What should teams do about Support Periods under UK PSTI Product Security?
Teams should treat Support Periods under the UK PSTI Act as a source-linked operating decision: confirm whether the product is a relevant connectable product, identify the manufacturer, importer or distributor duties that apply, and publish the minimum security update period information required by the regime, including the minimum length of time updates will be provided and an end date.
The safest first step is to classify the product and supply-chain role before deciding whether the duty belongs to the manufacturer, importer, distributor, or all of them.
- Write the Support Periods decision in one sentence before drafting controls.
- Attach the external source URL and a short source quote to the evidence record.
- Route unclear cases to legal, privacy, security, or compliance review before launch.
GOV.UK overview confirming the PSTI regime includes publishing minimum security update period information.
GOV.UK guidance supporting support-period evidence, statement-of-compliance checks, and supply-chain role review.
UK impact assessment background for the consumer-connectable-product security regime and update-transparency policy.