What must the vulnerability-reporting information contain?
Since the regime took effect on 29 April 2024, the manufacturer must publish information explaining how a person can report security issues. It must also publish the timescales within which the reporter can expect acknowledgement of receipt and status updates until the reported issue is resolved.
The information must be available without prior request, in English, free of charge, and without requiring the reporter to provide personal information before accessing it. It must be accessible, clear, and transparent. PSTI does not set one universal acknowledgement, remediation, or resolution deadline; the manufacturer publishes its own expected timescales.
- Provide a monitored reporting route and state the acknowledgement and status-update times separately.
- Describe the products or services covered and give reporters enough information to submit a useful report.
- Keep access to the policy public even if the later submission process asks for contact details needed to manage a case.
Sets the required reporting route, acknowledgement and update timescales, and publication conditions.
Provides the vulnerability-disclosure-policy provision named by the standards-based deemed-compliance route.