UK / PSTI / Schedule 1
Schedule 1 to the UK Product Security and Telecommunications Infrastructure Regulations 2023 sets out the exact content and manner of three publications: passwords, information on how to report security issues, and information on minimum security update periods.
Last updated 6th October 2026 · By Vas Parshin and Anabel Amar

Schedule 1 to the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 specifies security requirements that apply to manufacturers of relevant connectable products.
Those three duties are passwords, information on how to report security issues, and information on minimum security update periods.
Where more than one manufacturer makes a relevant connectable product, each manufacturer must meet any relevant security requirement specified in Schedule 1 or satisfy the conditions for deemed compliance in relation to that requirement in Schedule 2.
Under Schedule 1 to the UK Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, in force from 29th April 2024, passwords for a relevant connectable product must be unique per product or defined by the user of the product.
A password that is unique per product must not be based on incremental counters, or based on or derived from publicly available information.
It must also not be based on or derived from unique product identifiers, such as serial numbers, unless this is done using an encryption method or a keyed hashing algorithm that is accepted as part of good industry practice.
Nor may it otherwise be guessable in a manner unacceptable as part of good industry practice.
Cryptographic keys, personal identification numbers used for pairing in communication protocols which do not form part of the internet protocol suite, and application programming interface keys are not passwords for the purposes of this requirement.

Manufacturers of relevant connectable products must publish at least one point of contact for reporting security issues, under Schedule 1 to the UK Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, in force from 29th April 2024.
A manufacturer must also publish when a person who reports a security issue will receive an acknowledgment of that report, and when they will receive status updates until the reported security issues are resolved.
This information must be accessible, clear and transparent, and made available without a prior request, in English, free of charge and without asking for the person's personal information.
For a relevant connectable product, the defined support period for security updates must be published, under Schedule 1 to the UK Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, in force from 29th April 2024.
The defined support period means the minimum length of time, expressed as a period of time with an end date, for which security updates will be provided.
If a manufacturer extends that period, the new defined support period must be published as soon as is practicable, and the security requirement is not met if the defined support period is shortened after it has already been published.
Where a manufacturer publishes an invitation to purchase the product on its own website, the defined support period must be published alongside, or given equal prominence to, the information already required under the Consumer Protection from Unfair Trading Regulations 2008, and in a way that is understandable by a reader without prior technical knowledge.
A manufacturer is treated as complying with the password requirement in Schedule 1 where it meets provision 5.1-1 of ETSI EN 303 645, and provision 5.1-2 of that standard where relevant.
A manufacturer is treated as complying with the point of contact requirement where it meets provision 5.2-1 of ETSI EN 303 645, or complies with how a person may access the mechanism to receive reports, when they will receive an acknowledgement of receipt, and when they will receive ongoing communication, each described in paragraphs 6.2.2; 6.2.5; and 6.5 of ISO/IEC 29147.
A manufacturer is treated as complying with the requirement on the defined support period where it meets provision 5.3-13 of ETSI EN 303 645.
Where a statement of compliance is required to make a relevant connectable product available in the United Kingdom, the manufacturer of the product must retain a copy for whichever is the longer of 10 years beginning with the date it was issued, or the product's defined support period.
Where a statement of compliance is required to make a product available in the United Kingdom, the importer of the product must retain a copy for whichever is the longer of 10 years beginning with the date it was issued, or the product's defined support period.
The Secretary of State must from time to time carry out a review of the regulatory provision contained in these Regulations and publish a report setting out the conclusions of the review, with the first report published before the end of five years beginning with the date the Regulations came into force, and subsequent reports published at intervals not exceeding five years.
Most of the gaps we come across are a product that was engineered and tested for a different market, with its password defaults, its point of contact and its update-support wording never checked against what this one asks for in writing.
We check those three publications alongside the rest of a product's paperwork, before it goes on sale in the UK.
Contact usAt least one point of contact so a person can report security issues to the manufacturer, when that person will receive an acknowledgment of their report, and when they will receive status updates until the reported security issues are resolved.
The security requirements are not met if the defined support period is shortened after it has been published, though a manufacturer may extend it to a longer period, which must itself be published as soon as is practicable.
A manufacturer is treated as complying with the password requirement and with the requirement on the defined support period in Schedule 1 where it meets the matching provision of ETSI EN 303 645. For the point of contact requirement, a manufacturer is treated as complying where it meets either ETSI EN 303 645 or the following paragraphs of ISO/IEC 29147.