Duties on manufacturers, importers and distributors
The PSTI Act mandates that manufacturers, importers, and distributors ensure connectable and internet-connectable products meet specific security requirements before they are placed on the UK market. It establishes a chain of responsibility, meaning each party must verify compliance to prevent insecure devices from reaching consumers.
What it means
In practice, this requirement extends legal liability beyond the original manufacturer. If an organization imports a product into the UK or distributes it, they cannot simply rely on the manufacturer's word; they have a duty to ensure the product adheres to the security standards set by the government (such as those regarding default passwords and vulnerability disclosure).
The scope covers any "connectable" product—devices that can connect to other devices or networks. The intent is to create multiple checkpoints in the supply chain, ensuring that non-compliant hardware is identified and blocked before it reaches the end user.
How to meet it
- Conduct Supplier Due Diligence: Manufacturers must implement secure development lifecycles; importers and distributors must vet manufacturers through compliance questionnaires or third-party certifications.
- Verify Technical Compliance: Before importing, confirm that products do not use universal default passwords and that a clear security update policy is documented.
- Establish Contractual Safeguards: Include clauses in supply agreements requiring the manufacturer to certify PSTI compliance and notify the importer/distributor of any discovered vulnerabilities.
- Implement Market Monitoring: Create a process for distributors to identify and remove non-compliant stock from sale if a vulnerability or regulatory breach is identified.
- Ensure Transparency: Verify that the product's packaging or accompanying documentation clearly states the minimum period for security support.
Evidence an auditor asks for
- Compliance Declarations: Signed attestations or certificates of conformity from the manufacturer confirming all PSTI requirements are met.
- Due Diligence Records: Documentation showing the vetting process used to verify a supplier's security posture before onboarding them.
- Technical Files: Product specifications and documentation proving that default password requirements have been removed or randomized.
- Supply Chain Agreements: Contracts that explicitly outline the responsibilities of each party regarding PSTI compliance and vulnerability reporting.
Common pitfalls
- The "Manufacturer Assumption": Importers often wrongly assume that only the original manufacturer is liable, failing to realize that importing a non-compliant product into the UK makes them legally responsible.
- Lack of Written Proof: Relying on verbal assurances or generic emails from suppliers rather than formal compliance declarations.
- Ignoring White-Label Goods: Failing to apply these checks to "white label" products where the brand name on the box differs from the actual entity that designed and manufactured the device.