- Operational implementation support for Security Requirements In Practice.
"OPSS enforces the above legislation."
Turn the password, vulnerability-reporting, and update-period rules into product requirements, release tests, public information, approvals, and change-controlled evidence.
The guide separates binding duties from OPSS guidance, ETSI good practice, internal controls, and the limited deemed-compliance routes introduced in 2025.
Structured answer sets in this page tree.
Cited legal and guidance references.
This page explains the UK PSTI security requirements in plain terms. First classify the relevant connectable product and apply the Act's UK-consumer and manufacturer trigger; then turn the applicable 2023 Regulations requirements into release evidence before the product is made available in the United Kingdom.
Start by checking whether the product is a relevant connectable product and whether the team is acting as a manufacturer, importer, distributor, or authorised representative. The main practical question is whether the product and business role are in scope, and if so, what the team must do to comply.
For in-scope products, the core security requirements are straightforward: ban universal default and easily guessable passwords, publish information on how to report security issues, and publish information on the minimum security update period. Keep the legal source, product-scope decision, role, required action, owner, evidence, and escalation point together so the decision is reviewable.
Ownership should sit with the team that controls product design, supply-chain placement, importer/distributor checks, or customer security information, with legal and product-security review.
Evidence should show relevant-connectable-product scope, default-password controls, vulnerability disclosure channel, minimum support period, statement of compliance, supply-chain role checks, and OPSS notice response readiness.
Most PSTI mistakes happen at the boundary between manufacturer, importer and distributor duties, excepted products, bundled products, support-period statements, and evidence that does not match the shipped product.
Review this section before UK market placement, importer onboarding, distributor acceptance, or support-period publication so the evidence matches the actual product and supply-chain role.
Use a compact PSTI workflow that captures product scope, role, password control, vulnerability disclosure route, support-period information, statement-of-compliance approval, and OPSS escalation path.
The output should be a product-scope note, statement-of-compliance pack, supplier attestation, customer-facing support-period notice, or OPSS response record.
This UK PSTI Product Security guide helps turn Security Requirements In Practice into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Turn Security Requirements In Practice into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"OPSS enforces the above legislation."
"This document provides guidance on regulatory activities, enforcement, and related resources for the Product Security and Telecommunications Infrastructure"
"The government has been working with the tech industry to better secure consumer connectable products for several years"
"These Regulations create security requirements for manufacturers of relevant connectable products"
"This is a UK government guidance page about the PSTI Product Security regime and compliance requirements"