- OPSS enforcement guidance cited for regulator response evidence when support-period records are questioned.
"OPSS is the enforcement authority responsible for ensuring compliance with the legislation."
Support Period Evidence Workflow decisions under UK PSTI Product Security should be written in operational language: who is in scope, what must happen, what evidence proves it, and when escalation is needed.
Use this guide to turn official requirements into scope, evidence, owner, and review decisions. This guidance is practical, source-linked, and should be validated against current legal and policy requirements before implementation.
Structured answer sets in this page tree.
Cited legal and guidance references.
This page explains how to collect and record support-period evidence for UK PSTI Product Security. It shows what evidence to keep, when it is needed, and what a team should produce at the end so the statement of compliance and minimum security update period information are easy to check.
Run the workflow as a simple evidence trail: identify the product, confirm the support-period information that must be published, check the statement of compliance, and keep a clear record that shows who approved the decision and where the evidence is stored.
A useful template captures product identifiers, manufacturer, importer or distributor role, security requirement evidence, support-period wording, statement approver, importer/distributor checks, and review trigger.
Review the workflow after firmware changes, supplier changes, product bundling changes, UK market placement changes, vulnerability reports, OPSS notices, or support-period updates.
Use this UK PSTI Product Security guide to turn Support Period Evidence Workflow into owners, evidence requests, review checkpoints, and reusable operating records inside Sorena.
Turn Support Period Evidence Workflow into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"OPSS is the enforcement authority responsible for ensuring compliance with the legislation."
"- ETSI TR 103 621 (V0.0.6) (2021-06): "CYBER; Guide to Cyber Security for Consumer Internet of Things""
"The government has been working with the tech industry to better secure consumer connectable products for several years"
"publishing information on minimum security update periods"
"The security requirements relate to: banning universal default and easily guessable passwords; publishing information on how to report security issues; publishing information on minimum security update periods."