FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
30of30items
Across 10 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
UK PSTI Relevant Connectable Product Scope

How do you apply the product test?

Start with the physical product. It is a relevant connectable product only if it is internet-connectable or network-connectable under section 5 and is not an excepted product under section 6 and Schedule 3 of the Regulations.

An internet-connectable product can send and receive data over the internet using a protocol in the Internet Protocol suite. A network-connectable product can send and receive data by electrical or electromagnetic transmission, is not itself internet-connectable, and meets one of section 5's two direct-connectability conditions. Those conditions cover an IP-suite connection to an internet-connectable product or specified non-IP connections involving an internet-connectable product and, in one branch, two or more simultaneous product connections. A wired connection can still be direct for this test.

Section 5 also treats some wireless computer-input products as meeting the second condition when they are designed to work with a linking product that connects by a non-IP protocol to an internet-connectable product. A wire or cable used only to connect products is disregarded when counting the two simultaneous product connections, but a wire does not stop a connection from being direct.

  • Document every radio, wired interface, protocol, gateway, hub, and direct product-to-product connection.
  • Apply the definitions to the shipped product, not only the feature that marketing calls 'smart'.
  • Then test whether it is an excepted product under the current Schedule 3, including the territorial and product-specific conditions.
Citations
UK PSTI Relevant Connectable Product Scope

When do the UK consumer supply duties engage?

Relevant product status is only the first step. The manufacturer, importer, and distributor duties use the separate UK consumer connectable product concept in section 54 and actor-specific intention, awareness, or 'ought to be aware' conditions in Chapter 2.

A UK consumer connectable product can qualify when it is first made available to consumers in the United Kingdom. It can also qualify when first made available to non-consumers if products identical to it are or have been made available to UK consumers. Record the actual UK route, intended users, sales material, customer restrictions, and whether identical consumer products exist.

Do not decide the first-supply question from an invoice alone. Section 54 has specific rules for unwanted-product returns, returns made under the PSTI regime, products reconditioned by or for a manufacturer, and certain intermediary supplies. Section 55 also treats gifts, prizes, installation into a building, and some hire or lending arrangements as supply, while excluding transport-only services and scrap sales.

  • Do not treat a business-to-business sale as automatically outside scope.
  • Assess bundles and product families component by component, then record how the complete offering is supplied.
  • Identify each manufacturer, importer, distributor, and authorised representative separately; branding can make a reseller a manufacturer.
Citations
UK PSTI Relevant Connectable Product Scope

What should a defensible scope record show?

Keep the product model and configuration, connectivity diagram, intended purpose, instructions and promotional material, consumer-availability evidence, identical-product analysis, Schedule 3 review, UK supply chain, branding, and dated conclusion. State which facts would change the answer.

Reassess after changes to radios, gateways, associated products, branding, intended users, UK distribution, or the exception list. A prior decision for a related model is evidence, not a substitute for the current product test.

Citations
UK PSTI Security Update Support Periods

How long must a PSTI support period be?

The 2023 Regulations took effect on 29 April 2024 and do not set one minimum number of years for every product. For the hardware and software categories listed in Schedule 1 paragraph 3 that can receive security updates, the manufacturer determines a product-specific defined support period and must publish the minimum length of time for which security updates will be provided, together with an end date.

The period concerns security updates, not the warranty, ordinary customer support, spare-parts availability, or the product's expected lifetime. Those periods may differ. The published end date is the minimum commitment that the customer can identify for the relevant product.

  • Identify every product model and associated software or service covered by the security-update requirement.
  • Set the period using the product's risks, dependencies, service model, component support, and planned market life; PSTI does not prescribe the calculation method.
  • Approve a calendar end date and the supporting period calculation before the product is made available.
Citations
UK PSTI Security Update Support Periods

What should the support-period record contain?

Keep the product and software identifiers, the approved start and end dates, the calculation rationale, assumptions about third-party components and services, the owner, and the public notice. Preserve dated captures of what customers could see at launch and after each change. A security update includes software that protects or enhances security, including fixes for issues discovered by or reported to the manufacturer.

The statement of compliance must include the defined support period. When a statement is required, the manufacturer and importer must retain it for the longer of 10 years from issue or that defined support period. A manufacturer must not shorten the period after publication. If it extends the minimum and creates a new defined support period, it must publish the new period as soon as practicable.

  • Align the public end date, statement of compliance, product documentation, support site, and internal release records.
  • Record which security updates are within the commitment and how product variants or regional versions map to it.
  • Escalate any proposed shortening or ambiguous change before publication; do not silently replace the historical commitment.
Citations
UK PSTI Security Update Support Periods

How do standards and deemed compliance affect the decision?

The original standards-based deemed-compliance route refers to ETSI EN 303 645 V2.1.1 provision 5.3-13, subject to additional Schedule 1 and Schedule 2 conditions. ETSI TS 103 701 can help structure an assessment, but it is an assessment specification, not a separate PSTI safe harbour.

From 4 December 2025, valid labels under Japan JC-STAR STAR-1 or any level of the specified Singapore Cybersecurity Labelling Scheme can also satisfy listed deemed-compliance conditions. Record the label, scheme version, covered product, and expiry; the route does not remove unrelated duties under the Act.

Citations
UK PSTI Security Update Transparency

What must the manufacturer publish?

Since the regime took effect on 29 April 2024, the manufacturer must publish the minimum length of time for which security updates will be provided for the product and an end date. The information must be available without prior request, in English, free of charge, in an accessible, clear, and transparent form, and in language understandable without prior technical knowledge.

The published information must cover the update-capable product hardware and software categories described by Schedule 1 paragraph 3, including specified associated software used for the product's operation, user operation, or services. Use product names and model identifiers that let a customer match the notice to the item they own. If the manufacturer extends the minimum and creates a new defined support period, it must publish the new period as soon as practicable; it must not shorten the period after publication.

  • State a calendar end date, not only a duration such as 'three years'.
  • Explain what a security update means for the product without hiding the answer in technical release notes.
  • Make the information reachable without an account, support request, payment, or personal-data submission.
  • On a qualifying invitation to purchase on the manufacturer's own website or a free website under its control, publish the period alongside or with equal prominence to the product's main characteristics.
Citations
UK PSTI Security Update Transparency

How should teams control the published information?

Assign the notice to a product owner who can reconcile engineering support plans, third-party component commitments, and customer-facing copy. Keep the approval, product and software mapping, first-publication date, later versions, page captures, and change rationale.

PSTI sets no universal minimum number of years. The manufacturer chooses the period, but the published end date and the defined support period in the statement of compliance should agree. Review any proposed change against the current Regulations and preserve the earlier public record.

  • Check the notice during launch approval and after model, firmware, service, supplier, or end-of-life changes.
  • Keep redirects working if the notice moves, and retain a stable way to identify the supported model.
  • Separate security-update commitments from warranty, feature updates, general customer support, and product lifetime.
Citations
UK PSTI Security Update Transparency

What does publication not prove?

A visible end date does not by itself prove that the product is in scope, that the chosen date is operationally supportable, or that the manufacturer meets the password and vulnerability-reporting requirements. It also does not replace the statement-of-compliance, supply-chain, investigation, notification, remediation, or record duties.

If a manufacturer relies on a standards or labelling deemed-compliance route, keep evidence of the exact condition, covered product, version or label, and validity period. Do not describe a general ETSI assessment or expired scheme label as automatic PSTI compliance.

Citations
UK PSTI Statement of Compliance: Contents, Delivery, and Records

What must the statement contain?

The regime took effect on 29 April 2024. Under section 9 of the PSTI Act, a manufacturer must not make a relevant connectable product available in the United Kingdom unless a statement of compliance accompanies it. Regulation 7 and Schedule 4 prescribe the minimum contents. The statement is prepared by or on behalf of the manufacturer; it is not an OPSS certificate or approval.

The statement must identify the product by type and batch; name and address every manufacturer and any authorised representative; say that it was prepared by or on behalf of the manufacturer; declare that, in the manufacturer's opinion, the manufacturer complied with the applicable Schedule 1 security requirements or met the corresponding Schedule 2 deemed-compliance conditions; give the defined support period that was correct when the product was first supplied; and include the signatory's signature, name and function plus the place and date of issue. Where a product has multiple manufacturers, section 9 permits one joint statement prepared by or on behalf of all of them, but it must cover each manufacturer's declaration.

  • Tie the statement to the shipped product type, model, batch or other identifier used in production and distribution records.
  • Name each legal entity that meets the Act's manufacturer definition, including a business that markets the product under its own name or trade mark.
  • Check that the support-period entry agrees with the public support-period information and the product release record.
Citations
UK PSTI Statement of Compliance: Contents, Delivery, and Records

How can the statement accompany the product?

The Act calls the statement a document but does not define 'document' or 'accompany'. GOV.UK guidance therefore says it could be digital, while leaving each business to determine how its method meets the legal requirement for its products. A web link, QR code, package insert or electronic document is not automatically sufficient: the manufacturer, importer and distributor must be able to show that the statement accompanied the product at the relevant supply stage.

Since 4 December 2025, Schedule 2A provides a narrow alternative. The accompaniment requirement is treated as met where the product is currently assigned an unexpired Japan JC-STAR STAR-1 conformance label or is currently awarded an unexpired label under any level of Singapore's Cybersecurity Labelling Scheme. This route concerns accompaniment of the statement; it does not remove other PSTI duties.

  • For the ordinary route, retain the issued statement and evidence of how recipients could obtain it with the product.
  • For Schedule 2A, record the scheme, label identifier or level, product mapping, validity period, and the checks performed before supply.
  • Do not treat any other certification, test report, standard, or security label as a substitute for the statement-accompaniment duty.
Citations
UK PSTI Statement of Compliance: Contents, Delivery, and Records

Who checks and retains the evidence?

Manufacturers are responsible for preparing and accompanying the ordinary statement. Importers and distributors have separate pre-supply duties to check accompaniment, or to be satisfied that the Schedule 2A conditions are met when using that route. A supplier contract or general assurance does not replace those statutory checks.

Where the ordinary statement is required, the manufacturer and importer must each retain a copy for the longer of 10 years from its issue date or the defined support period stated in it. Keep the underlying product-scope decision, security evidence, signed approval, version history and distribution evidence with that copy so the statement can be connected to the product actually supplied.

  • Do not omit a manufacturer, authorised representative, batch identifier, declaration route, support period, signature, place or date.
  • Do not use a later support-period publication to disguise what was stated when the product was first supplied; preserve dated versions and any lawful extension.
  • Recheck the statement after a change to branding, manufacturer identity, product batch, connectivity, security controls or support commitment.
Citations
UK PSTI Vulnerability Disclosure Requirements

What must the vulnerability-reporting information contain?

Since the regime took effect on 29 April 2024, the manufacturer must publish information explaining how a person can report security issues. It must also publish the timescales within which the reporter can expect acknowledgement of receipt and status updates until the reported issue is resolved.

The information must be available without prior request, in English, free of charge, and without requiring the reporter to provide personal information before accessing it. It must be accessible, clear, and transparent. PSTI does not set one universal acknowledgement, remediation, or resolution deadline; the manufacturer publishes its own expected timescales.

  • Provide a monitored reporting route and state the acknowledgement and status-update times separately.
  • Describe the products or services covered and give reporters enough information to submit a useful report.
  • Keep access to the policy public even if the later submission process asks for contact details needed to manage a case.
Citations
UK PSTI Vulnerability Disclosure Requirements

How should the reporting process work behind the public page?

Assign the intake to a monitored team, route reports to the correct product owner, acknowledge them within the published time, and send status updates on the published cadence. Link each case to the affected model, firmware, associated service, and support-period record.

A vulnerability report can also trigger the Act's separate duties. If a manufacturer is informed of a possible compliance failure after the product has been made available, it must take all reasonable steps to investigate. If the manufacturer becomes aware, or ought to be aware, of a compliance failure for a UK consumer connectable product, section 11 requires all reasonable steps to prevent further customer supply, remedy the failure as soon as practicable, and make the specified notifications. Section 12 requires a 10-year record of the investigation and any failure.

  • Keep the public-policy version, mailbox or portal monitoring evidence, acknowledgements, status updates, triage, and closure decision.
  • Distinguish a security vulnerability from a PSTI compliance failure; one can exist without the other.
  • Escalate confirmed or suspected statutory failures to the product-security and legal owners who control notification and supply decisions.
Citations
UK PSTI Vulnerability Disclosure Requirements

How do standards and deemed compliance fit?

Schedule 2 allows standards-based deemed compliance through ETSI EN 303 645 V2.1.1 provision 5.2-1 or specified parts of ISO/IEC 29147:2018, subject to the Schedule's additional publication conditions. A general vulnerability-management certificate or policy does not establish that those exact conditions are met.

The 2025 amendment also added current-label routes under Japan JC-STAR STAR-1 and the specified Singapore Cybersecurity Labelling Scheme. Evidence should identify the exact route, covered product, label or standard version, and validity period. Deemed compliance with this security requirement does not remove other duties under the Act.

Citations
Page 2 of 2