A connected device can pass its functional tests, reach a UK distributor and still be missing the security evidence needed to support its sale. Since 29 April 2024, the UK Product Security regime has imposed baseline requirements on relevant consumer connectable products and duties across manufacturers, importers and distributors. The commercial gap is rarely “cybersecurity” in the abstract. It is a specific product family whose default credentials, vulnerability-reporting route, security-update period or statement of compliance cannot survive a release review. That makes the first purchase concrete: test one SKU family and decide whether it is ready, conditionally ready or blocked. This reading explains how to identify the responsible economic actor, build a product-security evidence pack and create an ongoing support-period service. It also shows how acquisition can reach businesses with a live launch or distribution trigger without claiming that a checklist makes a device secure or guarantees regulatory acceptance.
Which connected products fall within the UK Product Security regime?
The Product Security regime covers relevant internet-connectable and network-connectable products made available to UK consumers, subject to statutory exclusions and special cases. Scope depends on connectivity, intended use, customer and product configuration. A product name, tariff code or “professional” label alone cannot establish whether a particular model or bundle is in scope.
A boundary file should describe hardware, software, radio or network functions, intended customer, bundled components and route to market. Variants matter: a non-connected model and its app-enabled sibling may need different conclusions. Uncertainty remains visible until legal or technical ownership resolves it.
- 1Is the product in scope?
- 2Which business is manufacturer, importer or distributor?
- 3Are the three baseline security requirements evidenced?
- 4Does the statement of compliance match the shipped model?
How do manufacturer, importer and distributor duties differ?
Manufacturers carry the core security-requirement and statement duties; importers and distributors must check required documentation and act where they know or ought to know that a product is non-compliant. The statutory role follows what the business actually does, including branding and supply-chain control, rather than the title printed in a commercial agreement.
One company can hold different roles across product lines. The release file therefore maps the brand owner, designer, factory, UK importer, marketplace seller and distributor for each family. Contracts allocate evidence and cooperation, but cannot erase duties created by the real supply chain.
- Étape 1Manufacturer: designs or markets under its name
- Étape 2Importer: brings an overseas product into the UK
- Étape 3Distributor: makes the product available downstream
- Étape 4Retail or marketplace channel: exposes listing and document gaps
What are the three baseline security requirements?
The baseline requirements address passwords, vulnerability reporting and security updates. Products must not use universal or easily guessable default passwords; manufacturers must publish a route for security-problem reports; and they must publish the minimum period for which security updates will be provided. Each requirement needs product-specific evidence, not a policy statement detached from the shipped build.
Testing should follow activation, reset, recovery, refurbished-device and support states. The vulnerability route must reach a team able to acknowledge and act. The published support period must reconcile with engineering capacity, packaging, web copy and distributor data.
What should a paid PSTI release-gate sprint deliver?
A paid PSTI sprint should define scope and economic roles, test the three baseline controls, reconcile the statement of compliance with the shipped model and issue a release decision with remediation owners. It should focus on one SKU family or launch wave, avoiding an open-ended security programme that buyers cannot price or approve quickly.
The partner begins with product samples, firmware and support information, not a generic questionnaire. It records missing evidence, tests high-consequence states and distinguishes a document correction from engineering work. Where specialist legal interpretation or penetration testing is required, that dependency is named before the product is presented as ready.
What must a statement of compliance prove?
A statement of compliance identifies the product and manufacturer, confirms compliance with the applicable security requirements, records the relevant support period and includes prescribed signatory and date information. It must accompany the product as required and match the version being supplied. A reusable template is useful only when its underlying evidence remains accurate.
The statement index links model identifier, hardware revision, firmware baseline, evidence owner, approval date and distribution markets. A material change should trigger reassessment rather than silent reuse. This gives sales teams a precise answer when a retailer or importer requests assurance.
| Requirement | Product evidence | Operational owner |
|---|---|---|
| Password design | activation reset and recovery tests | engineering |
| Vulnerability reporting | published contact and handling workflow | security |
| Update period | dated commitment and release capacity | product |
| Statement of compliance | approved model-specific document | compliance |
| Supply-chain duty | importer and distributor acknowledgement | commercial |
How should vulnerability reports move from inbox to product action?
A vulnerability-reporting route should tell researchers where to report, acknowledge receipt and provide status information while the manufacturer triages, reproduces, prioritises and remedies the issue. A published mailbox with no owner or response process does not create useful handling. Sensitive details also need controlled disclosure throughout investigation and release.
The recurring service can maintain the queue, evidence response times, coordinate product and support teams, and confirm that public information remains available. Its value rises with the number of models and software branches because each unresolved report can expose multiple shipments and distributors.
Why must the security-update period be treated as a commercial promise?
The published minimum security-update period shapes both compliance evidence and the customer proposition. It must reflect how long the manufacturer can support the product, distribute fixes and maintain relevant components. Marketing a longer period without engineering capacity creates debt; publishing a short period can weaken retailer confidence and product differentiation.
The decision belongs across product, security, finance and sales. Bill-of-material dependencies, third-party components, signing infrastructure and update delivery all affect the promise. A portfolio review can expose products whose published commitment has no funded operating plan.
- 1Launch evidence approved
- 2Vulnerabilities received and triaged
- 3Fix developed and tested
- 4Update distributed and monitored
- 5Support-period end communicated
What does current OPSS activity reveal about the opportunity?
OPSS supervises the regime and can investigate product-security failures. In its 2024–25 delivery report, OPSS said it assessed 82 connected devices and found varying non-compliance in 75% of those within scope. That is a targeted official sample, not a market-wide failure rate, but it shows why model-level evidence deserves executive attention.
The strongest proposition avoids penalty theatre. It uses the official sample to open a practical conversation about the client’s own portfolio, then proves value through a release decision, remediation plan and maintained evidence rather than a broad claim about the whole sector.
- Product scope and economic actor
- Credential states
- Vulnerability handling
- Update commitment
- Statement-to-model reconciliation
Which businesses are most likely to buy a product-security sprint?
The best prospects have a near-term UK launch, imported connected products, multiple firmware branches, retailer diligence, a private-label change or a known evidence gap. A manufacturer needs engineering depth; an importer may need supplier evidence and role clarity; a distributor may need scalable checks across a catalogue. Their buying questions and offers should differ.
Search captures rule and statement questions. Trade networks, product-development partners, retailers, events, telephone, email and target-account outreach reveal shipment and launch timing. The qualification call must establish the actual product, actor role, evidence access and decision owner before offering technical work.
- Étape 1X: Evidence completeness
- Étape 2Y: UK sales and launch exposure
When is a PSTI acquisition offer ready to launch?
The offer is ready when the partner can identify its economic-actor audience, assess one bounded product family, refer specialist testing or legal questions and maintain security-support evidence within capacity. GetFishNet’s free eligibility test checks the trigger, proof, delivery model and channel economics before recommending a campaign.
The commercial promise should remain narrow: create a product-level decision and a durable control system. It must never imply that compliance prevents every vulnerability, that a statement guarantees enforcement immunity or that an importer can outsource all responsibility to the overseas factory.
Authorities cited: UK Legislation; Office for Product Safety and Standards; Department for Science, Innovation and Technology. Dated references remain in the private source register.
The eligibility report dates and quantifies it, then tests whether it deserves action.
Reading the diagram. A disease contact only progresses after proof of origin, qualification of the relationship and control of the product concerned.
Text alternative. Telephone, prescriber or incoming request follow different proofs; missing consent causes documented exit.
How can the testing cycle reach a stable operating rhythm?
Relative benchmarks: D00 sets the rules of origin and termination of contact, D14 closes the preparation, W03 to W06 tests the scripts, consents, relationships of more than thirty-six months and ceilings per product, W07 to W08 arbitrator, then M03 stabilizes documented paths. Variances are recorded before any budget extension.
Gantt chart for the testing cycle — NON-EXHAUSTIVE DEMONSTRATION
Reading the diagram. The foundation secures the right to contact; exploration then measures the quality of requests before any channel stabilization.
Textual alternative. D00 sets consent, D14 audits scripts, W03–W06 tests provenance, W07–W08 cuts discrepancies, M03 maintains compliance.
What financial potential does the model make visible?
Model: 132 qualified conversations, 44 reviews and 26 new customers. Weighted average: 1 527 CHF; monthly total: 39 700 CHF. The projection concerns acquisitions agreed and allocated, without using the ceilings as margin or portfolio value. No national denominator is applied.
Breakdown of acquisitions — NON-EXHAUSTIVE DEMONSTRATION
The chart counts customers, not percentage points.
Reading the diagram. 26 acquisitions represent subscriptions preceded by a controlled origin and relationship; the size of a share does not prejudge either the documentary quality or the maintained value.
Text alternative. The circle distributes customers obtained after verifiable consent, never people simply called. Total: 26 customers, reread with the value specific to each channel.
How do customers, average monthly revenue, and recurring revenue correlate by channel?
| Channel explored | Customers | Average monthly revenue per customer | Monthly Recurring Channel Revenue |
|---|---|---|---|
| Natural and paid referencing | 4 | 1 300 CHF | 5 200 CHF |
| Telephone outreach | 3 | 1 600 CHF | 4 800 CHF |
| Voicemails | 2 | 900 CHF | 1 800 CHF |
| Email Campaigns | 4 | 1 200 CHF | 4 800 CHF |
| Social networks | 3 | 1 400 CHF | 4 200 CHF |
| Partners and prescribers | 3 | 2 000 CHF | 6 000 CHF |
| Events and webinars | 2 | 1 700 CHF | 3 400 CHF |
| Advertising retargeting | 1 | 1 100 CHF | 1 100 CHF |
| Strategic accounts and outbound outreach | 2 | 2 300 CHF | 4 600 CHF |
| Content and press relations | 2 | 1 900 CHF | 3 800 CHF |
| Total / weighted average | 26 | 1 527 CHF | 39 700 CHF |
The value is read again with the product, the applicable ceiling and the cost of controlling the provenance. The product customers × average income totals 39 700 CHF without promising performance.
Monthly recurring revenue by channel — NON-EXHAUSTIVE DEMONSTRATION
Reading the diagram. Compliant disease contacts, their converted volumes and the corresponding monthly income recompose 39 700 CHF without a value outside the table.
Alternative text. Each height associates an authorized channel, actual assigned customers, and the value specific to their product. Their addition exactly equals monthly 39 700 CHF.
How should acquisition cost be assessed before recurring revenue is scaled?
Arbitration adds proof of consent, script control, relationship data, call supervision and refusal handling and reports the charge to assigned customers. It compares legal origin, product concerned, ceiling, full cost, expected termination and service capacity then reduces any channel that weakens the proof.
Funnel to Retained Monthly Recurring Revenue — NON-EXHAUSTIVE DEMONSTRATION
Reading the diagram. disease contacts whose origin is demonstrated produce raw 39 700 CHF, then 34 142 CHF after maintaining at 86 %.
Text alternative. 132 conversations become 44 journals and 26 clients for disease contacts whose provenance is demonstrated. 39 700 CHF weighted to 86 % gives 34 142 CHF.
Financial limit. The 70 francs and the sixteen bonuses limit the remuneration; they give neither margin, nor number of contracts, nor maintenance. The 34 142 CHF remains a hypothesis, without reference value or forecast.
Which sources and related readings deepen this analysis?
Text references: Federal Office of Public Health, decision and rules applicable to intermediaries; monitoring activity report. The federal office describes ceilings and outreach, while consent and history remain evidence specific to the file. The addresses remain in the internal source register. Each topic retains a clear documentary boundary.
The ISA 2024 processes the status. The ICA 2022 processes the contract trace. The nLPD 2023 shows another prequalification of the contact and data.
CORRELATED READINGS — DYNAMIC MODULE
The thematic map will link rules 2024 of health insurance intermediaries to ISA for status, ICA for contract and nLPD for legality of contact data. The links remain governed without implying equivalence.
- See the insurance & brokerage market
- Explore all market readings
- Test the eligibility of your own window
The September deadline has passed; each origin of contact must always be able to be explained The report isolates the proof and the next action without reopening the 2024 rules of health insurance intermediaries.
The topic is broken down into entities, attributes, evidence, channels, costs and decision points. Institutions are cited in the text; no external resource interrupts the reading path.