- Review support for PSTI Scope Classifier Workflow.
"OPSS is able to prosecute in relation to offences under the PSTI Act"
PSTI Scope Classifier Workflow decisions under UK PSTI Product Security should be written in operational language: who is in scope, what must happen, what evidence proves it, and when escalation is needed.
Use this guide to turn official requirements into scope, evidence, owner, and review decisions. This guidance is practical, source-linked, and should be validated against current legal and policy requirements before implementation.
Structured answer sets in this page tree.
Cited legal and guidance references.
This page explains the UK PSTI scope-classifier workflow: how to decide whether a product is in scope, who owns each step, what evidence to capture, and when to escalate the decision. Use it to produce a clear, auditable output for manufacturers, importers, distributors, and their compliance teams.
Run the workflow as PSTI product triage: scope the product, classify the role, verify the three security requirements, approve the statement, and prepare OPSS-response evidence.
A product is in scope if it is a relevant connectable product - that is, an internet-connectable product or a network-connectable product that is not an excepted product. The regime applies to manufacturers, importers, and distributors, and also creates duties for authorised representatives in some cases.
A useful template captures product identifiers, responsible economic operator, security requirement evidence, support-period wording, statement approver, importer/distributor checks, and review trigger.
Review the workflow after firmware changes, supplier changes, product bundling changes, UK market placement changes, vulnerability reports, OPSS notices, or support-period updates.
Use this UK PSTI Product Security guide to turn PSTI Scope Classifier Workflow into owners, evidence requests, review checkpoints, and reusable operating records inside Sorena.
Turn PSTI Scope Classifier Workflow into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"OPSS is able to prosecute in relation to offences under the PSTI Act"
"Our approach to carrying out our regulatory activities will be risk-based."
"The government has been working with the tech industry to better secure consumer connectable products for several years"
"security requirements for relevant connectable products"
"The conditions under which a relevant person is subject to a specific duty are set out in the section of the Act where that duty is provided for."