- OPSS guidance explains compliance failures, investigations, notifications, notices, penalties, representations, and appeals.
References and citations
- ETSI EN 303 645 V2.1.1 is the edition named in the Regulations for specified deemed-compliance conditions; its wider provisions are not all UK statutory requirements.
- Part 1 defines product and actor scope, statements, investigations, remediation, notifications, records, and enforcement.
- The current consolidated Regulations contain the detailed password, vulnerability-reporting, update-period, statement, deemed-compliance, and exception rules.
- OPSS and DSIT guidance explains the regime, covered actors and products, the three requirements, statement accompaniment, and enforcement authority.