Auditen
Home / Frameworks / UK PSTI / Duties on manufacturers, importers and distributors

Duties on manufacturers, importers and distributors

The PSTI Act mandates that manufacturers, importers, and distributors ensure connectable and internet-connectable products meet specific security requirements before they are placed on the UK market. It establishes a chain of responsibility, meaning each party must verify compliance to prevent insecure devices from reaching consumers.

What it means

In practice, this requirement extends legal liability beyond the original manufacturer. If an organization imports a product into the UK or distributes it, they cannot simply rely on the manufacturer's word; they have a duty to ensure the product adheres to the security standards set by the government (such as those regarding default passwords and vulnerability disclosure).

The scope covers any "connectable" product—devices that can connect to other devices or networks. The intent is to create multiple checkpoints in the supply chain, ensuring that non-compliant hardware is identified and blocked before it reaches the end user.

How to meet it

Evidence an auditor asks for

  • Compliance Declarations: Signed attestations or certificates of conformity from the manufacturer confirming all PSTI requirements are met.
  • Due Diligence Records: Documentation showing the vetting process used to verify a supplier's security posture before onboarding them.
  • Technical Files: Product specifications and documentation proving that default password requirements have been removed or randomized.
  • Supply Chain Agreements: Contracts that explicitly outline the responsibilities of each party regarding PSTI compliance and vulnerability reporting.

Common pitfalls

  • The "Manufacturer Assumption": Importers often wrongly assume that only the original manufacturer is liable, failing to realize that importing a non-compliant product into the UK makes them legally responsible.
  • Lack of Written Proof: Relying on verbal assurances or generic emails from suppliers rather than formal compliance declarations.
  • Ignoring White-Label Goods: Failing to apply these checks to "white label" products where the brand name on the box differs from the actual entity that designed and manufactured the device.