Before a Connected Appliance Is Supplied to UK Consumers

UK Consumer Connectable Appliance PSTI Security and Statement Handoff

A Wi-Fi, Bluetooth or network-connected appliance supplied to UK consumers may fall within the Product Security and Telecommunications Infrastructure security regime. Since 29 April 2024, businesses in the supply chain of relevant consumer connectable products have duties covering baseline security requirements, a Statement of Compliance, record control and action when a compliance failure is suspected or identified.

This guide helps UK importers and private-label buyers define the product, software, support and responsibility file before approving connected air fryers, fans, pumps, ovens and other wholesale appliances. It is general B2B procurement information, not UK legal, cybersecurity, conformity, product-safety or market-access advice. The responsible businesses should confirm the exact product and route with qualified UK professionals. MOQ starts from 1000 PCS. Wholesale only.

Connected appliance production requiring controlled UK PSTI product software and compliance evidence

Direct Answer for UK Importers

Is a Wi-Fi module report enough for UK PSTI compliance?

No. PSTI duties concern the relevant consumer connectable product and the responsible businesses that manufacture, import or distribute it. A module report may help identify part of the technical design, but it does not establish the finished product's password behavior, reporting channel, support period, Statement of Compliance, software ownership or post-market process.

The buyer should freeze the exact marketed model and connected architecture before relying on a quotation. Product hardware, pre-installed software, software required for the manufacturer's intended purposes, mobile applications, cloud services, credentials and update commitments can all affect the project. A factory can coordinate genuine order evidence, but the UK importer cannot outsource its own legal duties by asking for a generic certificate.

Scope Before Claims

Decide whether the actual product and supply route are covered

Project factQuestion to recordEvidence to requestWhy it matters
Connection functionCan the product connect to the internet or a network directly or through another device?Connection diagram, protocols, module, app flow, intended purpose and user journey.Commercial words such as "smart" or "remote control" do not replace a technical scope decision.
Consumer availabilityCould the product be used by consumers, even if it is also promoted to business customers?Target buyer, sales channels, packaging, instructions and intended end users.B2B distribution does not automatically remove a consumer connectable product from scope.
UK territoryWhere will the product be supplied, and does a listed exclusion or Northern Ireland rule need separate review?Destination, importer, distributor, online offer and launch plan.The legal route must match the territory and the current legislation.
Brand ownershipWhose name or trademark appears on the product, packaging and offer?Brand entity, manufacturer identity, importer identity and authorised representative where applicable.A business marketing a product under its own name or trademark can be treated as a manufacturer.
Software dependencyWhich software is pre-installed or required for every intended connected purpose?Firmware, app, libraries, cloud, APIs, account flow and version ownership.The security requirements can extend beyond the physical circuit board.
ExceptionsDoes the product fall within a specific exclusion such as certain medical devices, smart meters, EV charge points or listed computer categories?Formal product classification and current official text.Exceptions are specific; they should not be inferred from a similar product name.

Three Baseline Security Requirements

Translate each legal requirement into a controlled order record

Passwords

No universal default or easily guessable passwords

Where the requirement applies, passwords must be unique per product or defined by the user. A unique product password cannot rely on simple counters, public information or guessable product identifiers.

Security Issues

Publish a vulnerability-reporting contact

The manufacturer must publish at least one reporting point and say when a reporter will receive an acknowledgment and status updates until resolution. The information must be accessible, clear, in English, free and available without requesting personal information.

Security Updates

Publish the defined support period

The minimum period for security updates must be published clearly and accessibly. If it is extended, the new period must be published as soon as practicable; a published support period cannot later be shortened.

Online Offers

Give support information suitable prominence

Where the manufacturer publishes an invitation to purchase on its own or controlled non-paid website, the defined support period must be displayed alongside or with equal prominence to the relevant purchase information.

Evidence

Test behavior, not only written policy

Record onboarding, password creation, reset, update checks, reporting links and support-period publication for the exact production firmware, app and cloud environment.

Change Control

Reopen the decision after software changes

A module, firmware, app, account, server, credential, update, vulnerability-contact or support-period change can make an earlier file incomplete.

Statement of Compliance

The document must identify the product, responsible parties and support commitment

Required informationProcurement controlFailure to avoid
Product type and batchLink the statement to the marketed model, factory model, variant and traceable production batch.Using a generic family statement that cannot identify the shipped units.
Manufacturer and representativeState the name and address of each manufacturer and each authorised representative where applicable.Listing only a platform, laboratory or importer that did not prepare the statement.
Preparation declarationDeclare that the statement is prepared by or on behalf of the product manufacturer.Reusing an unsigned supplier template with no accountable issuer.
Compliance declarationState the manufacturer's opinion that the applicable Schedule 1 requirements or relevant Schedule 2 deemed-compliance conditions are met.Calling a test report or standard title the Statement of Compliance.
Defined support periodRecord the period that was correct when the manufacturer first supplied the product.Leaving the support period open, shortening it later or using a period that does not match public information.
Standard identification where applicableIf deemed compliance relies on a specified standard, include its identification number, version and issue date where applicable.Writing "ETSI compliant" without identifying the actual standard basis.
Signature and issue detailsInclude signatory name, function, signature, place and date of issue.Approving shipment with a blank, undated or unauthorised statement.

Official UK guidance explains that the Statement of Compliance must accompany the product. It does not state that the document must be physical, so a digital route may be possible, but the manufacturer, importer and distributor remain responsible for ensuring that the required statement actually accompanies the product and meets the legislation.

UK PSTI Scope Master

Freeze fourteen fields before sample approval and packaging release

Control fieldRecord for the actual wholesale SKUCommercial purpose
Product identityBrand, commercial model, factory model, variant, intended purpose, images and approved sample revision.Keeps software, support and compliance records attached to the shipped product.
Economic operatorsManufacturer, brand owner, UK importer, distributors and authorised representative where applicable.Shows who performs each duty and who receives a compliance notice.
Connection mapWi-Fi, Bluetooth, cellular or other network route; direct and indirect internet connections.Defines the actual connectable functions instead of relying on marketing labels.
Hardware baselineModule, PCB, antenna, memory, secure element, ports, reset method and production programming.Links security behavior to a controlled construction.
Software baselineFirmware, bootloader, libraries, app, cloud, APIs, version identifiers and release owners.Prevents an assessed sample from becoming a different software product at shipment.
Password behaviorFactory state, onboarding, unique or user-defined credentials, reset, recovery and transfer.Provides evidence against universal default and easily guessable passwords.
Security contactPublished reporting URL or email, responsible team, acknowledgment timing and update process.Turns a policy sentence into an operational vulnerability route.
Support periodStart basis, minimum end date or period, public location, responsible funder and extension process.Prevents the product, website and Statement of Compliance from carrying different promises.
Update processSigning, delivery, verification, rollback, emergency update, failed-update recovery and user notice.Shows how the support promise can be performed in practice.
Cloud continuityTenant, domain, certificates, administrator, regions, logs, backup, fees and termination route.Protects the importer from an undocumented third-party platform dependency.
Assessment evidenceScope decision, requirement map, test records, standard basis, exceptions and unresolved actions.Supports the statement without treating it as a stand-alone certificate.
Statement fileAll required Schedule 4 fields, issue control, translation or digital access route, and batch link.Ensures the correct document accompanies the correct product.
Production controlsApproved BOM and software, credential provisioning, inspection, serialization, substitution and release authority.Keeps production aligned with the reviewed model.
Failure responseInvestigation owner, notification contacts, stop-supply trigger, remediation, customer communication, recall and retained records.Allows the supply chain to act promptly when a potential failure appears.

Supply-Chain Responsibility Matrix

A supplier document does not remove the importer's own duty

PartyOrder-stage controlPost-market control
Manufacturer or private-label manufacturerDesign for the requirements, prepare the Statement of Compliance, publish security-reporting and support information, and maintain product and software evidence.Investigate potential failures, keep required records, take corrective action and notify relevant parties where required.
UK importerCheck the manufacturer route, security requirements and accompanying statement before making the product available; retain evidence appropriate to its role.Investigate potential failures, act on known or suspected non-compliance, coordinate the manufacturer and notify OPSS or other parties when required.
Distributor or retailerCheck the product and accompanying information before supply and avoid distributing a product it knows or ought to know is non-compliant.Take action on compliance failures, preserve distribution traceability and support customer or regulator communication.
App or cloud providerProvide documented software identity, security controls, update capability, support commitment, incident route and service ownership.Maintain the agreed service, vulnerability response, logs, change notice and transition or shutdown plan.
Yaoyuan factory teamCoordinate available genuine product, component, firmware, platform, sample, production and change records for the contracted model.Support factual investigation and corrective-production records within the agreed factory scope.

Factory-to-Importer Workflow

Close the security file before the carton artwork is frozen

01 Scope

Identify the product and UK route

Record intended consumers, territory, brand, connected functions, software dependencies, exclusions and responsible businesses.

02 Architecture

Freeze hardware and software ownership

Identify the module, firmware, app, cloud, accounts, credentials, administrators, domains and update authority.

03 Requirements

Map passwords, reporting and updates

Turn each applicable requirement into a design control, evidence item, test and production check.

04 Commercial Support

Fund the promised support period

Agree the minimum period, service owner, platform fees, update resources, vulnerability contact and exit route.

05 Statement

Prepare the correct accompanying document

Complete all required fields for the actual product and choose a reliable physical or digital delivery method.

06 Production

Control programming and traceability

Verify approved software, credentials, serial or batch records, labels, instructions, statement access and final inspection.

07 Launch

Publish support and reporting information

Check the live security contact, support period, online offer, customer instructions and UK responsible-party details.

08 Monitor

Operate the failure-response route

Log issues, investigate promptly, stop supply when necessary, communicate corrections and preserve evidence.

Post-Market Control

The file must support action, not only a pre-shipment audit

OPSS is the UK enforcement authority for this regime. Its published enforcement tools include compliance notices, stop notices, recall notices, monetary penalties, forfeiture applications and court action relating to information notices. Manufacturers and importers must investigate potential compliance failures and take action when they become aware, or ought to be aware, of a failure. Distributors and authorised representatives also have action duties.

A useful procurement file therefore identifies who receives a vulnerability report, who can change firmware or cloud services, who can stop a shipment, who contacts UK distributors, who holds customer and batch traceability, and who prepares the facts for any required notification. Official OPSS guidance says a notification should describe the failure, known risk, remedial steps and their outcome, plus relevant manufacturer or importer actions known to an importer or distributor.

Do not wait for a regulator letter before deciding who owns the response. Put the investigation, escalation, software, production, communication and evidence-retention route into the commercial project while the parties can still negotiate it.

Reassessment Triggers

Reopen the file when the product or service changes

Hardware

Module, PCB or credential component

A substitute can alter connection behavior, provisioning, update capability and traceability.

Software

Firmware, app, library or API

Record the impact on passwords, reporting, updates, user accounts and intended functions.

Cloud

Provider, tenant, endpoint or certificate

Confirm operational ownership, data flow, service continuity and customer communication.

Support

Period, funding or responsible team

Do not shorten a published defined support period; control any extension across every public and accompanying record.

Market

Brand, importer, territory or channel

Recheck economic-operator identities, online offers, statements and delivery route.

Law and Standards

Updated official requirements

Review current UK legislation and guidance with qualified professionals before a new production release.

Official UK Sources

Use current primary material for the final project decision

Requirements and official guidance can change. Verify the current product scope, exclusions, standard route, statement content and economic-operator duties before supply. Yaoyuan does not provide a legal opinion, issue UK regulatory approval or guarantee market acceptance.

Wholesale Project Intake

Send a model-specific UK connected-appliance inquiry

Send buyer company, UK manufacturer or importer entity, brand, product and model, quantity, intended consumers, connection functions, module, firmware owner, app and cloud owner, password flow, security-reporting contact, planned support period, available evidence, target launch date and destination port. Use inquiry code PSTIFILE1000.

Wholesale only. MOQ starts from 1000 PCS. No retail or one-piece orders.