Skip to content

Evidence request lists

UK Product Security and Telecommunications Infrastructure Act (PSTI)

Evidence request list. 35 controls, 35 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Default Passwords

UKPSTIACT-1
Default Password Prohibition

Per UK PSTI Act + Regulations 2023: Prohibition of Universal Default Passwords + unique per device or user-set passwords for connectable products.

Artefacts an auditor will ask for
  • PSTI evidence for UKPSTIACT-1
Where this commonly fails
  • defaults + VDP + support period partial

Distribution and Enforcement

UKPSTIACT-4
Distributor, Importer, Retailer Duties + Enforcement

Per PSTI: distributor + importer + retailer due diligence + enforcement including civil penalties + product recall.

Artefacts an auditor will ask for
  • PSTI evidence for UKPSTIACT-4
Where this commonly fails
  • defaults + VDP + support period partial

Economic Operator Duties

PSTI-06
Importer Duties

Importers must check that products bear or are accompanied by a statement of compliance, that the manufacturer has met security requirements, and must keep records and act on non-compliance.

Artefacts an auditor will ask for
  • Importer compliance check procedure
  • SoC archive
  • Non-compliance investigations
  • Records retained for required period
Where this commonly fails
  • Importer relies on manufacturer assurances without verification
  • No archive of SoCs
  • No process to halt supply on non-compliance
PSTI-07
Distributor Duties

Distributors (including online marketplaces in scope) must verify that products have the required SoC and that manufacturers and importers appear to have complied, and must take corrective action if not.

Artefacts an auditor will ask for
  • Distributor compliance checklist
  • Sample audit records
  • Removal records for non-compliant products
  • Communications to manufacturers
Where this commonly fails
  • No SKU level verification
  • Marketplaces relying solely on seller self-attestation
  • No takedown when non-compliance found
PSTI-15
Authorised Representative for Non-UK Manufacturers

Manufacturers established outside the United Kingdom should ensure a UK responsible person or compliant supply chain entity can act in their place for PSTI obligations.

Artefacts an auditor will ask for
  • Authorised representative appointment
  • Contractual responsibilities
  • Contact details on SoC and packaging
  • OPSS notification of representative
Where this commonly fails
  • No UK responsible person
  • Importer treated as manufacturer without contract
  • Inconsistent contact details across products
PSTI-16
Marketplace and Online Listing Compliance

Online marketplaces that fulfil a distributor role under PSTI must ensure listings for in-scope products are supported by a valid SoC and that non-compliant listings are removed.

Artefacts an auditor will ask for
  • Marketplace policy
  • Seller onboarding checks
  • Automated scanning of listings
  • Takedown logs
Where this commonly fails
  • No verification of seller SoC
  • No automated detection of non-compliance
  • Slow takedown of flagged listings
PSTI-19
Supplier and Component Security Assurance

Manufacturers should obtain security assurance from suppliers of chipsets, modules and third party firmware components used in connectable products.

Artefacts an auditor will ask for
  • Supplier security questionnaires
  • SBOMs for shipped firmware
  • Component vulnerability monitoring
  • Contractual security clauses
Where this commonly fails
  • No SBOM for product firmware
  • No vulnerability monitoring on third party modules
  • Contracts silent on PSTI obligations
PSTI-3.3
Authorised Representative Designation

Manufacturers established outside the UK that supply relevant products to UK consumers may appoint an authorised representative, who must be empowered to act and maintain documentation on the manufacturer's behalf.

Artefacts an auditor will ask for
  • Written mandate between manufacturer and representative
  • Representative contact details on file
  • Document access arrangement
  • Renewal schedule for the mandate
Where this commonly fails
  • Mandate verbal only
  • Representative cannot produce statements of compliance
  • No backup arrangement if representative ceases
PSTI-3.4
Online Marketplace Operator Duties

Online marketplaces facilitating the sale of relevant products to UK consumers must take reasonable steps to ensure listings comply with security requirements and respond to enforcement requests.

Artefacts an auditor will ask for
  • Seller onboarding checks
  • Automated listing screening rules
  • Takedown procedure and SLA
  • Reporting channel for enforcement notices
Where this commonly fails
  • No proactive screening of new listings
  • Takedown takes weeks
  • Repeat sellers not blocked after multiple violations

Enforcement and Compliance Management

PSTI-09
Compliance Failure Notification

Manufacturers, importers and distributors must notify OPSS when they become aware that a relevant connectable product they have made available has failed to comply with a security requirement, and take action to address the failure.

Artefacts an auditor will ask for
  • Notification procedure
  • OPSS notifications register
  • Root cause analysis
  • Customer communications
Where this commonly fails
  • No definition of when awareness is triggered
  • Late notification
  • No customer notification where appropriate
PSTI-17
Penalty and Enforcement Readiness

Manufacturers, importers and distributors should be prepared for OPSS enforcement, including information notices, compliance notices, stop notices, recall notices and civil monetary penalties up to GBP 10 million or 4 percent of global turnover.

Artefacts an auditor will ask for
  • Regulatory liaison plan
  • Internal escalation matrix
  • Response templates for OPSS notices
  • Penalty risk modelling
Where this commonly fails
  • No regulatory point of contact
  • No internal process to handle notices
  • No financial provisioning for penalties
PSTI-2.1
Non-Compliance Investigation Cooperation

Relevant persons must cooperate with the enforcement authority during investigations, including providing requested information, samples, and access to premises where products are held.

Artefacts an auditor will ask for
  • Investigation response playbook
  • Designated single point of contact for OPSS
  • Legal hold notice template
  • Records location index
Where this commonly fails
  • No SPOC named for regulator contact
  • Records dispersed across systems with no index
  • Slow response to information notices
PSTI-2.2
Compliance Notice Remediation

Where the enforcement authority issues a compliance notice, the relevant person must take the steps specified within the period stated to remedy the non-compliance.

Artefacts an auditor will ask for
  • Remediation project plan
  • Customer notification letters
  • Post-remediation conformity evidence
  • Regulator response file
Where this commonly fails
  • Customers not notified of corrected products
  • No verification of effectiveness
  • Remediation deadline missed without extension request
PSTI-2.3
Stop Notice and Recall Execution

Where a stop notice or recall notice is issued, the relevant person must cease the relevant activity and execute any recall as specified, maintaining records of actions taken.

Artefacts an auditor will ask for
  • Product recall procedure
  • Inventory hold logs
  • Customer recall communications
  • Returns reconciliation report
Where this commonly fails
  • Slow channel notification
  • No tracking of returned units versus units sold
  • Recall communications buried in marketing emails
PSTI-20
Periodic Compliance Review and Continuous Improvement

Organisations should review PSTI compliance regularly across the product portfolio, incorporating findings from incidents, audits and regulator engagement.

Artefacts an auditor will ask for
  • Annual compliance review
  • Audit findings tracker
  • Lessons learned register
  • Board reporting
Where this commonly fails
  • Compliance assumed not measured
  • No tracker for audit findings
  • Reviews not reported to board
PSTI-3.6
Public Reporting of Compliance Failures

Manufacturers should publicly notify customers and registered users when a security flaw materially affects compliance with the requirements, with clear instructions on what action to take.

Artefacts an auditor will ask for
  • Security advisory template
  • Communications channel inventory
  • Plain language review record
  • Acknowledgement and response statistics
Where this commonly fails
  • Advisory hidden in technical bulletin format
  • Email channel only with no in-product notice
  • No follow-up if user has not actioned the advisory
PSTI-3.7
Penalty Awareness and Provisioning

Organisations should account for the financial penalties available under the PSTI regime (up to GBP 10 million or 4 percent of worldwide revenue) in their compliance governance and risk reporting.

Artefacts an auditor will ask for
  • Risk register entry quantifying PSTI penalty exposure
  • Board paper covering the regime
  • Insurance review noting regulatory fines exclusions
  • Compliance committee minutes
Where this commonly fails
  • No board awareness of the regime
  • Risk register lacks quantified exposure
  • Compliance treated only as operational

Scope and Excepted Products

PSTI-01
Scope and Relevant Connectable Product Identification

Manufacturers, importers and distributors must determine whether their products are relevant connectable products under Part 1 of the PSTI Act 2022 and associated regulations, effective from 29 April 2024.

Artefacts an auditor will ask for
  • Product scoping memorandum
  • Connectivity assessment per SKU
  • Schedule of in-scope and out-of-scope products
  • Legal opinion on exemptions
Where this commonly fails
  • Products misclassified as out of scope
  • No reassessment after firmware change adds connectivity
  • B2B carve-out applied without evidence
PSTI-3.2
Excepted Products Determination

Manufacturers must accurately determine whether a product falls within the scope of the security requirements or qualifies as an excepted product under the regulations, with documented rationale.

Artefacts an auditor will ask for
  • Per-SKU scope determination
  • Legal opinion or written rationale for exceptions
  • Product taxonomy mapping to PSTI categories
  • Periodic re-review schedule
Where this commonly fails
  • Scope decided informally without documentation
  • Excepted status not re-reviewed when product changes
  • No legal sign-off on borderline cases

Security Requirements for Connectable Products

PSTI-02
Prohibition of Universal Default Passwords

Manufacturers must not supply products with universal default passwords; passwords must be unique per product or set by the user during initialisation, and meet defined complexity criteria.

Artefacts an auditor will ask for
  • Password provisioning design
  • Manufacturing process records
  • Cryptographic uniqueness evidence
  • User initialisation flow screenshots
Where this commonly fails
  • Same default password across batches
  • Password derived from MAC address or serial number in a guessable way
  • No way to set password before network connection
PSTI-03
Vulnerability Disclosure Policy

Manufacturers must publish information allowing security researchers and others to report vulnerabilities, with a designated point of contact, expected response timelines and information about status updates.

Artefacts an auditor will ask for
  • Public VDP page URL
  • security.txt file
  • Triage SLA records
  • Researcher communication logs
Where this commonly fails
  • No public VDP
  • No response within stated timeframe
  • Researchers threatened with legal action
PSTI-04
Defined Support Period (Minimum Security Update Period)

Manufacturers must publish the minimum length of time during which security updates will be made available for each product, and ensure it is accessible without requiring the user to give personal information.

Artefacts an auditor will ask for
  • Published support periods per SKU
  • Internal roadmap aligned to commitment
  • Update build pipeline records
  • Public website screenshot
Where this commonly fails
  • Support period not published
  • Support period shorter than user expectations or sectoral norms
  • Inconsistent dates across product page, packaging and EU equivalent
PSTI-10
Secure Software Update Delivery

Although not separately mandated in the first three security requirements, manufacturers should deliver software updates over secure channels and verify integrity, in line with ETSI EN 303 645 expectations.

Artefacts an auditor will ask for
  • Code signing key management
  • TLS configuration for update servers
  • OTA update logs
  • Rollback prevention design
Where this commonly fails
  • Updates over HTTP
  • Unsigned firmware images
  • No rollback protection
PSTI-11
Secure Storage of Credentials and Sensitive Data

Manufacturers should ensure credentials, cryptographic keys and other security parameters are stored securely on the device and not in plaintext.

Artefacts an auditor will ask for
  • Secure element / TEE usage records
  • Key storage design
  • Firmware reverse engineering review
  • Threat model
Where this commonly fails
  • Credentials in firmware images
  • Keys hardcoded in source
  • No protection against extraction via debug ports
PSTI-12
Minimisation of Exposed Attack Surfaces

Manufacturers should disable unused interfaces, services and accounts and ensure debug interfaces are not accessible in production.

Artefacts an auditor will ask for
  • Hardening guidelines
  • Port and service scan results on production builds
  • Debug interface removal evidence
  • Threat model for exposed services
Where this commonly fails
  • Telnet or UART accessible
  • Default open ports on LAN
  • Debug builds shipped to customers
PSTI-13
Resilience to Outages

Products should remain functioning and locally usable in the case of a loss of network and re-connect cleanly without exposing users to additional risk.

Artefacts an auditor will ask for
  • Offline mode design
  • Network loss test reports
  • Reconnect security checks
  • Customer documentation
Where this commonly fails
  • No offline functionality
  • Insecure reconnect (no certificate validation)
  • Excessive reconnect attempts amplifying outages
PSTI-14
Personal Data Protection on Device

Where products process personal data, manufacturers must ensure that data is protected in transit and at rest and that users can delete personal data from the device.

Artefacts an auditor will ask for
  • Data protection impact assessment
  • Encryption in transit / at rest evidence
  • Factory reset design
  • Privacy notice
Where this commonly fails
  • Personal data not encrypted at rest
  • Factory reset does not erase all data
  • No DPIA
PSTI-3.5
Software Update Mechanism Security

Where products receive software updates, the update mechanism must validate authenticity and integrity of updates before installation to prevent the device being compromised through the update channel.

Artefacts an auditor will ask for
  • Code signing key management procedure
  • Update verification routine in firmware
  • Anti-rollback protection design
  • Penetration test of update flow
Where this commonly fails
  • Updates downloaded over plain HTTP
  • Signature checked but rollback to vulnerable firmware allowed
  • Signing keys stored without HSM protection
PSTI-3.8
Security Requirements Review on Product Change

When a relevant product undergoes a material change that could affect its security compliance, the manufacturer must re-assess and, where needed, re-issue the Statement of Compliance.

Artefacts an auditor will ask for
  • Engineering change request form including security review
  • Updated Statement of Compliance archive
  • Customer notification of change
  • Version-to-compliance mapping
Where this commonly fails
  • Firmware updates not triggering compliance review
  • No version history tied to compliance statements
  • Material changes treated as minor

Statements of Compliance and Records

PSTI-05
Statement of Compliance

Manufacturers must produce a statement of compliance for each in-scope product before supply, containing the prescribed information, and make it available to distributors and on request to OPSS.

Artefacts an auditor will ask for
  • Statement of compliance per SKU
  • Version control of SoC
  • Translation records (if applicable)
  • Distribution mechanism to importers and distributors
Where this commonly fails
  • Missing prescribed fields
  • SoC not updated when firmware changes affect compliance
  • SoC not shared with all distributors
PSTI-08
Record Keeping

Manufacturers, importers and distributors must keep records of statements of compliance and other prescribed information for at least 10 years (or such period as set by regulations).

Artefacts an auditor will ask for
  • Document retention schedule
  • Archive system
  • Access procedure for OPSS requests
  • Audit trail of changes
Where this commonly fails
  • No central archive
  • Records purged early
  • No procedure to retrieve historical SoCs
PSTI-18
Product Documentation and User Guidance

Manufacturers should provide clear and accessible user documentation including secure configuration steps, update behaviour and end of support implications.

Artefacts an auditor will ask for
  • User manuals
  • Quick start guides referencing security setup
  • End of support notices
  • Translations as required
Where this commonly fails
  • Security setup omitted from documentation
  • End of support not communicated
  • Documentation only in English where required otherwise
PSTI-3.1
Record Keeping for Security Compliance

Relevant persons must keep records that evidence compliance with each applicable security requirement for the periods specified in the regulations, in a form accessible to enforcement.

Artefacts an auditor will ask for
  • Records retention policy
  • Compliance evidence repository
  • Index mapping evidence to security requirements
  • Access logs showing retrieval capability
Where this commonly fails
  • Records held only on individual laptops
  • Retention period below regulatory minimum
  • No mapping between artefact and requirement

Support Period

UKPSTIACT-3
Defined Support Period and Statement of Compliance

Per PSTI: Defined Support Period (Minimum Security Update Period Declaration) + Statement of Compliance + Manufacturer Identification.

Artefacts an auditor will ask for
  • PSTI evidence for UKPSTIACT-3
Where this commonly fails
  • defaults + VDP + support period partial

VDP

UKPSTIACT-2
Vulnerability Disclosure Policy and Reporting

Per PSTI: Vulnerability Disclosure Policy Publication + handling + acknowledgement + statutory contact.

Artefacts an auditor will ask for
  • PSTI evidence for UKPSTIACT-2
Where this commonly fails
  • defaults + VDP + support period partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.