Artifact GuideUKImporter and Distributor Duties

UK PSTI Product Security Importer and Distributor Duties

Identify the pre-supply checks, statement or deemed-compliance evidence, stop-supply decisions, notification and remediation duties required of UK importers and distributors, plus importer-specific investigation and record duties.

Sections 14 to 25 of the 2022 Act control the role-specific duties; the current 2023 Regulations set statement retention and deemed-compliance conditions, while OPSS guidance explains enforcement administration.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

An or distributor must stop an in-scope product from reaching the UK market if the required statement evidence is missing or the business knows or believes the manufacturer has failed a relevant security requirement. An importer also investigates reported failures and keeps investigation records; a distributor has separate contact, notification, remediation, and stop-supply duties. These rules have applied since 29 April 2024 to relevant connectable products intended, or known or reasonably expected, to be UK consumer connectable products.

Section 1

Classify the importer or distributor before supply

Classify the business role for the exact supply transaction. Under the Act, an brings a product into the United Kingdom from outside the United Kingdom and is not its manufacturer. A distributor makes a product available in the United Kingdom and is neither its manufacturer nor importer. A business that markets a product under its own name or trade mark is a manufacturer, so a private-label arrangement changes the duty set.

Before supply, both roles must decide whether the item is a relevant connectable product and whether they intend it to be, or know or ought to know it will be, a UK consumer connectable product. If so, they must comply with any security requirements that apply to their role and must not make the product available unless the statement-of-compliance route is satisfied.

  • : obtain the statement of compliance before supply. The Act anticipates a possible summary route, but the current Regulations do not specify a permitted summary. If a 2025 deemed-compliance route is used, verify and record every specified condition instead.
  • Distributor: check for the statement before supply or verify every condition for an applicable 2025 deemed-compliance route. The Act does not impose the 's statement-copy retention duty on distributors.
  • or distributor: do not supply when the business knows or believes that the manufacturer has failed a relevant security requirement.
  • Record the product model and version, UK consumer-use decision, role, supplier and manufacturer, evidence checked, decision date, and the person who approved release.
Section 2

Keep role-specific evidence and records

Procurement or market-access teams should own the pre-supply gate, with product security assessing technical failures and legal or compliance staff reviewing scope and notification decisions. The evidence must identify the shipped product, not only a product family or an earlier firmware release.

Under the current Regulations, an must retain the statement for the longer of 10 years from issue or the defined support period stated in it. The importer must also keep each investigation record for 10 years from the day the record is made. That record must include the outcome, identified failure, remedial steps, and whether those steps succeeded.

  • Keep the manufacturer's statement or deemed-compliance evidence linked to the exact model, version, batch, and defined support period.
  • Keep intake evidence showing why the business is an or distributor and why the product is or is not expected to be a UK consumer connectable product.
  • For an investigation, record the information received, reasonable investigative steps, outcome, failure details, remediation, and attempts to obtain missing manufacturer information.
  • For a distributor, retain the pre-supply check and all later communications, notifications, stop-supply decisions, and remedial actions even though section 20's investigation-record duty applies to importers.
Section 3

Check rebranding, business channels, bundles, and label routes

Role labels in a contract do not settle the statutory classification. Check who imports the product, whose name or trademark is used, who first makes it available in the United Kingdom, and whether any modification or rebranding changes the manufacturer analysis.

The consumer-use test includes what the business ought to know, not only its stated sales channel. Review products sold as business-only if consumers could reasonably obtain and use them, and check Schedule 3 before assuming that another regulatory regime or product category creates an exception.

  • Re-run the decision for bundles and kits: identify each connectable product and the entity performing each supply-chain act.
  • Do not treat a statement of compliance as proof that the shipped unit meets every duty. A known or believed manufacturer failure still triggers the stop-supply rule.
  • Do not carry an approval across a change in branding, connectivity, firmware, intended use, manufacturer, , or distribution route without checking whether the role or evidence changed.
  • From 4 December 2025, Schedule 2A can deem the statement-accompaniment requirement met where the product is currently assigned an unexpired Japan JC-STAR STAR-1 label or currently awarded an unexpired label under any level of Singapore's Cybersecurity Labelling Scheme. An or distributor relying on that route must be satisfied that the specified condition is met; a label or foreign scheme name is not enough by itself.
Section 4

Investigate and act after supply

After supply, an that receives information about a possible importer or manufacturer compliance failure must take all reasonable steps to investigate. Importers and distributors must act when they become aware, or ought to be aware, of their own failure; the Act also sets separate steps when the failure is the manufacturer's.

Notifications depend on the role, whose failure it is, who has already been told, and whether specified customer-notification conditions apply. OPSS guidance says notifications to the authority should describe the failure, known risks, remedial steps, and whether remediation succeeded.

  • Quarantine affected stock and block new UK supply while the facts are investigated; preserve model, batch, firmware, supplier, and sales-channel records.
  • For the 's or distributor's own failure after customer supply, take all reasonable steps to remedy it as soon as practicable and notify the enforcement authority as soon as possible.
  • For a manufacturer's failure, contact the manufacturer as soon as possible. If remediation appears unlikely, take all reasonable steps to prevent further customer supply and make the role-specific notifications required by sections 19 or 25.
  • Do not duplicate a notification that the Act says is unnecessary because the relevant person already supplied the information, but record who notified whom, when, and what they confirmed.
Primary sources

References and citations

Related guides

Explore more topics

UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a UK PSTI statement is required, the Schedule 4 fields, supply-chain checks, retention, digital accompaniment, and the December 2025 label route.
UK PSTI Act: vulnerability disclosure policy requirements and template
Publish a free, clear, accessible English reporting route plus expected acknowledgement and status-update times, and retain evidence that the information remained available.
UK PSTI applicability test: product, market, and actor scope
Apply the UK PSTI tests in order: connectivity, current exceptions, UK consumer availability, supply facts, and the manufacturer, importer, or distributor trigger.
UK PSTI compliance checklist for product release
Use a release checklist with scope, role, security-control, statement, records, and compliance-failure evidence for UK consumer connectable products.
UK PSTI compliance: duties, evidence, and response
Build a UK PSTI compliance process covering product scope, supply-chain roles, the three security requirements, statements, records, and post-market failures.
UK PSTI default password requirements
Apply the UK PSTI password rule to each relevant password, test unique-per-product generation, and keep reset and release evidence for the shipped model.
UK PSTI Default Password Rules
PSTI requires each covered password to be user-defined or unique per product. Unique credentials must not use prohibited predictable generation methods.
UK PSTI ETSI Evidence and Deemed Compliance
ETSI EN 303 645 and TS 103 701 can structure technical evidence, but the standards-based PSTI route depends on the exact mapped provisions and additional Schedule 2 conditions.
UK PSTI Excepted Products and Boundaries
An internet- or network-connectable product is outside the relevant-product definition only when a current Schedule 3 exception applies; record the exact category and facts rather than relying on a broad sector label.
UK PSTI Importer and Distributor Duties
Importers and distributors have their own statement, stop-supply, remediation, and notification duties; importers also have statutory investigation and 10-year investigation-record duties.
UK PSTI Manufacturer, Importer and Distributor Roles
Distinguish manufacturer, importer, distributor, and authorised-representative duties per product and supply route, including rebranding, imports, statement checks, stop-supply decisions, and compliance failures.
UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties
OPSS can use compliance, stop, and recall notices alongside monetary and other measures; notice recipients should preserve the notice, product scope, supply records, corrective actions, representations, and appeal dates.
UK PSTI password and security update policy requirements
Implement the UK PSTI password rule and publish a defined security support period with the required end date, access conditions, and change controls.
UK PSTI Product Security Deadlines and Compliance Calendar Guide
Track the UK PSTI regime's commencement and amendment dates, product-specific support periods, record retention, and OPSS response and appeal windows.
UK PSTI Product Security FAQ
Get direct, sourced answers on product scope, exceptions, roles, passwords, vulnerability reporting, update-period information, statements, records, and OPSS enforcement.
UK PSTI Product Security Minimum Support Period and Update Transparency Guide
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in clear language, without implying that PSTI sets one duration for every product.
UK PSTI Product Security OPSS Enforcement and Penalties Guide
Understand OPSS investigations, compliance, stop and recall notices, monetary penalties, forfeiture, court orders, representations, appeals, and evidence needed to respond.
UK PSTI Product Security OPSS Notices Guide
Prepare for compliance, stop, and recall notices by understanding their effects, representation and appeal routes, product records, and corrective-action evidence.
UK PSTI Product Security Penalties and Fines Guide
Understand the maximum fixed and daily PSTI penalties, how OPSS sets an amount, representation and appeal rights, and separate court-ordered sanctions.
UK PSTI product security requirements
Read the three Schedule 1 security requirements and the surrounding manufacturer, importer, distributor, statement, record, and failure-response duties.
UK PSTI Relevant Connectable Product Scope
A product is relevant when it is internet-connectable or network-connectable and not excepted, then the UK consumer-use and supply facts determine whether the Part 1 duties engage.
UK PSTI relevant connectable product scope test
Decide whether one product meets the UK PSTI connectivity definition, falls within a current exception, and reaches the separate UK-consumer duty tests.
UK PSTI relevant connectable products: categories and exceptions
Understand which connected product categories can enter UK PSTI scope, how the statutory tests work, and why examples never replace the current exception schedule.
UK PSTI Scope Classifier Workflow
Decide whether a product falls within the UK PSTI product-security regime by checking connectivity, consumer supply, exceptions, actor roles, and product-specific evidence.
UK PSTI security requirements in practice
Implement the three UK PSTI security requirements through product specifications, release tests, public information, approvals, and post-release evidence.
UK PSTI Security Update Support Periods
PSTI does not prescribe a universal minimum number of support years. The manufacturer sets and publishes a product-specific minimum period and end date; preserve the published commitment and assess any later change against the current Regulations.
UK PSTI Security Update Transparency
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in language understandable without technical knowledge.
UK PSTI Statement of Compliance Evidence Pack
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
UK PSTI Statement of Compliance Template
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
UK PSTI Statement of Compliance Workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
UK PSTI Statement of Compliance: Contents, Delivery, and Records
A statement must contain the prescribed information and accompany the product unless a current deemed-compliance route applies; a digital method is possible, but each business must ensure that it meets the Act.
UK PSTI Support Period Evidence Workflow
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
UK PSTI to ETSI Evidence Mapping
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
UK PSTI vs Australia Smart Device Rules
Compare UK PSTI with Australia's Cyber Security Act smart-device rules by scope, duties, statements, security controls, retention, dates, and enforcement.
UK PSTI vs ETSI EN 303 645
See how binding UK PSTI duties relate to ETSI EN 303 645, which edition the UK Regulations name, what the standard adds, and what evidence to retain.
UK PSTI vs EU Cyber Resilience Act
Decide whether UK PSTI, the EU Cyber Resilience Act, or both apply, then compare actors, exclusions, security work, documents, reporting, and dates.
UK PSTI vs EU Cyber Resilience Act (CRA)
Compare UK PSTI and the EU Cyber Resilience Act by scope, security duties, support periods, conformity assessment, reporting, evidence, and application dates.
UK PSTI Vulnerability Disclosure Requirements
Publish a clear reporting route plus expected acknowledgement and status-update times. PSTI requires the information and timescales to be available; it does not prescribe one universal response deadline for every report.
UK PSTI Vulnerability Disclosure Workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.