← Back to insights

“We Need the PSTI Statement This Week”: Is This a Document Job or an Evidence Repair?

Field notes for connected-product cybersecurity consultancy business-development leads separating a UK PSTI statement review from product-file reconstruction, evidence remediation and engineering work.

A connected-product file links the UK statement of compliance to the model, responsible business and security evidence
#UK PSTI#Statement of Compliance#Connected Products#Product Security

Signals to watch

  • The requester can identify the exact UK product type, batch, model or variant
  • The manufacturer and the requesting importer or distributor are not being treated as the same legal role
  • A named evidence owner can support the password, vulnerability-reporting and defined-support-period claims

Picture a familiar request in an authorised device-manufacturer Telegram group:

“Retailer wants the PSTI statement this week. Same app as the EU model, password setup already tested. Can someone issue the document?”

For the business-development lead at a connected-product cybersecurity consultancy, the temptation is to price a short drafting job. That is too early. The message does not identify the UK product type or batch, the hardware and software versions, the legal manufacturer, the importer, the applicable evidence route, the defined support period or the person expected to sign.

This is a composite scene, not a real customer request or compliance result. It is useful because the missing details create the commercial decision: the statement is not the job definition; the first unsupported line in it is.

The lead is usually monitoring authorised groups used by device makers, UK importers, retail compliance teams and test laboratories. If this fragment is seen a day late, the cost is not merely a late reply. A retailer review may move forward while engineering, legal and the importer still believe somebody else owns the missing record.

Fix the product identity before quoting “the statement”

The UK consumer connectable-product security regime came into force on 29 April 2024. Government guidance for businesses highlights requirements concerning passwords, publication of vulnerability-reporting information and publication of minimum security-update periods.

The statement of compliance is a specific document within that regime. Schedule 4 of the 2023 Regulations requires information including:

  • the product type and batch;
  • the name and address of each manufacturer and, where applicable, each authorised representative;
  • declarations about who prepared the statement and the manufacturer’s opinion on compliance;
  • the defined support period that was correct when the manufacturer first supplied the product;
  • the signature, name and function of the signatory; and
  • the place and date of issue.

Those lines cannot be filled safely from “same app as the EU model.” A different radio module, firmware branch, onboarding flow or branded variant can break the link between the document and the evidence.

The first reply therefore needs only two forks:

  1. Which exact UK product is this? Ask for the commercial model, product type and batch or other controlled variant, hardware revision, firmware and app versions.
  2. Who is asking in which legal role? Record the manufacturer, any authorised representative, the UK importer and the distributor or retailer that has set the deadline.

“Party” here means a legal actor in the supply chain; “batch” means the production batch identified on the statement. Mixing the two produces more than a translation problem—it can attach the statement to the wrong product or entity.

Follow the first unsupported sentence

Once the product and roles are fixed, open the proposed statement beside the product dossier. The request then branches.

Branch A: every statement line has a current source

The model and batch match. The manufacturer details are current. The applicable Schedule 1 requirements or deemed-compliance route have been selected. The defined support period is published and maps to this product. A responsible signatory can trace the declaration back to reviewed records.

This is a document assignment: review the inputs, prepare or revise the statement, record assumptions and return a controlled version for the responsible organisation to approve. It is not a new security assessment merely because the deadline is close.

Branch B: the statement wording is clear, but a source record is absent

This is evidence remediation. Three gaps appear often:

  • Password evidence: “setup tested” does not show whether factory reset, shared defaults or credentials derived from public identifiers were covered for the UK version.
  • Vulnerability reporting: an internal support inbox is not the same as published information telling people how to report a security issue.
  • Defined support period: an internal roadmap does not establish the period published for the product, its start and end points or the owner who approved it.

The quote should cover finding the evidence owner, reviewing or producing the missing record, publishing what the regulation requires and reconnecting it to the product dossier. Drafting the statement is a later deliverable, not the first one.

Branch C: nobody can prove which variant the retailer will receive

This is product-file reconstruction. Compare the UK stock-keeping unit with the reference product at the level that changes the security claim: hardware, firmware, companion app, credential flow, update service and manufacturer identity.

European radio-equipment or Cyber Resilience Act records may help explain an engineering decision, but they do not automatically supply the product identity and statement required for the UK item.

Branch D: the available evidence shows a design conflict

If the product uses a prohibited default-password pattern, lacks an effective reporting route or has no support-period decision that the manufacturer can stand behind, the work has moved beyond evidence housekeeping. It needs engineering or governance remediation and, where relevant, testing again.

A consultancy can organise and challenge the evidence. It cannot turn a design conflict into compliance by polishing the declaration.

The regime assigns obligations to manufacturers, importers and distributors; it does not make them interchangeable. The OPSS business guidance is useful for checking the role-specific starting point.

If the manufacturer asks for help, find the product evidence owner and the person authorised to approve the manufacturer’s declaration. If an importer asks, first obtain the manufacturer’s statement and confirm that it maps to the imported product; do not silently rewrite the importer as the manufacturer. If a retailer or distributor says “upload the document,” treat that as a supply gate and trace the request upstream to the manufacturer and importer.

Schedule 4 allows the statement to say it was prepared by or on behalf of the manufacturer. That wording does not transfer the underlying security claims to a consultant. The signatory’s function must be stated, and the organisation taking responsibility must know which records support the declaration.

This distinction also prevents a common sales mistake: quoting one fixed fee before knowing whether the buyer owns the necessary records. The same one-line request can be document review, product-file reconstruction or an engineering project whose end date cannot be promised before the first technical review.

Return a two-lane scope note

The business-development lead does not need to diagnose the whole product in the group. A short scope note can expose the fork:

Lane 1 — statement review: exact product type and batch, manufacturer details, evidence index, defined support period and proposed signatory are available. We review the records and prepare a controlled draft.

Lane 2 — evidence remediation: one or more of those inputs is missing or inconsistent. We first map the product variant and the unsupported requirement, then scope the owner, publication, testing or engineering work needed before drafting.

If the initial file already shows that the design contradicts a requirement, add a third line: statement work is deferred until the technical issue and the affected versions have been resolved.

The reply to the original message can stay concrete:

“Please send the exact UK model and batch, hardware/firmware/app versions, manufacturer and importer names, the current password test record, the public vulnerability-reporting page, the published support period and the proposed signatory. We can then tell you whether this is statement review or evidence remediation.”

That is not a request for a perfect procurement brief. The sender may answer in fragments. One person may know the retailer date, another the model, and an engineer may later provide the support-period page. Unknowns should remain unknown until a source appears.

Decide whether the fragment deserves immediate follow-up

The urgent sentence becomes a useful commercial Signal when later messages add at least three things: an identifiable UK product, a real supply milestone and somebody who can open the evidence file. A deadline without a product is noise. A named model without an evidence owner is discovery work. A named model, retailer gate and available product owner justify a quick qualification call even if the final scope is still unknown.

Across Telegram groups a user has intentionally connected and is authorised to access, TOP Prospect can preserve the relevant fragments and their sources, then move the combined candidate up the review queue. Firmware inspection, control validation, sender contact, signing and the compliance decision remain with the consultancy and the responsible business—not the discovery layer.

At the end of initial qualification, the original request should have one of four labels in the sales note: document review, product-file reconstruction, evidence remediation or engineering remediation. If the sender returns the exact product and a supported line-by-line file, quote the document work. If the first missing answer is “we have never published the support period,” quote that gap instead.

The sentence “we need the statement this week” creates urgency. The first unsupported sentence in the statement creates the scope.

Sources and further reading

RESEARCH & DEFINITIONS

How a Signal worth attention is found

See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.

Open the methodology and core definitions

START WITH ONE MONITORED GROUP

Try the workflow free for seven days.

Open the product, connect one authorized group, and describe the Signal you want to find. If you need help choosing the scope, ask us on Telegram.

Back to homepage