The statement of compliance
The statement of compliance is a formal declaration by the manufacturer that a connectable or internet-connectable product meets the security requirements mandated by the UK Product Security and Telecommunications Infrastructure (PSTI) Act 2022. It serves as legal confirmation that the product has been assessed and conforms to the law before being placed on the Great Britain market.
What it means
In practice, this is a "declaration of conformity" focused specifically on security. Rather than just claiming a product is "secure," the manufacturer must explicitly state that it complies with the specific legal obligations set out in the PSTI legislation.
The intent is to create accountability. By signing and issuing a statement of compliance, the organization takes legal responsibility for the product's security posture. It ensures that there is a documented bridge between the technical implementation of security controls and the legal requirement to provide them.
This applies to any organization acting as the manufacturer or the entity placing the product on the UK market (including importers). The statement must be accurate at the time of placement and maintained throughout the product's lifecycle.
How to meet it
- Perform a comprehensive gap analysis between your current product security features and the PSTI requirements (e.g., password defaults, vulnerability disclosure, and software update transparency).
- Create a technical file that documents how each specific requirement of the Act has been implemented in the hardware and software.
- Develop a formal Statement of Compliance document that explicitly references the UK Product Security and Telecommunications Infrastructure Act 2022.
- Ensure the statement is signed by an authorized representative or senior officer within the organization who holds accountability for product compliance.
- Integrate the issuance of this statement into your "Definition of Done" or final release gate in the product development lifecycle to ensure no product ships without one.
Evidence an auditor asks for
- The finalized, signed Statement of Compliance document associated with the specific product model and version.
- A traceability matrix linking each PSTI requirement to a corresponding technical feature or configuration in the product.
- Verification reports or test logs (internal or third-party) proving that the security controls claimed in the statement actually function as intended.
- Records showing where the statement is stored or how it is made available to regulators upon request.
Common pitfalls
- Signing the statement as a formality before technical testing is complete, leading to legal exposure if vulnerabilities are discovered later.
- Using generic "Security Declarations" or marketing brochures instead of a formal document that specifically cites the PSTI Act 2022.
- Failing to version-control the statement when significant firmware updates change how security requirements (such as update mechanisms) are handled.