Artifact GuideUKSecurity Requirements In Practice

UK PSTI Product Security Security Requirements In Practice

Turn the password, vulnerability-reporting, and update-period rules into product requirements, release tests, public information, approvals, and change-controlled evidence.

The guide separates binding duties from OPSS guidance, ETSI good practice, internal controls, and the limited deemed-compliance routes introduced in 2025.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 16, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 16, 2026
Overview

This page explains the UK PSTI security requirements in plain terms. First classify the relevant connectable product and apply the Act's UK-consumer and manufacturer trigger; then turn the applicable 2023 Regulations requirements into release evidence before the product is made available in the United Kingdom.

Section 1

What should teams decide about Security Requirements In Practice under UK PSTI Product Security?

Start by checking whether the product is a relevant connectable product and whether the team is acting as a manufacturer, importer, distributor, or authorised representative. The main practical question is whether the product and business role are in scope, and if so, what the team must do to comply.

For in-scope products, the core security requirements are straightforward: ban universal default and easily guessable passwords, publish information on how to report security issues, and publish information on the minimum security update period. Keep the legal source, product-scope decision, role, required action, owner, evidence, and escalation point together so the decision is reviewable.

  • Confirm whether the product is in scope as a relevant connectable product and whether any excepted product rule applies.
  • Record which role is responsible: manufacturer, importer, distributor, or authorised representative.
  • Link the security requirement to the action, such as password control, vulnerability reporting information, or minimum update-period information.
  • Escalate uncertainty when the facts depend on scope, exemptions, supply-chain role, or whether the statement of compliance can accompany the product.
Section 2

Who should own Security Requirements In Practice, and what evidence should prove the decision?

Ownership should sit with the team that controls product design, supply-chain placement, importer/distributor checks, or customer security information, with legal and product-security review.

Evidence should show relevant-connectable-product scope, default-password controls, vulnerability disclosure channel, minimum support period, statement of compliance, supply-chain role checks, and OPSS notice response readiness.

  • Name one accountable owner and one reviewer for the Security Requirements In Practice workflow.
  • Keep current source links, scope and role decisions, test results, published notices, statement approvals, and release identifiers together.
  • Use dated evidence for deadlines, notices, risk assessments, contracts, user journeys, and regulator-facing records.
  • Review the evidence after product changes, new markets, new vendors, enforcement updates, or material changes in the source text.
Section 3

Which edge cases should teams check before relying on a Security Requirements In Practice decision?

Most PSTI mistakes happen at the boundary between manufacturer, importer and distributor duties, excepted products, bundled products, support-period statements, and evidence that does not match the shipped product.

Review this section before UK market placement, importer onboarding, distributor acceptance, or support-period publication so the evidence matches the actual product and supply-chain role.

  • Check intended consumer use, products marketed as business-only but predictably used by consumers, children’s products, sector-regulated products, bundles, and cellular-capable computers.
  • Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
  • Do not reuse a previous decision if connectivity, intended purpose, branding, product composition, firmware, supplier, or distribution model changed.
  • Track unresolved assumptions in an open-questions section and route legal interpretation points for review.
Section 4

How should teams operationalize Security Requirements In Practice with proportionate controls?

Use a compact PSTI workflow that captures product scope, role, password control, vulnerability disclosure route, support-period information, statement-of-compliance approval, and OPSS escalation path.

The output should be a product-scope note, statement-of-compliance pack, supplier attestation, customer-facing support-period notice, or OPSS response record.

  • Use a product intake that captures connectivity, intended use, UK availability, exceptions, role, control owner, statement route, and evidence location.
  • Map the answer to a required action, evidence field, owner, reviewer, and review date.
  • Link related artifact pages with descriptive anchors so users can move from scope to deadlines, controls, penalties, and templates.
  • Update the workflow when legislation or OPSS guidance changes and when product reviews reveal recurring scope, statement, or evidence failures.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Operational implementation support for Security Requirements In Practice.
"The government has been working with the tech industry to better secure consumer connectable products for several years"
Related guides

Explore more topics

UK PSTI Act relevant connectable products: full scope and category definitions
Understand relevant-product classification, section 54 UK-consumer and first-supply conditions, actor awareness, components and bundles, and current Schedule 3 exceptions.
UK PSTI Act statement of compliance: evidence requirements and audit documentation
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a statement must accompany a product, what prescribed information it contains, who must check it, and how the December 2025 deemed-compliance route changes—but does not erase—the evidence decision.
UK PSTI Act: is your product a relevant connectable product? scope test
Apply the statutory connectivity test, section 54 UK-consumer and first-supply conditions, actor awareness, and current excepted-product schedule to a specific product.
UK PSTI Act: step-by-step statement of compliance preparation workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
UK PSTI Act: step-by-step vulnerability disclosure process workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.
UK PSTI Act: vulnerability disclosure policy requirements and template
Publish a free, clear, accessible English reporting route plus expected acknowledgement and status-update times, and retain evidence that the information remained available.
UK PSTI Default Password Requirements
Apply the password rule to relevant passwords: user-defined credentials or unique-per-product credentials that are not incremental, publicly derived, identifier-derived without accepted protection, or otherwise easily guessable.
UK PSTI Product Security Applicability Test Guide
Use a step-by-step test for connectivity, current exceptions, section 54 UK-consumer and first-supply conditions, actor awareness, and the exact section 7 role.
UK PSTI Product Security Checklist
Use a release checklist that joins product scope, role, the three Schedule 1 controls, statement accompaniment, record retention, and compliance-failure escalation.
UK PSTI Product Security Compliance Guide
Understand how the 2022 Act, the 2023 Regulations, the 2025 amendments, and OPSS guidance fit together in an operational product-compliance system.
UK PSTI Product Security Deadlines and Compliance Calendar Guide
Separate the 29 April 2024 commencement, the two 2025 amendments, recurring product-support commitments, 10-year records, and OPSS notice or appeal windows.
UK PSTI Product Security ETSI Evidence Mapping Guide
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
UK PSTI Product Security FAQ
Get direct, sourced answers on product scope, exceptions, roles, passwords, vulnerability reporting, update-period information, statements, records, and OPSS enforcement.
UK PSTI Product Security Importer and Distributor Duties Guide
Identify the pre-supply checks, statement or deemed-compliance evidence, stop-supply decisions, investigation, notification, remediation, and records required of UK importers and distributors.
UK PSTI Product Security Minimum Support Period and Update Transparency Guide
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in clear language—without implying PSTI sets a universal minimum duration.
UK PSTI Product Security OPSS Enforcement and Penalties Guide
Understand OPSS investigations, compliance, stop and recall notices, monetary penalties, forfeiture, court orders, representations, appeals, and evidence needed to respond.
UK PSTI Product Security OPSS Notices Guide
Prepare for compliance, stop, and recall notices by understanding their effects, representation and appeal routes, product records, and corrective-action evidence.
UK PSTI Product Security penalties and fines Guide
Explain the statutory maximum monetary penalty—the greater of £10 million and 4% of qualifying worldwide revenue—alongside daily penalties, notice rights, and non-monetary measures.
UK PSTI Product Security PSTI Password and Update Policy Requirements Guide
Connect the binding password and support-period publication rules to firmware, account setup, packaging, web notices, change control, and released-product evidence.
UK PSTI Product Security PSTI Scope Classifier Workflow Guide
Classify connectivity and Schedule 3 exceptions, then record section 54 UK-consumer facts, first supply, actor awareness, bundles, rebranding, and the section 7 role.
UK PSTI Product Security PSTI Statement Of Compliance Template Guide
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
UK PSTI Product Security PSTI vs CRA Guide
A concise UK PSTI versus EU Cyber Resilience Act crosswalk for product scope, actor roles, security duties, conformity, reporting, support periods, and transition dates.
UK PSTI Product Security PSTI vs ETSI EN 303 645 Guide
Separate the three binding UK PSTI requirements from the broader ETSI EN 303 645 baseline and use ETSI evidence only where it actually supports the corresponding UK condition.
UK PSTI Product Security PSTI vs EU Cyber Resilience Act Guide
Compare UK PSTI with the EU Cyber Resilience Act across territorial scope, covered products, actor roles, security lifecycle, conformity, vulnerability reporting, support periods, and transition dates.
UK PSTI Product Security Requirements Guide
Read the three binding Schedule 1 requirements together with the role, statement, records, investigation, remediation, and notification duties that surround them.
UK PSTI Product Security Supply Chain Roles Manufacturer Importer Distributor Guide
Distinguish manufacturer, importer, distributor, and authorised-representative duties per product and supply route, including rebranding, imports, statement checks, stop-supply decisions, and compliance failures.
UK PSTI Product Security Support Period Evidence Workflow Guide
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
UK PSTI vs Australia Cyber Security Act Guide
Compare the UK and Australian connected-product regimes by product scope, actor duties, security standards, statements, commencement, evidence, and enforcement rather than assuming one file satisfies both.
What should teams do about Default Passwords under UK PSTI Product Security?
No: PSTI does not merely ban one shared factory password. Relevant passwords must be user-defined or unique per product, and unique credentials must not be incremental, publicly derived, identifier-derived without accepted protection, or otherwise easily guessable.
What should teams do about ETSI Evidence under UK PSTI Product Security?
ETSI EN 303 645 and TS 103 701 can structure technical evidence, but only mapped provisions support the three UK requirements; the wider ETSI baseline is not automatically binding under PSTI.
What should teams do about Excepted Products under UK PSTI Product Security?
An internet- or network-connectable product is outside the relevant-product definition only when a current Schedule 3 exception applies; record the exact category and facts rather than relying on a broad sector label.
What should teams do about Importer and Distributor Duties under UK PSTI Product Security?
Importers and distributors have their own statement checks, stop-supply, investigation, notification, remediation, and record duties; a manufacturer assurance does not replace those decisions.
What should teams do about OPSS Notices under UK PSTI Product Security?
OPSS can use compliance, stop, and recall notices alongside monetary and other measures; notice recipients should preserve the notice, product scope, supply records, corrective actions, representations, and appeal dates.
What should teams do about Relevant Connectable Products under UK PSTI Product Security?
A product is relevant when it is internet-connectable or network-connectable and not excepted, then the UK consumer-use and supply facts determine whether the Part 1 duties engage.
What should teams do about Statement Of Compliance under UK PSTI Product Security?
A statement must contain the prescribed information and accompany the product unless a current deemed-compliance route applies; digital accompaniment can be possible, but the business must prove its method meets the Act.
What should teams do about Support Periods under UK PSTI Product Security?
PSTI does not prescribe a universal minimum number of support years. The manufacturer sets and publishes a product-specific minimum period and end date; preserve the published commitment and assess any later change against the current Regulations.
What should teams do about Update Transparency under UK PSTI Product Security?
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in language understandable without technical knowledge.
What should teams do about Vulnerability Disclosure under UK PSTI Product Security?
Publish a clear reporting route plus expected acknowledgement and status-update times. PSTI requires the information and timescales to be available; it does not prescribe one universal response deadline for every report.