How should teams handle vulnerability disclosure under UK PSTI Product Security?
Teams should treat vulnerability disclosure under the UK PSTI Act as a source-linked operating decision: confirm whether the product is a relevant connectable product and which manufacturer, importer, distributor, statement-of-compliance, vulnerability-disclosure, password, support-period, or OPSS enforcement duty is relevant, assign the team that can change the process, and keep evidence showing the action and review trigger.
The safest first step is to classify the product and supply-chain role before deciding whether the duty belongs to the manufacturer, importer, distributor, or all of them.
- Write the vulnerability-disclosure decision in one sentence before drafting controls.
- Attach the external source URL and a short source quote to the evidence record.
- Route unclear cases to legal, privacy, security, or compliance review before launch.
OPSS enforcement guidance confirms the PSTI Act and Security Requirements Regulations are the legislation OPSS enforces for product-security duties.
GOV.UK regime guidance confirms the relevant persons and duties that sit around vulnerability-disclosure compliance.
Direct support for the FAQ answer on vulnerability disclosure.