliance, stop or recall notice. If the Secretary of State is satisfied on the balance of probabilities that a person failed to comply with a relevant duty, section 36 permits a financial penalty. The maximum fixed penalty is the greater of GBP 10 million and 4% of the person's qualifying worldwide revenue. A further daily penalty can be imposed for continuing failure, up to GBP 20,000 per day. These are statutory ceilings, not automatic penalties.

The Act provides review and appeal mechanisms for specified notices and penalties. The available route, deadline, tribunal and effect on the notice depend on the provision used and the notice served. Use the notice and current Act text rather than a generic timetable. Continue to control product risk and preserve evidence while any challenge is considered.

  • Do not describe the maximum penalty as the likely outcome or as applying automatically to every breach.
  • Do not miss a deadline while debating product scope; record the dispute and protect the procedural route stated in the notice.
  • Do not restart supply solely because a technical fix exists; confirm that every notice condition and required verification step has been satisfied.
Citations
Page 1 of 2
Previous12Next