Artifact GuideUKPSTI Password and Update Policy Requirements

UK PSTI Product Security PSTI Password and Update Policy Requirements

Connect the binding password and support-period publication rules to firmware, account setup, packaging, web notices, change control, and released-product evidence.

The guide separates binding duties from OPSS guidance, ETSI good practice, internal controls, and the limited deemed-compliance routes introduced in 2025.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 16, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 16, 2026
Overview

This page explains the two core requirements visitors come here for: passwords must be unique per product or user-defined, and minimum security update periods must be published in a clear, accessible and transparent way.

Section 1

What are the PSTI password and update policy requirements?

Where the Schedule 1 password requirement applies, relevant passwords must be unique per product or capable of being defined by the user. A unique-per-product password must not rely on incremental counters, public information, an unprotected unique product identifier, or anything otherwise easily guessable.

The update-policy obligation is to publish information on minimum security update periods. That information must be made available to the consumer in a clear, accessible and transparent manner, and it must state the minimum length of time security updates will be provided together with an end date.

  • Use unique passwords per product or let the user define the password.
  • Do not use passwords that are based on easily guessable patterns or public product data.
  • Publish the minimum security update period clearly and include the end date.
  • Make the update-period information available without prior request, in English, and free of charge.
Section 2

Who should own the password control and update notice, and what evidence should prove compliance?

Ownership should sit with the team that controls product design and release, because the password setting and the published support period are product claims that must match the shipped product.

Evidence should show the password rule chosen for the product, the minimum update period, the end date, the customer-facing wording, and the approval record that ties the published information to the product version.

  • Name one accountable owner for the password rule and the update-period notice.
  • Keep screenshots or links for the published update-period information.
  • Retain implementation tickets or design records showing how the password rule is enforced.
  • Update the evidence when the product changes or when the support period changes.
Section 3

Which edge cases should teams check before relying on a password or update-policy decision?

Check the product scope first. The regime applies to relevant connectable products that can connect to the internet or a network, and the official guidance also lists excluded categories such as certain Northern Ireland products, EV charge points, medical devices, smart meter products, and some desktop, laptop and tablet computers without cellular connectivity.

If the product is in scope, make sure the password rule and the support-period information still match the final configuration, not an earlier prototype or a different market version.

  • Confirm the product is a relevant connectable product before applying the password and update rules.
  • Check that the password requirement is not being satisfied by a universal default password.
  • Verify that the published update period matches the shipped version and planned support end date.
  • Escalate if the product is part of an excluded category or if the published wording is unclear.
Section 4

How should teams operationalize PSTI Password and Update Policy Requirements with proportionate controls?

Use a short product checklist that asks two questions: does the product avoid universal default and easily guessable passwords, and does the published support information state the minimum security update period and end date clearly enough for a consumer to understand it?

The output should be the configured password rule, the published update-period notice, and the approval record that links both items to the product version and launch date.

  • Ask whether the password is unique per product or user-defined.
  • Ask whether the update-period notice includes the minimum length of time and end date.
  • Keep the customer-facing text aligned with the approved product version.
  • Review the wording again when the support period, firmware plan, or product configuration changes.
Primary sources

References and citations

gov.uk
Referenced sections
  • OPSS enforcement guidance for notices and enforcement responses when PSTI product-security requirements are not met.
"take appropriate and proportionate action against businesses that fail to comply"
gov.uk
Referenced sections
  • Operational guidance for manufacturers, importers and distributors under the PSTI regime.
"publishing information on minimum security update periods"
Related guides

Explore more topics

UK PSTI Act relevant connectable products: full scope and category definitions
Understand relevant-product classification, section 54 UK-consumer and first-supply conditions, actor awareness, components and bundles, and current Schedule 3 exceptions.
UK PSTI Act statement of compliance: evidence requirements and audit documentation
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a statement must accompany a product, what prescribed information it contains, who must check it, and how the December 2025 deemed-compliance route changes—but does not erase—the evidence decision.
UK PSTI Act: is your product a relevant connectable product? scope test
Apply the statutory connectivity test, section 54 UK-consumer and first-supply conditions, actor awareness, and current excepted-product schedule to a specific product.
UK PSTI Act: step-by-step statement of compliance preparation workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
UK PSTI Act: step-by-step vulnerability disclosure process workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.
UK PSTI Act: vulnerability disclosure policy requirements and template
Publish a free, clear, accessible English reporting route plus expected acknowledgement and status-update times, and retain evidence that the information remained available.
UK PSTI Default Password Requirements
Apply the password rule to relevant passwords: user-defined credentials or unique-per-product credentials that are not incremental, publicly derived, identifier-derived without accepted protection, or otherwise easily guessable.
UK PSTI Product Security Applicability Test Guide
Use a step-by-step test for connectivity, current exceptions, section 54 UK-consumer and first-supply conditions, actor awareness, and the exact section 7 role.
UK PSTI Product Security Checklist
Use a release checklist that joins product scope, role, the three Schedule 1 controls, statement accompaniment, record retention, and compliance-failure escalation.
UK PSTI Product Security Compliance Guide
Understand how the 2022 Act, the 2023 Regulations, the 2025 amendments, and OPSS guidance fit together in an operational product-compliance system.
UK PSTI Product Security Deadlines and Compliance Calendar Guide
Separate the 29 April 2024 commencement, the two 2025 amendments, recurring product-support commitments, 10-year records, and OPSS notice or appeal windows.
UK PSTI Product Security ETSI Evidence Mapping Guide
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
UK PSTI Product Security FAQ
Get direct, sourced answers on product scope, exceptions, roles, passwords, vulnerability reporting, update-period information, statements, records, and OPSS enforcement.
UK PSTI Product Security Importer and Distributor Duties Guide
Identify the pre-supply checks, statement or deemed-compliance evidence, stop-supply decisions, investigation, notification, remediation, and records required of UK importers and distributors.
UK PSTI Product Security Minimum Support Period and Update Transparency Guide
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in clear language—without implying PSTI sets a universal minimum duration.
UK PSTI Product Security OPSS Enforcement and Penalties Guide
Understand OPSS investigations, compliance, stop and recall notices, monetary penalties, forfeiture, court orders, representations, appeals, and evidence needed to respond.
UK PSTI Product Security OPSS Notices Guide
Prepare for compliance, stop, and recall notices by understanding their effects, representation and appeal routes, product records, and corrective-action evidence.
UK PSTI Product Security penalties and fines Guide
Explain the statutory maximum monetary penalty—the greater of £10 million and 4% of qualifying worldwide revenue—alongside daily penalties, notice rights, and non-monetary measures.
UK PSTI Product Security PSTI Scope Classifier Workflow Guide
Classify connectivity and Schedule 3 exceptions, then record section 54 UK-consumer facts, first supply, actor awareness, bundles, rebranding, and the section 7 role.
UK PSTI Product Security PSTI Statement Of Compliance Template Guide
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
UK PSTI Product Security PSTI vs CRA Guide
A concise UK PSTI versus EU Cyber Resilience Act crosswalk for product scope, actor roles, security duties, conformity, reporting, support periods, and transition dates.
UK PSTI Product Security PSTI vs ETSI EN 303 645 Guide
Separate the three binding UK PSTI requirements from the broader ETSI EN 303 645 baseline and use ETSI evidence only where it actually supports the corresponding UK condition.
UK PSTI Product Security PSTI vs EU Cyber Resilience Act Guide
Compare UK PSTI with the EU Cyber Resilience Act across territorial scope, covered products, actor roles, security lifecycle, conformity, vulnerability reporting, support periods, and transition dates.
UK PSTI Product Security Requirements Guide
Read the three binding Schedule 1 requirements together with the role, statement, records, investigation, remediation, and notification duties that surround them.
UK PSTI Product Security Requirements In Practice Guide
Turn the password, vulnerability-reporting, and update-period rules into product requirements, release tests, public information, approvals, and change-controlled evidence.
UK PSTI Product Security Supply Chain Roles Manufacturer Importer Distributor Guide
Distinguish manufacturer, importer, distributor, and authorised-representative duties per product and supply route, including rebranding, imports, statement checks, stop-supply decisions, and compliance failures.
UK PSTI Product Security Support Period Evidence Workflow Guide
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
UK PSTI vs Australia Cyber Security Act Guide
Compare the UK and Australian connected-product regimes by product scope, actor duties, security standards, statements, commencement, evidence, and enforcement rather than assuming one file satisfies both.
What should teams do about Default Passwords under UK PSTI Product Security?
No: PSTI does not merely ban one shared factory password. Relevant passwords must be user-defined or unique per product, and unique credentials must not be incremental, publicly derived, identifier-derived without accepted protection, or otherwise easily guessable.
What should teams do about ETSI Evidence under UK PSTI Product Security?
ETSI EN 303 645 and TS 103 701 can structure technical evidence, but only mapped provisions support the three UK requirements; the wider ETSI baseline is not automatically binding under PSTI.
What should teams do about Excepted Products under UK PSTI Product Security?
An internet- or network-connectable product is outside the relevant-product definition only when a current Schedule 3 exception applies; record the exact category and facts rather than relying on a broad sector label.
What should teams do about Importer and Distributor Duties under UK PSTI Product Security?
Importers and distributors have their own statement checks, stop-supply, investigation, notification, remediation, and record duties; a manufacturer assurance does not replace those decisions.
What should teams do about OPSS Notices under UK PSTI Product Security?
OPSS can use compliance, stop, and recall notices alongside monetary and other measures; notice recipients should preserve the notice, product scope, supply records, corrective actions, representations, and appeal dates.
What should teams do about Relevant Connectable Products under UK PSTI Product Security?
A product is relevant when it is internet-connectable or network-connectable and not excepted, then the UK consumer-use and supply facts determine whether the Part 1 duties engage.
What should teams do about Statement Of Compliance under UK PSTI Product Security?
A statement must contain the prescribed information and accompany the product unless a current deemed-compliance route applies; digital accompaniment can be possible, but the business must prove its method meets the Act.
What should teams do about Support Periods under UK PSTI Product Security?
PSTI does not prescribe a universal minimum number of support years. The manufacturer sets and publishes a product-specific minimum period and end date; preserve the published commitment and assess any later change against the current Regulations.
What should teams do about Update Transparency under UK PSTI Product Security?
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in language understandable without technical knowledge.
What should teams do about Vulnerability Disclosure under UK PSTI Product Security?
Publish a clear reporting route plus expected acknowledgement and status-update times. PSTI requires the information and timescales to be available; it does not prescribe one universal response deadline for every report.