Auditen
Home / Frameworks / UK PSTI / OPSS enforcement and penalties

OPSS enforcement and penalties

OPSS enforcement and penalties refer to the legal authority of the Office for Product Safety and Standards (OPSS) to police compliance with PSTI security requirements. Organizations that fail to meet these standards or refuse to provide information upon request face significant civil monetary penalties.

What it means

The PSTI Act is not a voluntary framework; it is statutory law. The OPSS acts as the regulator, meaning they have the power to monitor the UK market and investigate products that appear non-compliant with security mandates (such as those regarding default passwords or vulnerability disclosure).

Enforcement focuses on "placing" products on the market. This means anyone who manufactures, imports, or distributes connectable or internet-connectable products in the UK is within scope. If a product is found to be insecure according to the Act's specific requirements, the OPSS can intervene.

Penalties are primarily civil monetary fines. These are designed to be punitive and deterrent, meaning they can scale based on the severity of the breach or the size of the organization. Unlike some standards that require an audit for certification, enforcement here is often triggered by market surveillance or reported vulnerabilities.

How to meet it

Evidence an auditor asks for

  • A comprehensive list of all connectable/internet-connectable products sold in the UK and their corresponding compliance status.
  • Technical documentation proving the removal or randomization of universal default passwords.
  • The published statement on the product's minimum supported security update period.
  • Records of vulnerability assessments and a log showing how identified flaws were patched and deployed to users.
  • Proof of a UK-based authorized representative (for non-UK manufacturers) who is responsible for regulatory correspondence.

Common pitfalls

  • Assuming that compliance with other international standards (like ETSI EN 303 645) automatically grants legal immunity; while they align, the OPSS enforces the specific wording of the UK Act.
  • Neglecting to update security statements when a product's support lifecycle changes, leading to "misleading" claims which can trigger penalties.
  • Failing to treat an OPSS Information Notice as a high-priority legal requirement, resulting in fines for non-cooperation regardless of whether the product itself is secure.