The demand that hasn’t called yet Log in
getfishnet
Test my eligibility

Change your language and country?

You are currently viewing the Switzerland version, in English. Another version may be better suited to your situation.

Stay on this version Change version
Market reading · it cybersecurite

PSTI compliance: which connected-product launch is carrying hidden security debt?

How connected-product suppliers can scope PSTI duties, fix release evidence and build a recurring product-security service in the UK.

getfishnetDocumented analysis20266 min read

A connected device can pass its functional tests, reach a UK distributor and still be missing the security evidence needed to support its sale. Since 29 April 2024, the UK Product Security regime has imposed baseline requirements on relevant consumer connectable products and duties across manufacturers, importers and distributors. The commercial gap is rarely “cybersecurity” in the abstract. It is a specific product family whose default credentials, vulnerability-reporting route, security-update period or statement of compliance cannot survive a release review. That makes the first purchase concrete: test one SKU family and decide whether it is ready, conditionally ready or blocked. This reading explains how to identify the responsible economic actor, build a product-security evidence pack and create an ongoing support-period service. It also shows how acquisition can reach businesses with a live launch or distribution trigger without claiming that a checklist makes a device secure or guarantees regulatory acceptance.

Which connected products fall within the UK Product Security regime?

The Product Security regime covers relevant internet-connectable and network-connectable products made available to UK consumers, subject to statutory exclusions and special cases. Scope depends on connectivity, intended use, customer and product configuration. A product name, tariff code or “professional” label alone cannot establish whether a particular model or bundle is in scope.

A boundary file should describe hardware, software, radio or network functions, intended customer, bundled components and route to market. Variants matter: a non-connected model and its app-enabled sibling may need different conclusions. Uncertainty remains visible until legal or technical ownership resolves it.

Four questions before a connected product reaches the UK marketFour questions before a connected product reaches the UK market
  1. 1Is the product in scope?
  2. 2Which business is manufacturer, importer or distributor?
  3. 3Are the three baseline security requirements evidenced?
  4. 4Does the statement of compliance match the shipped model?

How do manufacturer, importer and distributor duties differ?

Manufacturers carry the core security-requirement and statement duties; importers and distributors must check required documentation and act where they know or ought to know that a product is non-compliant. The statutory role follows what the business actually does, including branding and supply-chain control, rather than the title printed in a commercial agreement.

One company can hold different roles across product lines. The release file therefore maps the brand owner, designer, factory, UK importer, marketplace seller and distributor for each family. Contracts allocate evidence and cooperation, but cannot erase duties created by the real supply chain.

Follow the product, not the job titlesFollow the product, not the job titles
  • Étape 1Manufacturer: designs or markets under its name
  • Étape 2Importer: brings an overseas product into the UK
  • Étape 3Distributor: makes the product available downstream
  • Étape 4Retail or marketplace channel: exposes listing and document gaps

What are the three baseline security requirements?

The baseline requirements address passwords, vulnerability reporting and security updates. Products must not use universal or easily guessable default passwords; manufacturers must publish a route for security-problem reports; and they must publish the minimum period for which security updates will be provided. Each requirement needs product-specific evidence, not a policy statement detached from the shipped build.

Testing should follow activation, reset, recovery, refurbished-device and support states. The vulnerability route must reach a team able to acknowledge and act. The published support period must reconcile with engineering capacity, packaging, web copy and distributor data.

What should a paid PSTI release-gate sprint deliver?

A paid PSTI sprint should define scope and economic roles, test the three baseline controls, reconcile the statement of compliance with the shipped model and issue a release decision with remediation owners. It should focus on one SKU family or launch wave, avoiding an open-ended security programme that buyers cannot price or approve quickly.

The partner begins with product samples, firmware and support information, not a generic questionnaire. It records missing evidence, tests high-consequence states and distinguishes a document correction from engineering work. Where specialist legal interpretation or penetration testing is required, that dependency is named before the product is presented as ready.

What must a statement of compliance prove?

A statement of compliance identifies the product and manufacturer, confirms compliance with the applicable security requirements, records the relevant support period and includes prescribed signatory and date information. It must accompany the product as required and match the version being supplied. A reusable template is useful only when its underlying evidence remains accurate.

The statement index links model identifier, hardware revision, firmware baseline, evidence owner, approval date and distribution markets. A material change should trigger reassessment rather than silent reuse. This gives sales teams a precise answer when a retailer or importer requests assurance.

RequirementProduct evidenceOperational owner
Password designactivation reset and recovery testsengineering
Vulnerability reportingpublished contact and handling workflowsecurity
Update perioddated commitment and release capacityproduct
Statement of complianceapproved model-specific documentcompliance
Supply-chain dutyimporter and distributor acknowledgementcommercial

How should vulnerability reports move from inbox to product action?

A vulnerability-reporting route should tell researchers where to report, acknowledge receipt and provide status information while the manufacturer triages, reproduces, prioritises and remedies the issue. A published mailbox with no owner or response process does not create useful handling. Sensitive details also need controlled disclosure throughout investigation and release.

The recurring service can maintain the queue, evidence response times, coordinate product and support teams, and confirm that public information remains available. Its value rises with the number of models and software branches because each unresolved report can expose multiple shipments and distributors.

Why must the security-update period be treated as a commercial promise?

The published minimum security-update period shapes both compliance evidence and the customer proposition. It must reflect how long the manufacturer can support the product, distribute fixes and maintain relevant components. Marketing a longer period without engineering capacity creates debt; publishing a short period can weaken retailer confidence and product differentiation.

The decision belongs across product, security, finance and sales. Bill-of-material dependencies, third-party components, signing infrastructure and update delivery all affect the promise. A portfolio review can expose products whose published commitment has no funded operating plan.

A release decision lasts for the whole published support periodA release decision lasts for the whole published support period
  1. 1Launch evidence approved
  2. 2Vulnerabilities received and triaged
  3. 3Fix developed and tested
  4. 4Update distributed and monitored
  5. 5Support-period end communicated

What does current OPSS activity reveal about the opportunity?

OPSS supervises the regime and can investigate product-security failures. In its 2024–25 delivery report, OPSS said it assessed 82 connected devices and found varying non-compliance in 75% of those within scope. That is a targeted official sample, not a market-wide failure rate, but it shows why model-level evidence deserves executive attention.

The strongest proposition avoids penalty theatre. It uses the official sample to open a practical conversation about the client’s own portfolio, then proves value through a release decision, remediation plan and maintained evidence rather than a broad claim about the whole sector.

Test the gaps that can block a release decisionDiagnostic categories, not market prevalence data.
  • Product scope and economic actor
  • Credential states
  • Vulnerability handling
  • Update commitment
  • Statement-to-model reconciliation

Which businesses are most likely to buy a product-security sprint?

The best prospects have a near-term UK launch, imported connected products, multiple firmware branches, retailer diligence, a private-label change or a known evidence gap. A manufacturer needs engineering depth; an importer may need supplier evidence and role clarity; a distributor may need scalable checks across a catalogue. Their buying questions and offers should differ.

Search captures rule and statement questions. Trade networks, product-development partners, retailers, events, telephone, email and target-account outreach reveal shipment and launch timing. The qualification call must establish the actual product, actor role, evidence access and decision owner before offering technical work.

Prioritise product families by exposure and actionabilityPrioritise product families by exposure and actionability
  • Étape 1X: Evidence completeness
  • Étape 2Y: UK sales and launch exposure

When is a PSTI acquisition offer ready to launch?

The offer is ready when the partner can identify its economic-actor audience, assess one bounded product family, refer specialist testing or legal questions and maintain security-support evidence within capacity. GetFishNet’s free eligibility test checks the trigger, proof, delivery model and channel economics before recommending a campaign.

The commercial promise should remain narrow: create a product-level decision and a durable control system. It must never imply that compliance prevents every vulnerability, that a statement guarantees enforcement immunity or that an importer can outsource all responsibility to the overseas factory.

Authorities cited: UK Legislation; Office for Product Safety and Standards; Department for Science, Innovation and Technology. Dated references remain in the private source register.

Does your market present a comparable window?

The eligibility report dates and quantifies it, then tests whether it deserves action.

Test my eligibility
Strategic development · non-exhaustive demonstration

Reading the diagram. A disease contact only progresses after proof of origin, qualification of the relationship and control of the product concerned.

Text alternative. Telephone, prescriber or incoming request follow different proofs; missing consent causes documented exit.

How can the testing cycle reach a stable operating rhythm?

Relative benchmarks: D00 sets the rules of origin and termination of contact, D14 closes the preparation, W03 to W06 tests the scripts, consents, relationships of more than thirty-six months and ceilings per product, W07 to W08 arbitrator, then M03 stabilizes documented paths. Variances are recorded before any budget extension.

Gantt chart for the testing cycle — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. The foundation secures the right to contact; exploration then measures the quality of requests before any channel stabilization.

Textual alternative. D00 sets consent, D14 audits scripts, W03–W06 tests provenance, W07–W08 cuts discrepancies, M03 maintains compliance.

What financial potential does the model make visible?

Model: 132 qualified conversations, 44 reviews and 26 new customers. Weighted average: 1 527 CHF; monthly total: 39 700 CHF. The projection concerns acquisitions agreed and allocated, without using the ceilings as margin or portfolio value. No national denominator is applied.

Breakdown of acquisitions — NON-EXHAUSTIVE DEMONSTRATION

The chart counts customers, not percentage points.

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. 26 acquisitions represent subscriptions preceded by a controlled origin and relationship; the size of a share does not prejudge either the documentary quality or the maintained value.

Text alternative. The circle distributes customers obtained after verifiable consent, never people simply called. Total: 26 customers, reread with the value specific to each channel.

How do customers, average monthly revenue, and recurring revenue correlate by channel?

Channel exploredCustomersAverage monthly revenue per customerMonthly Recurring Channel Revenue
Natural and paid referencing41 300 CHF5 200 CHF
Telephone outreach31 600 CHF4 800 CHF
Voicemails2900 CHF1 800 CHF
Email Campaigns41 200 CHF4 800 CHF
Social networks31 400 CHF4 200 CHF
Partners and prescribers32 000 CHF6 000 CHF
Events and webinars21 700 CHF3 400 CHF
Advertising retargeting11 100 CHF1 100 CHF
Strategic accounts and outbound outreach22 300 CHF4 600 CHF
Content and press relations21 900 CHF3 800 CHF
Total / weighted average261 527 CHF39 700 CHF

The value is read again with the product, the applicable ceiling and the cost of controlling the provenance. The product customers × average income totals 39 700 CHF without promising performance.

Monthly recurring revenue by channel — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. Compliant disease contacts, their converted volumes and the corresponding monthly income recompose 39 700 CHF without a value outside the table.

Alternative text. Each height associates an authorized channel, actual assigned customers, and the value specific to their product. Their addition exactly equals monthly 39 700 CHF.

How should acquisition cost be assessed before recurring revenue is scaled?

Arbitration adds proof of consent, script control, relationship data, call supervision and refusal handling and reports the charge to assigned customers. It compares legal origin, product concerned, ceiling, full cost, expected termination and service capacity then reduces any channel that weakens the proof.

Funnel to Retained Monthly Recurring Revenue — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. disease contacts whose origin is demonstrated produce raw 39 700 CHF, then 34 142 CHF after maintaining at 86 %.

Text alternative. 132 conversations become 44 journals and 26 clients for disease contacts whose provenance is demonstrated. 39 700 CHF weighted to 86 % gives 34 142 CHF.

Financial limit. The 70 francs and the sixteen bonuses limit the remuneration; they give neither margin, nor number of contracts, nor maintenance. The 34 142 CHF remains a hypothesis, without reference value or forecast.

Text references: Federal Office of Public Health, decision and rules applicable to intermediaries; monitoring activity report. The federal office describes ceilings and outreach, while consent and history remain evidence specific to the file. The addresses remain in the internal source register. Each topic retains a clear documentary boundary.

The ISA 2024 processes the status. The ICA 2022 processes the contract trace. The nLPD 2023 shows another prequalification of the contact and data.

CORRELATED READINGS — DYNAMIC MODULE

The thematic map will link rules 2024 of health insurance intermediaries to ISA for status, ICA for contract and nLPD for legality of contact data. The links remain governed without implying equivalence.

The September deadline has passed; each origin of contact must always be able to be explained The report isolates the proof and the next action without reopening the 2024 rules of health insurance intermediaries.

g
getfishnet editorial team

The topic is broken down into entities, attributes, evidence, channels, costs and decision points. Institutions are cited in the text; no external resource interrupts the reading path.

documented

All market readings.

Could connected-product readiness become your next acquisition engine?

Test the target portfolio, first purchase, evidence and recurring service with GetFishNet. The eligibility review is 100% free and looks for genuine development synergies.

Test your eligibility
Test d'éligibilité

Vérifions votre marché.

Dossier reçu.

Nous étudions votre marché et rendons le verdict sous 48 heures.

Fermer

Deux minutes. Verdict sous 48 heures, sans engagement.

Vérifier mon éligibilité