Artifact GuideUKPSTI Scope Classifier Workflow

UK PSTI Scope Classifier Workflow

Decide whether a product is a relevant connectable product supplied to UK consumers, then identify the manufacturer, importer, distributor, and any exception.

The result is product- and supply-route-specific. A connectable product is not automatically subject to every duty.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Classify the product before mapping the company and supply chain. Under Part 1 of the Product Security and Telecommunications Infrastructure (PSTI) Act 2022, a product is a if it is internet-connectable or network-connectable and is not an excepted product. Then apply the separate UK consumer-product conditions and identify each actor's role for the actual supply route. Record the facts used at every step because branding, connectivity, intended purpose, bundling, and route to market can change the result.

Section 1

Step 1: classify the product

Document how the product connects. An is capable of connecting to the internet by using a protocol in the Internet Protocol suite to send and receive data. A must be capable of both sending and receiving data by electrical or electromagnetic transmission, must not itself be internet-connectable, and must meet one of the Act's direct-connectability conditions.

For the first network-connectability condition, the product can connect directly to an using an IP-suite protocol. For the second, it can use a non-IP protocol to connect directly to two or more products at once and can connect directly to an internet-connectable product using that protocol. Section 5 also treats certain wireless computer input products as meeting the second condition when they work through a linking product.

Classify the whole item made available, including embedded software and supplied components. For bundles, record whether each item is independently a product and whether the bundle changes how the items connect. Do not decide scope from a marketing label such as "smart" or "IoT". Example candidates include a Wi-Fi camera as internet-connectable and a non-IP wireless peripheral that reaches an internet-connected computer through its supplied hub as network-connectable; the exact architecture still controls.

  • Record the model, hardware revision, firmware or software version, radios, ports, protocols, companion apps, cloud services, and connection path.
  • State whether data can be sent and received, whether internet access is direct or through another product, and which factual evidence supports the answer.
  • If a product only receives or only sends data, preserve the architecture evidence: it does not meet the network-connectable send-and-receive limb on that path, but another path may still make it internet-connectable or network-connectable.
  • Do not treat every indirect connection as sufficient. Record the protocol, the directly connected products, and whether the statutory first or second connectability condition is met.
Section 2

Step 2: check every Schedule 3 exception

A technically connectable product is outside the relevant-connectable-product definition if Schedule 3 excepts it. Check the exact conditions, not only the category name. Current exceptions cover specified Northern Ireland supply, EV smart charge points, medical devices, smart meter products, certain non-cellular desktop, laptop and tablet computers, and specified vehicle categories.

The computer exception does not cover a product with cellular connectivity. It also does not cover a non-cellular computer designed exclusively for children under 14. Vehicle exceptions depend on the cited sector legislation, so a vehicle accessory or component needs a provision-specific check.

  • Record the Schedule 3 paragraph, the product facts satisfying every condition, and the evidence owner.
  • For Northern Ireland, identify the actual supply destination and the relevant Annex 2 legislation with a free-movement provision; UK-wide branding alone does not answer the exception.
  • Reassess an exception after intended-purpose, connectivity, vehicle-integration, medical-device, metering, or market-destination changes.
Section 3

Step 3: apply the UK consumer and supply conditions

Relevant-product status is only the first gate. Section 54 treats a as a UK consumer connectable product when it is first made available to UK consumers, or when it is first made available to UK business customers and identical products are first made available to UK consumers. The first-supply conditions have specific rules for returns, compliance-related returns, reconditioned products, and supplies through a person who would otherwise be a distributor. Record those facts instead of assuming that business-only sales are outside scope.

For each duty, apply the conditions in the Act, including what the actor intended, knew, believed, or ought to have known when making the product available. The manufacturer's security-requirement, statement, and compliance-failure duties, and the importer's and distributor's checks, have separate triggers. Record first-supply and later-supply facts separately.

Classify roles per product and transaction. A person that makes or has a product made and markets it under its own name or trade mark is a manufacturer, including a rebrander. An importer brings the product into the UK from outside the UK and is not the manufacturer. A distributor makes it available in the UK and is neither manufacturer nor importer.

  • Record intended users, sales channels, UK listings, packaging, instructions, contracts, forecasts, actual supply history, and the date each actor first made the product available.
  • For a business-only model, compare hardware, software, configuration, intended purpose, and branding with the consumer model before calling the products identical under section 54.
  • Identify every manufacturer where more than one entity meets the definition; regulation 5 requires each manufacturer to meet or be deemed to meet the relevant security requirements.
  • Record any UK authorised representative and the manufacturer duties it agreed to perform. The appointment does not remove the manufacturer's liability.
  • Output one decision for the product and supply route: in scope, out of scope with the failed gate or exception, or unresolved. An unresolved result must name the missing fact, owner, and release consequence and must block reliance on the classification.
Primary sources

References and citations

Related guides

Explore more topics

UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a UK PSTI statement is required, the Schedule 4 fields, supply-chain checks, retention, digital accompaniment, and the December 2025 label route.
UK PSTI Act: vulnerability disclosure policy requirements and template
Publish a free, clear, accessible English reporting route plus expected acknowledgement and status-update times, and retain evidence that the information remained available.
UK PSTI applicability test: product, market, and actor scope
Apply the UK PSTI tests in order: connectivity, current exceptions, UK consumer availability, supply facts, and the manufacturer, importer, or distributor trigger.
UK PSTI compliance checklist for product release
Use a release checklist with scope, role, security-control, statement, records, and compliance-failure evidence for UK consumer connectable products.
UK PSTI compliance: duties, evidence, and response
Build a UK PSTI compliance process covering product scope, supply-chain roles, the three security requirements, statements, records, and post-market failures.
UK PSTI default password requirements
Apply the UK PSTI password rule to each relevant password, test unique-per-product generation, and keep reset and release evidence for the shipped model.
UK PSTI Default Password Rules
PSTI requires each covered password to be user-defined or unique per product. Unique credentials must not use prohibited predictable generation methods.
UK PSTI ETSI Evidence and Deemed Compliance
ETSI EN 303 645 and TS 103 701 can structure technical evidence, but the standards-based PSTI route depends on the exact mapped provisions and additional Schedule 2 conditions.
UK PSTI Excepted Products and Boundaries
An internet- or network-connectable product is outside the relevant-product definition only when a current Schedule 3 exception applies; record the exact category and facts rather than relying on a broad sector label.
UK PSTI Importer and Distributor Duties
Importers and distributors have their own statement, stop-supply, remediation, and notification duties; importers also have statutory investigation and 10-year investigation-record duties.
UK PSTI Manufacturer, Importer and Distributor Roles
Distinguish manufacturer, importer, distributor, and authorised-representative duties per product and supply route, including rebranding, imports, statement checks, stop-supply decisions, and compliance failures.
UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties
OPSS can use compliance, stop, and recall notices alongside monetary and other measures; notice recipients should preserve the notice, product scope, supply records, corrective actions, representations, and appeal dates.
UK PSTI password and security update policy requirements
Implement the UK PSTI password rule and publish a defined security support period with the required end date, access conditions, and change controls.
UK PSTI Product Security Deadlines and Compliance Calendar Guide
Track the UK PSTI regime's commencement and amendment dates, product-specific support periods, record retention, and OPSS response and appeal windows.
UK PSTI Product Security FAQ
Get direct, sourced answers on product scope, exceptions, roles, passwords, vulnerability reporting, update-period information, statements, records, and OPSS enforcement.
UK PSTI Product Security Importer and Distributor Duties Guide
Identify the pre-supply checks, statement or deemed-compliance evidence, stop-supply decisions, notification and remediation duties required of UK importers and distributors, plus importer-specific investigation and record duties.
UK PSTI Product Security Minimum Support Period and Update Transparency Guide
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in clear language, without implying that PSTI sets one duration for every product.
UK PSTI Product Security OPSS Enforcement and Penalties Guide
Understand OPSS investigations, compliance, stop and recall notices, monetary penalties, forfeiture, court orders, representations, appeals, and evidence needed to respond.
UK PSTI Product Security OPSS Notices Guide
Prepare for compliance, stop, and recall notices by understanding their effects, representation and appeal routes, product records, and corrective-action evidence.
UK PSTI Product Security Penalties and Fines Guide
Understand the maximum fixed and daily PSTI penalties, how OPSS sets an amount, representation and appeal rights, and separate court-ordered sanctions.
UK PSTI product security requirements
Read the three Schedule 1 security requirements and the surrounding manufacturer, importer, distributor, statement, record, and failure-response duties.
UK PSTI Relevant Connectable Product Scope
A product is relevant when it is internet-connectable or network-connectable and not excepted, then the UK consumer-use and supply facts determine whether the Part 1 duties engage.
UK PSTI relevant connectable product scope test
Decide whether one product meets the UK PSTI connectivity definition, falls within a current exception, and reaches the separate UK-consumer duty tests.
UK PSTI relevant connectable products: categories and exceptions
Understand which connected product categories can enter UK PSTI scope, how the statutory tests work, and why examples never replace the current exception schedule.
UK PSTI security requirements in practice
Implement the three UK PSTI security requirements through product specifications, release tests, public information, approvals, and post-release evidence.
UK PSTI Security Update Support Periods
PSTI does not prescribe a universal minimum number of support years. The manufacturer sets and publishes a product-specific minimum period and end date; preserve the published commitment and assess any later change against the current Regulations.
UK PSTI Security Update Transparency
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in language understandable without technical knowledge.
UK PSTI Statement of Compliance Evidence Pack
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
UK PSTI Statement of Compliance Template
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
UK PSTI Statement of Compliance Workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
UK PSTI Statement of Compliance: Contents, Delivery, and Records
A statement must contain the prescribed information and accompany the product unless a current deemed-compliance route applies; a digital method is possible, but each business must ensure that it meets the Act.
UK PSTI Support Period Evidence Workflow
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
UK PSTI to ETSI Evidence Mapping
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
UK PSTI vs Australia Smart Device Rules
Compare UK PSTI with Australia's Cyber Security Act smart-device rules by scope, duties, statements, security controls, retention, dates, and enforcement.
UK PSTI vs ETSI EN 303 645
See how binding UK PSTI duties relate to ETSI EN 303 645, which edition the UK Regulations name, what the standard adds, and what evidence to retain.
UK PSTI vs EU Cyber Resilience Act
Decide whether UK PSTI, the EU Cyber Resilience Act, or both apply, then compare actors, exclusions, security work, documents, reporting, and dates.
UK PSTI vs EU Cyber Resilience Act (CRA)
Compare UK PSTI and the EU Cyber Resilience Act by scope, security duties, support periods, conformity assessment, reporting, evidence, and application dates.
UK PSTI Vulnerability Disclosure Requirements
Publish a clear reporting route plus expected acknowledgement and status-update times. PSTI requires the information and timescales to be available; it does not prescribe one universal response deadline for every report.
UK PSTI Vulnerability Disclosure Workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.