Artifact GuideUKOPSS enforcement and penalties

UK PSTI Product Security OPSS enforcement and penalties

Understand OPSS investigations, compliance, stop and recall notices, monetary penalties, forfeiture, court orders, representations, appeals, and evidence needed to respond.

The available response depends on the action, its legal test, the notice date, and whether OPSS used an urgent procedure. Keep the notice and proof of service with the response record.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

can investigate suspected breaches of the UK PSTI product-security regime, which has applied since 29 April 2024, and use compliance, stop, recall, monetary-penalty, forfeiture, and information-notice powers. Several actions can be used together. A recipient should identify the exact notice, affected product and Chapter 2 duty, preserve proof of service, stop any prohibited activity, and calculate the representation or appeal deadline from the notice.

Section 1

What OPSS can do and when

A Compliance Notice can require action within a specified period to comply with a Chapter 2 duty and can require evidence. needs reasonable grounds to believe that the duty was breached and cannot use another Compliance Notice for the same act or omission. A Stop Notice can prohibit an activity that OPSS reasonably believes is occurring or likely to occur in breach of a Chapter 2 duty, or restrict a product from being made available until specified steps are completed.

A Recall Notice concerns UK consumer connectable products already supplied to customers. needs reasonable grounds to believe there is a compliance failure, must consider the business's action inadequate, and may use recall only where it considers a Compliance Notice, Stop Notice, or forfeiture application insufficient to address the risk. The Act does not create a general duty to recall every failed product, but the underlying reasonable-steps duties can still require the business to consider recall or another corrective action before OPSS intervenes.

may impose a Monetary Penalty when it is satisfied, on the balance of probabilities, that a Chapter 2 duty was breached. It may also ask a court for a Forfeiture Order covering qualifying products or for an order relating to failure to comply with an Information Notice. The statutory tests differ, and OPSS guidance says it selects action on the facts and may combine measures.

  • Compliance Notice: identify the specified duty, act or omission, required steps, evidence, and completion date. Failure to complete the specified action can lead to consider prosecution.
  • Stop Notice: identify the prohibited or restricted activity, affected products, required risk communication, evidence deadline, and any condition for revocation. Do not continue the restricted activity while preparing a challenge.
  • Recall Notice: identify the supplied products, customers and other end users, return arrangements, risk communications, evidence, and costs that may recover if it carries out the recall after non-compliance.
  • Monetary Penalty or court application: separate 's administrative penalty power from court-ordered forfeiture and the separate court-order and penalty route for failure to comply with an Information Notice.
Section 2

Representations, urgent action, and appeals

Before serving a Compliance Notice, gives a notice of intent and allows 10 days beginning with the day it is given for written representations. OPSS normally follows the same process for Stop and Recall Notices. It may serve a Stop Notice without prior notice where it considers this urgently necessary to address a consumer health or safety risk, and may serve a Recall Notice without prior notice where it considers there is an urgent need. A proposed Monetary Penalty carries a 28-day representation period.

A recipient generally has 28 days to appeal a Compliance, Stop, Recall, or Monetary Penalty Notice, a variation, or an eligible compensation decision to the First-tier Tribunal. An appeal against a notice suspends it pending the outcome. An appeal against a variation suspends only the variation, so the original notice remains effective. Forfeiture appeals follow separate court routes and also have a 28-day period under the guidance.

  • Log the day the notice was given or served, the calculation method, the due date, the notice's own instructions, and the person who verified the deadline.
  • Address the proposed action and the amount separately when responding to a proposed Monetary Penalty.
  • Do not assume that informal correspondence extends a statutory period; obtain written confirmation and case-specific advice.
  • Use the General Regulatory Chamber's current GRC1 process for a First-tier Tribunal appeal and attach the notice, grounds, decision date, and supporting evidence.
Section 3

What to do when a compliance failure is found

Manufacturers and importers must investigate potential compliance failures and act on failures they know or ought to know about. Authorised representatives and distributors also have actor-specific duties to act. Manufacturers, importers, and distributors must notify specified persons, including , in the circumstances set by Chapter 2.

guidance asks a notification to identify the failure, known risk, remedial steps and their result, and, for an importer or distributor, known remedial action by the upstream manufacturer or importer. OPSS says it considers compliance with investigation, action, and notification duties when deciding whether and how to enforce.

  • Open a dated investigation record and identify the product, versions, UK supply period, actors, customers, and relevant duty.
  • Preserve test results, vulnerability reports, statements of compliance, support-period publications, release records, supplier communications, and customer notices.
  • Record containment, remediation, prevention of further supply, customer protection, and whether each required notification was sent to and the other persons specified by the actor's duty.
  • Reassess the response when new affected versions, customers, risks, failed remediation, continued supply, or upstream corrective actions become known; update where the statutory notification duty requires it.
  • Do not delay immediate risk controls while deciding whether will take formal action.
Section 4

Evidence, publication, compensation, and escalation

can publish details of compliance failures where it considers publication in the public interest, including information about product risks and protective steps. It publishes details of formal notices and penalties in line with its Enforcement Policy. A response plan should therefore cover customers and other affected parties as well as the regulator.

Compensation for a Stop or Recall Notice is limited. The underlying breach must not have occurred, and service of the notice must not be attributable to the recipient's neglect or default. A claim should document the loss or damage, amount sought, causal link to the notice, and steps taken to minimise loss. guidance says it will give a written decision within 45 days.

  • Assign a response lead, legal reviewer, product-security lead, customer-communications owner, and evidence custodian.
  • Maintain a chronology containing every notice, call, submission, delivery receipt, decision, remediation release, customer communication, and deadline.
  • Keep the scope analysis and technical evidence tied to the exact product and version named by .
  • Escalate immediately if the notice is unclear, products remain on sale, an urgent notice bypassed representations, or a statutory deadline may have been missed.
Primary sources

References and citations

gov.uk
Referenced sections
  • Explains the general framework OPSS uses to select and apply proportionate enforcement responses.
Related guides

Explore more topics

UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a UK PSTI statement is required, the Schedule 4 fields, supply-chain checks, retention, digital accompaniment, and the December 2025 label route.
UK PSTI Act: vulnerability disclosure policy requirements and template
Publish a free, clear, accessible English reporting route plus expected acknowledgement and status-update times, and retain evidence that the information remained available.
UK PSTI applicability test: product, market, and actor scope
Apply the UK PSTI tests in order: connectivity, current exceptions, UK consumer availability, supply facts, and the manufacturer, importer, or distributor trigger.
UK PSTI compliance checklist for product release
Use a release checklist with scope, role, security-control, statement, records, and compliance-failure evidence for UK consumer connectable products.
UK PSTI compliance: duties, evidence, and response
Build a UK PSTI compliance process covering product scope, supply-chain roles, the three security requirements, statements, records, and post-market failures.
UK PSTI default password requirements
Apply the UK PSTI password rule to each relevant password, test unique-per-product generation, and keep reset and release evidence for the shipped model.
UK PSTI Default Password Rules
PSTI requires each covered password to be user-defined or unique per product. Unique credentials must not use prohibited predictable generation methods.
UK PSTI ETSI Evidence and Deemed Compliance
ETSI EN 303 645 and TS 103 701 can structure technical evidence, but the standards-based PSTI route depends on the exact mapped provisions and additional Schedule 2 conditions.
UK PSTI Excepted Products and Boundaries
An internet- or network-connectable product is outside the relevant-product definition only when a current Schedule 3 exception applies; record the exact category and facts rather than relying on a broad sector label.
UK PSTI Importer and Distributor Duties
Importers and distributors have their own statement, stop-supply, remediation, and notification duties; importers also have statutory investigation and 10-year investigation-record duties.
UK PSTI Manufacturer, Importer and Distributor Roles
Distinguish manufacturer, importer, distributor, and authorised-representative duties per product and supply route, including rebranding, imports, statement checks, stop-supply decisions, and compliance failures.
UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties
OPSS can use compliance, stop, and recall notices alongside monetary and other measures; notice recipients should preserve the notice, product scope, supply records, corrective actions, representations, and appeal dates.
UK PSTI password and security update policy requirements
Implement the UK PSTI password rule and publish a defined security support period with the required end date, access conditions, and change controls.
UK PSTI Product Security Deadlines and Compliance Calendar Guide
Track the UK PSTI regime's commencement and amendment dates, product-specific support periods, record retention, and OPSS response and appeal windows.
UK PSTI Product Security FAQ
Get direct, sourced answers on product scope, exceptions, roles, passwords, vulnerability reporting, update-period information, statements, records, and OPSS enforcement.
UK PSTI Product Security Importer and Distributor Duties Guide
Identify the pre-supply checks, statement or deemed-compliance evidence, stop-supply decisions, notification and remediation duties required of UK importers and distributors, plus importer-specific investigation and record duties.
UK PSTI Product Security Minimum Support Period and Update Transparency Guide
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in clear language, without implying that PSTI sets one duration for every product.
UK PSTI Product Security OPSS Notices Guide
Prepare for compliance, stop, and recall notices by understanding their effects, representation and appeal routes, product records, and corrective-action evidence.
UK PSTI Product Security Penalties and Fines Guide
Understand the maximum fixed and daily PSTI penalties, how OPSS sets an amount, representation and appeal rights, and separate court-ordered sanctions.
UK PSTI product security requirements
Read the three Schedule 1 security requirements and the surrounding manufacturer, importer, distributor, statement, record, and failure-response duties.
UK PSTI Relevant Connectable Product Scope
A product is relevant when it is internet-connectable or network-connectable and not excepted, then the UK consumer-use and supply facts determine whether the Part 1 duties engage.
UK PSTI relevant connectable product scope test
Decide whether one product meets the UK PSTI connectivity definition, falls within a current exception, and reaches the separate UK-consumer duty tests.
UK PSTI relevant connectable products: categories and exceptions
Understand which connected product categories can enter UK PSTI scope, how the statutory tests work, and why examples never replace the current exception schedule.
UK PSTI Scope Classifier Workflow
Decide whether a product falls within the UK PSTI product-security regime by checking connectivity, consumer supply, exceptions, actor roles, and product-specific evidence.
UK PSTI security requirements in practice
Implement the three UK PSTI security requirements through product specifications, release tests, public information, approvals, and post-release evidence.
UK PSTI Security Update Support Periods
PSTI does not prescribe a universal minimum number of support years. The manufacturer sets and publishes a product-specific minimum period and end date; preserve the published commitment and assess any later change against the current Regulations.
UK PSTI Security Update Transparency
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in language understandable without technical knowledge.
UK PSTI Statement of Compliance Evidence Pack
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
UK PSTI Statement of Compliance Template
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
UK PSTI Statement of Compliance Workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
UK PSTI Statement of Compliance: Contents, Delivery, and Records
A statement must contain the prescribed information and accompany the product unless a current deemed-compliance route applies; a digital method is possible, but each business must ensure that it meets the Act.
UK PSTI Support Period Evidence Workflow
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
UK PSTI to ETSI Evidence Mapping
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
UK PSTI vs Australia Smart Device Rules
Compare UK PSTI with Australia's Cyber Security Act smart-device rules by scope, duties, statements, security controls, retention, dates, and enforcement.
UK PSTI vs ETSI EN 303 645
See how binding UK PSTI duties relate to ETSI EN 303 645, which edition the UK Regulations name, what the standard adds, and what evidence to retain.
UK PSTI vs EU Cyber Resilience Act
Decide whether UK PSTI, the EU Cyber Resilience Act, or both apply, then compare actors, exclusions, security work, documents, reporting, and dates.
UK PSTI vs EU Cyber Resilience Act (CRA)
Compare UK PSTI and the EU Cyber Resilience Act by scope, security duties, support periods, conformity assessment, reporting, evidence, and application dates.
UK PSTI Vulnerability Disclosure Requirements
Publish a clear reporting route plus expected acknowledgement and status-update times. PSTI requires the information and timescales to be available; it does not prescribe one universal response deadline for every report.
UK PSTI Vulnerability Disclosure Workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.