Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04

The UK PSTI regime: what it asks of a product list

The UK regime for relevant connectable products made available to UK consumers: no universal default passwords, a published point of contact for security issues, a published defined support period, and a statement of compliance that travels with the product; importers and distributors check it. A product sold only to businesses is outside it.

Duties by role

RoleClauses
manufacturerUK PSTI M.8 Duty to comply with security requirements
UK PSTI M.9 Statement of compliance and its retention
UK PSTI R.1 No universal default passwords
UK PSTI R.2 Published point of contact for security issues
UK PSTI R.3 Published defined support period
importerUK PSTI I.14 Importer duty to comply with security requirements
UK PSTI I.15 Importer statement of compliance checks and retention
distributorUK PSTI D.21 Distributor duty to comply with security requirements
UK PSTI D.22 Distributor statement of compliance check
own brand (becomes the manufacturer)UK PSTI M.8 Duty to comply with security requirements
UK PSTI M.9 Statement of compliance and its retention
UK PSTI R.1 No universal default passwords
UK PSTI R.2 Published point of contact for security issues
UK PSTI R.3 Published defined support period

Notes that cite it

NoteClause
5. No support period stated, or under five years with no reason recordedUK PSTI R.3
6. A universal default passwordUK PSTI R.1
UK PSTI R.D
7. No published vulnerability contactUK PSTI R.2
10. Sold to UK consumers with no statement of complianceUK PSTI M.9
UK PSTI I.15
UK PSTI D.22

UK PSTI: every clause cited

10 of the 22 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

UK PSTI D.21Distributor duty to comply with security requirements

A distributor of a relevant connectable product intended, known or foreseeably to be a UK consumer connectable product complies with the security requirements that apply to distributors.

What a notified body or authority asks to see: Distributor compliance procedure
Where lists usually fall short: Marketplace resellers unaware of the regime
Source: UK PSTI regime (Product Security and Telecommunications Infrastructure Act and the security requirements regulations)
UK PSTI D.22Distributor statement of compliance check

A distributor makes the product available only with a statement of compliance (or summary), or where the JC-STAR or Singapore route is used, only once satisfied the conditions are met.

What a notified body or authority asks to see: Statement checks at goods-in or listing
Where lists usually fall short: Online listings with no statement available
Source: UK PSTI regime (Product Security and Telecommunications Infrastructure Act and the security requirements regulations)
UK PSTI I.14Importer duty to comply with security requirements

An importer of a relevant connectable product intended, known or foreseeably to be a UK consumer connectable product complies with the security requirements that apply to importers.

What a notified body or authority asks to see: Importer compliance checks
Where lists usually fall short: Importer assumes the manufacturer covers everything
Source: UK PSTI regime (Product Security and Telecommunications Infrastructure Act and the security requirements regulations)
UK PSTI I.15Importer statement of compliance checks and retention

An importer makes the product available only with a statement of compliance (or summary) and keeps a copy for the longer of 10 years and the support period; where the manufacturer relies on the JC-STAR or Singapore deemed-compliance route for the statement, the importer must be satisfied that the conditions are met.

What a notified body or authority asks to see: Statements of compliance on file per imported product; Label verification for deemed-compliance products
Where lists usually fall short: Imported stock without statements
Source: UK PSTI regime (Product Security and Telecommunications Infrastructure Act and the security requirements regulations)
UK PSTI M.8Duty to comply with security requirements

A manufacturer of a relevant connectable product that it intends, knows or ought to know will be a UK consumer connectable product complies with the security requirements; where there are several manufacturers each meets them or the deemed-compliance conditions.

What a notified body or authority asks to see: Compliance file per product; Assessment against Schedule 1
Where lists usually fall short: Private-label products with no manufacturer taking responsibility
Source: UK PSTI regime (Product Security and Telecommunications Infrastructure Act and the security requirements regulations)
UK PSTI M.9Statement of compliance and its retention

The product is not made available in the UK unless accompanied by a statement of compliance (or permitted summary) prepared by or for the manufacturer stating it has met the applicable requirements, containing product type and batch, each manufacturer's and authorised representative's name and address, the manufacturer's declaration, the requirements or deemed-compliance conditions relied on (with standard number, version and date), the defined support period, signatory details, and place and date of issue; the manufacturer keeps a copy for the longer of 10 years and the support period.

What a notified body or authority asks to see: Signed statements of compliance; Distribution with the product (packaging or insert); Retention records
Where lists usually fall short: Statement missing batch or support period; Standard cited without version and date
Source: UK PSTI regime (Product Security and Telecommunications Infrastructure Act and the security requirements regulations)
UK PSTI R.1No universal default passwords

For product hardware (outside the factory default state), pre-installed software and software that must be installed for the product's intended purposes, any password is unique per product or set by the user; unique passwords are not based on incremental counters, public information, or product identifiers such as serial numbers (unless derived by encryption or keyed hashing accepted as good industry practice), nor otherwise guessable; cryptographic keys, pairing PINs for non-IP protocols and API keys are not treated as passwords.

What a notified body or authority asks to see: Password generation design; Factory provisioning records; Test evidence that no default credential is shared
Where lists usually fall short: Same admin password across a product line; Password derived from the MAC address without a keyed hash
Source: UK PSTI regime (Product Security and Telecommunications Infrastructure Act and the security requirements regulations)
UK PSTI R.2Published point of contact for security issues

For the product's hardware and software (including companion apps and cloud software used for the intended purpose, except for cellular smartphones and tablets), the manufacturer publishes at least one point of contact for reporting security issues across its relevant products, and when the reporter will receive an acknowledgement and status updates until resolution; the information is accessible, clear and transparent, available without request, in English, free and without requiring personal information.

What a notified body or authority asks to see: Published vulnerability disclosure policy; Security contact channel; Acknowledgement and update timelines
Where lists usually fall short: Contact only reachable after creating an account; Policy silent on when reporters hear back
Source: UK PSTI regime (Product Security and Telecommunications Infrastructure Act and the security requirements regulations)
UK PSTI R.3Published defined support period

For hardware and software capable of receiving security updates, the manufacturer publishes the defined support period (minimum time, with an end date, for security updates), publishes any extension as soon as practicable, makes it accessible, clear, free, in English, without request or personal data and understandable without technical knowledge, shows it with equal prominence alongside the main product information where it invites purchase on its own or controlled free websites, and never shortens it after publication.

What a notified body or authority asks to see: Published support period with end date; Product web pages showing the period; Update policy
Where lists usually fall short: Support period expressed as 'lifetime' with no end date; Period missing from product listing pages
Source: UK PSTI regime (Product Security and Telecommunications Infrastructure Act and the security requirements regulations)
UK PSTI R.DDeemed compliance routes

A manufacturer is treated as meeting a security requirement if it meets the corresponding deemed-compliance condition: ETSI EN 303 645 V2.1.1 provisions 5.1-1 (and 5.1-2) for passwords, 5.2-1 or ISO/IEC 29147:2018 paragraphs 6.2.2, 6.2.5 and 6.5 (publishing how to access the reporting mechanism and when acknowledgement and ongoing communication follow) for reporting, and 5.3-13 for the support period; or, since 4 December 2025, the product holds an unexpired Japan JC-STAR STAR-1 label or a label at any level of the Singapore Cybersecurity Labelling Scheme.

What a notified body or authority asks to see: Mapping of each requirement to the chosen route; Test reports against ETSI EN 303 645; JC-STAR or Singapore CLS label certificates
Where lists usually fall short: Claiming the later ETSI edition when the regulations cite V2.1.1; Expired foreign label relied on
Source: UK PSTI regime (Product Security and Telecommunications Infrastructure Act and the security requirements regulations)