Product Security and Telecommunications Infrastructure (Product Security) regime
Consumer connectable products sold in the UK: no universal default passwords, a published vulnerability disclosure policy, a stated minimum period of security updates, and a statement of compliance that must accompany the product. In force since April 2024 and enforced by the Office for Product Safety and Standards.
named This regime is named, not quoted: what it covers and the documents it expects are described in our own words, and no requirement text is reproduced. On the sheet its chip is outlined; a product whose regimes are all named stands as reference.
What it expects in the file
- Declaration of conformity
The EU or UK declaration of conformity (or the food-contact declaration of compliance), signed by the manufacturer, naming the product, the legislation and the standards, and the notified or approved body where one was involved. - Cybersecurity documentation
The software bill of materials, the vulnerability handling and disclosure policy, the stated support period, and the secure update mechanism, as the connected-product rules expect. - Labelling and instructions
Markings on the product and packaging (conformity mark, identification, warnings, manufacturer and importer details) and the instructions and safety information in the language of the market.
Duties that continue after sale
- Security updates and vulnerability handling
Provide security updates for the stated support period, run a coordinated vulnerability disclosure process, and report actively exploited vulnerabilities and severe incidents within the reporting clock.
Product categories that engage it
See which of your products engage it
Paste the list and every product that engages UK PSTI in the markets you sell to shows it as a chip, with the documents it expects ticked against what you hold. Five products free, no account.
Build my conformity sheet