UK Statutory Instrument SI 2023 United Kingdom

Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023

These Regulations create security requirements for manufacturers of relevant connectable products and set out conditions to be met for deemed compliance of a security requirement as part of the regulatory regime as set out in Part 1 of the Product Security and Telecommunications Infrastructure Act 2022 (c. 46) (“the Act”).

Enforced by
OPSS
Status
In Force
Penalty ceiling
Regulated

Does it bind you?

Business-side roles with duties under this instrument.

Manufacturer6

Other Acts binding the same actors

If a role above is yours, these are the other instruments that most often bind it.

Manufacturer — also bound by 502 other Acts

What it requires

Regulations creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.

s.005 Multiple manufacturers Regulated
  • Comply with security requirements if multiple manufacturers produce the same productManufacturer
s.008 Manufacturer retention of statement of compliance Regulated
  • Retain statement of compliance for 10 years or product support periodManufacturer
s.009 Importer retention of statement of compliance Regulated
  • Keep a copy of your product's statement of complianceManufacturer
8 other provisions — procedural and definitional
s.001 Citation, commencement and extent
s.002 Interpretation
s.003 Security requirements for manufacturers
s.004 Deemed compliance with security requirements
s.004 Deemed compliance with the requirement to have a relevant connectable product accompanied by a statement of compliance
s.006 Excepted products
s.007 Minimum information required for statement of compliance
s.010 Review
Schedules

Schedules

3 of 18 shown
s.sch001 Passwords Regulated
  • Ensure product passwords are unique or user‑set and not easily guessableManufacturer
s.sch001 Information on how to report security issues Regulated
  • Publish a security issue reporting contact and response timelineManufacturer
s.sch004 (1) The statement of compliance must include the following information—... Regulated
  • Include required information in the statement of complianceManufacturer
15 other schedules
s.sch001 Information on minimum security update periods
s.sch002 Passwords
s.sch002 Information on how to report security issues
s.sch002 Information on minimum security update periods
s.sch002a A manufacturer is treated as having complied with the requirement...
s.sch002a Condition A is that the relevant connectable product, of which...
s.sch002a Condition B is that the relevant connectable product, of which...
s.sch003 Products made available to be supplied in Northern Ireland
s.sch003 Charge points for electric vehicles
s.sch003 Medical devices
s.sch003 Smart meter products
s.sch003 Computers
s.sch003 Motor vehicles
s.sch003 Two- or three-wheel vehicles and quadricycles
s.sch003 Agricultural and forestry vehicles

Help complying

Guvnor’s practical routes through this instrument.

Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.