The UK PSTI regime: what it asks of a product list
The UK regime for relevant connectable products made available to UK consumers: no universal default passwords, a published point of contact for security issues, a published defined support period, and a statement of compliance that travels with the product; importers and distributors check it. A product sold only to businesses is outside it.
Duties by role
| Role | Clauses |
|---|---|
| manufacturer | UK PSTI M.8 Duty to comply with security requirements UK PSTI M.9 Statement of compliance and its retention UK PSTI R.1 No universal default passwords UK PSTI R.2 Published point of contact for security issues UK PSTI R.3 Published defined support period |
| importer | UK PSTI I.14 Importer duty to comply with security requirements UK PSTI I.15 Importer statement of compliance checks and retention |
| distributor | UK PSTI D.21 Distributor duty to comply with security requirements UK PSTI D.22 Distributor statement of compliance check |
| own brand (becomes the manufacturer) | UK PSTI M.8 Duty to comply with security requirements UK PSTI M.9 Statement of compliance and its retention UK PSTI R.1 No universal default passwords UK PSTI R.2 Published point of contact for security issues UK PSTI R.3 Published defined support period |
Notes that cite it
| Note | Clause |
|---|---|
| 5. No support period stated, or under five years with no reason recorded | UK PSTI R.3 |
| 6. A universal default password | UK PSTI R.1 UK PSTI R.D |
| 7. No published vulnerability contact | UK PSTI R.2 |
| 10. Sold to UK consumers with no statement of compliance | UK PSTI M.9 UK PSTI I.15 UK PSTI D.22 |
UK PSTI: every clause cited
10 of the 22 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
UK PSTI D.21Distributor duty to comply with security requirementsA distributor of a relevant connectable product intended, known or foreseeably to be a UK consumer connectable product complies with the security requirements that apply to distributors.
UK PSTI D.22Distributor statement of compliance checkA distributor makes the product available only with a statement of compliance (or summary), or where the JC-STAR or Singapore route is used, only once satisfied the conditions are met.
UK PSTI I.14Importer duty to comply with security requirementsAn importer of a relevant connectable product intended, known or foreseeably to be a UK consumer connectable product complies with the security requirements that apply to importers.
UK PSTI I.15Importer statement of compliance checks and retentionAn importer makes the product available only with a statement of compliance (or summary) and keeps a copy for the longer of 10 years and the support period; where the manufacturer relies on the JC-STAR or Singapore deemed-compliance route for the statement, the importer must be satisfied that the conditions are met.
UK PSTI M.8Duty to comply with security requirementsA manufacturer of a relevant connectable product that it intends, knows or ought to know will be a UK consumer connectable product complies with the security requirements; where there are several manufacturers each meets them or the deemed-compliance conditions.
UK PSTI M.9Statement of compliance and its retentionThe product is not made available in the UK unless accompanied by a statement of compliance (or permitted summary) prepared by or for the manufacturer stating it has met the applicable requirements, containing product type and batch, each manufacturer's and authorised representative's name and address, the manufacturer's declaration, the requirements or deemed-compliance conditions relied on (with standard number, version and date), the defined support period, signatory details, and place and date of issue; the manufacturer keeps a copy for the longer of 10 years and the support period.
UK PSTI R.1No universal default passwordsFor product hardware (outside the factory default state), pre-installed software and software that must be installed for the product's intended purposes, any password is unique per product or set by the user; unique passwords are not based on incremental counters, public information, or product identifiers such as serial numbers (unless derived by encryption or keyed hashing accepted as good industry practice), nor otherwise guessable; cryptographic keys, pairing PINs for non-IP protocols and API keys are not treated as passwords.
UK PSTI R.2Published point of contact for security issuesFor the product's hardware and software (including companion apps and cloud software used for the intended purpose, except for cellular smartphones and tablets), the manufacturer publishes at least one point of contact for reporting security issues across its relevant products, and when the reporter will receive an acknowledgement and status updates until resolution; the information is accessible, clear and transparent, available without request, in English, free and without requiring personal information.
UK PSTI R.3Published defined support periodFor hardware and software capable of receiving security updates, the manufacturer publishes the defined support period (minimum time, with an end date, for security updates), publishes any extension as soon as practicable, makes it accessible, clear, free, in English, without request or personal data and understandable without technical knowledge, shows it with equal prominence alongside the main product information where it invites purchase on its own or controlled free websites, and never shortens it after publication.
UK PSTI R.DDeemed compliance routesA manufacturer is treated as meeting a security requirement if it meets the corresponding deemed-compliance condition: ETSI EN 303 645 V2.1.1 provisions 5.1-1 (and 5.1-2) for passwords, 5.2-1 or ISO/IEC 29147:2018 paragraphs 6.2.2, 6.2.5 and 6.5 (publishing how to access the reporting mechanism and when acknowledgement and ongoing communication follow) for reporting, and 5.3-13 for the support period; or, since 4 December 2025, the product holds an unexpired Japan JC-STAR STAR-1 label or a label at any level of the Singapore Cybersecurity Labelling Scheme.