- OPSS guidance explains compliance failures, investigations, notifications, notices, penalties, representations, and appeals.
References and citations
- Part 1 defines product and actor scope, statements, investigations, remediation, notifications, records, and enforcement.
- S.I. 2025/1267 added limited deemed-compliance conditions from 4 December 2025.
- The current consolidated Regulations contain the detailed password, vulnerability-reporting, update-period, statement, deemed-compliance, and exception rules.
- OPSS and DSIT guidance explains the regime, covered actors and products, the three requirements, statement accompaniment, and enforcement authority.
- The government policy paper explains the legislative framework, economic-operator duties, statements, and the relationship to ETSI provisions.