UK PSTI workflowUK PSTIStatement Of Compliance Workflow
UK PSTI Statement of Compliance Workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
The guide separates binding duties from OPSS guidance, ETSI good practice, internal controls, and the limited deemed-compliance routes introduced in 2025.
Complete the route decision before drafting. Under the ordinary route, the manufacturer prepares the Schedule 4 statement and ensures it accompanies the product; importers and distributors perform their own checks before supply. From 4 December 2025, can treat the manufacturer as satisfying the accompaniment duty when the exact product meets a current Japan JC-STAR STAR-1 or Singapore Cybersecurity Labelling Scheme condition in the Regulations. That alternative does not remove the security requirements or other actor-specific PSTI duties.
1
Section 1
1. Confirm scope, trigger, and route
Confirm that the item is a relevant connectable product and apply the section 9 condition for the manufacturer. Record the product, batch, intended UK consumer supply, first-supply date, manufacturer, import route, distributor, and any exception.
Choose one documented route. Use the ordinary route unless the exact product meets every condition, including the applicable scheme, product coverage, label level where relevant, and current validity. A certificate for a component, related model, manufacturer, or former version does not establish the product condition.
For Japan, map the evidence to the JC-STAR STAR-1 scheme based on JST-CR-01-01-2024R1 (December 2024). For Singapore, map it to the Cybersecurity Labelling Scheme specification CCC SP-151-2 version 1.4 (April 2025). Record the scheme evidence named by the Regulations rather than relying on a generic cyber label.
Ordinary route output: a controlled Schedule 4 statement, its supporting evidence, and proof of accompaniment.
output: scheme, label identifier and level where applicable, covered product identifier, issue and expiry evidence, verification date, and monitoring owner.
Stop the workflow if product scope, label coverage, label validity, or actor identity cannot be established.
Complete all Schedule 4 fields: product type and batch; each manufacturer's name and address; each applicable authorised representative; a declaration that the statement was prepared by or on behalf of the manufacturer; compliance-basis declaration; the defined support period correct at first supply; signatory signature, name and function; and place and date of issue. Add the specified standard's identifier, version, and issue date where Schedule 2 reliance requires it. Schedule 4 prescribes this minimum information but no official form.
Link the statement to release-specific password, vulnerability-reporting, and support-period evidence.
Check that the defined support period and end date match the published customer information and the product first supplied.
Confirm the signatory can act for the manufacturer and that every listed entity and product identifier is current.
Approve the exact issued file and preserve its version before it enters the supply chain.
For the ordinary route, test how the statement accompanies the product. GOV.UK says it may be digital because the Act does not require a physical document, but each business must determine whether its method meets the legal requirement for its product. Record the customer path to the exact statement.
The importer verifies the applicable statement route before supply and, under the ordinary route, retains the statement. The distributor also verifies the route before supply. Manufacturer and importer retention under regulations 8 and 9 is the longer of 10 years from issue or the defined support period stated in the statement. Calculate both dates and record the later one.
Block release if the statement is missing, mismatched, unsigned, incomplete, inaccessible, or tied to the wrong type or batch.
For , recheck product coverage, scheme conditions, label level where relevant, and expiry before each controlled supply decision and preserve the verification result.
Reassess after a new model or batch, rebranding, manufacturer change, material firmware change, support-period change, expired scheme label, or compliance failure.
Keep the issued statement, delivery evidence, importer receipt, verification records, and retention deadline together.
Turn UK PSTI Product Security Statement Of Compliance Workflow into assigned work
This UK PSTI Product Security guide helps turn Statement Of Compliance Workflow into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.