Article overview

A Wi-Fi digital photo frame sold to UK consumers is not only a screen inside a decorative enclosure. It may receive photographs through an app, connect to a household network, depend on a cloud service and accept remote software updates. Those functions can bring the product into the UK's consumer connectable product security regime, which has applied since 29 April 2024. Importers should therefore ask more than whether an overseas factory has produced a “PSTI certificate.”

This guide is for UK importers, private-label brands, retailers and OEM/ODM suppliers developing connected photo, family-calendar, memorabilia or promotional display frames. It turns the official Product Security and Telecommunications Infrastructure regime into a supplier handover. It does not determine that a specific product is in scope, approve a statement of compliance, prescribe security architecture or replace the Department for Science, Innovation and Technology, OPSS, legal or cybersecurity advice.

Decide whether the frame is a relevant connectable product

Official guidance says a relevant connectable product is an internet-connectable or network-connectable product that is not an excepted product. A frame with Wi-Fi, Bluetooth or another network function may appear likely to require review, but the business should assess the actual model, intended use and legal definitions. A passive LED lightbox or an offline screen with removable storage may present a different question.

Create a connectivity declaration for every SKU. List radios, ports, protocols, app connections, remote services, local-network functions and whether the product can send or receive data. Note which functions are enabled at first supply and which can be activated later. Ask qualified UK advisers to record the scope decision; do not copy the conclusion from a visually similar device.

Map who is manufacturer, importer and distributor

The regime places duties on manufacturers, importers and distributors. A private-label arrangement may make the brand the manufacturer for legal purposes even when an overseas factory performs physical assembly. The importer also has its own duties and cannot rely on the carton saying that the factory is responsible.

Prepare a role table with the legal entities, UK addresses, brand ownership, authorised representative where relevant, importer of record, distributor and retailer. State who creates the statement of compliance, who verifies it before release, who keeps the required copy and who investigates a potential compliance failure. Contracts can allocate work and evidence, but they do not erase duties created by law.

Freeze the exact connected configuration

A ten-inch frame may be sold under several brands with different firmware, apps and cloud endpoints. Treat each controlled configuration as a product identity: model, hardware revision, wireless module, operating system, firmware build, app version, cloud tenant, power supply and packaging version. A supplier test report for one radio board should not be attached automatically to every later variant.

Maintain a family matrix showing what is shared and what differs. If the factory substitutes memory, radio module, system image or app SDK, require a written change notice and review. Cybersecurity behaviour can change without altering the external mould. The release gate should compare the actual production image and components with the approved record.

Hands testing a Wi-Fi digital photo frame and smartphone during secure first-time onboarding
First-time setup should be tested on the production software and hardware, including how credentials are created and how the user recovers access.

Do not accept universal default passwords

The UK's minimum security requirements address passwords used by consumer connectable products. The product must not rely on a universal, easily guessable or easily derivable default password in a way prohibited by the Regulations. A batch-level credential printed on every quick-start card is not made secure because it contains mixed characters.

Ask the engineering team to show the complete first-use journey. Identify credentials for the device, app account, local administration interface, service mode, debugging channel and cloud administration. Confirm which are unique, user-defined, disabled or inaccessible in production. Test reset, transfer and recovery without exposing credentials in photographs, shared spreadsheets or carton labels.

Control hidden service and factory accounts

Visible onboarding is only one layer. Reference platforms sometimes retain factory test accounts, engineering menus, remote-support credentials or open debug services. Request a production-hardening checklist that covers removal or restriction of development interfaces, sample credentials, test endpoints and unnecessary services.

Verify the production build rather than a presentation sample. Ask who authorises service access, whether access is logged, how credentials are rotated and how a returned unit is handled. A support function should not create a permanent shared back door. Qualified security testing should determine whether the implemented controls are effective.

Publish a usable vulnerability disclosure route

The Regulations require information on how security issues can be reported. A vulnerability disclosure policy should give researchers and users a clear contact, explain the information that helps investigation and state when they can expect acknowledgement and status updates. It should remain available without forcing a reporter through an ordinary warranty form.

Name the team that monitors the route and provide a deputy. Link reports to product identity, preserve the original timestamp and protect sensitive technical information. The policy should not promise payment, immunity or a fix deadline without organisational approval. Test the mailbox and web page before launch and during the defined support period.

Define the security-update period before quotation

The regime requires manufacturers to publish information about the minimum period for which security updates will be provided. That period is a commercial commitment as well as a compliance field. A low hardware price can hide years of app maintenance, hosting, certificate renewal, library monitoring and update delivery.

Ask for a dated support plan covering device firmware, mobile applications and cloud services. Define the starting point, end date, included models, security-fix route, customer communication and what happens if a software partner changes. The final period must be determined and communicated according to the Regulations; “updates when available” is not a measurable supplier commitment.

Check how the support period is published

The manufacturer should make the defined support period available in the required manner. Coordinate the product page, instruction material, support portal and statement of compliance so they do not show different dates. Keep evidence of what was published when the product was first supplied.

If the same hardware is sold under several private labels, each manufacturer should control its own public information and support promise. Do not rely on a factory webpage that may change or disappear. The UK customer-facing route should be durable, understandable and linked to the model the user can identify.

Prepare the statement of compliance as a controlled document

Official guidance says manufacturers must ensure that a statement of compliance with the specified information accompanies the product. Importers and distributors must not make a covered product available unless it is accompanied by the statement. The Regulations specify information including product identification, manufacturer details, the compliance declaration, defined support period, signatory and issue details.

Create the statement from approved product and legal records, not from a generic supplier template. Confirm the named manufacturer, exact product or type, applicable requirements or deemed-compliance route, support period and authorised signatory. A laboratory report is not the statement, and the statement is not proof that the implemented security controls work.

Choose a practical way for the statement to accompany the product

Official guidance allows the regime's document requirements to be met in the permitted formats and conditions. The buyer should decide how the customer and channel partner can access the correct statement at supply. A loose URL that later redirects to a different model creates avoidable traceability risk.

Test the customer journey from sealed retail package to the statement. Ensure that model identification is clear, the link or document remains available and accessibility needs are considered. Archive the issued version. If packaging artwork is changed, verify that the compliance route still points to the correct model and support information.

Retain the required copies and release evidence

The official regime guidance highlights manufacturer and importer duties to retain copies of the statement of compliance. Build retention into the product record alongside final artwork, approved software identity, vulnerability policy, support-period evidence, supplier declarations and change history.

Set access permissions and a retention owner. Keep a released PDF or equivalent controlled artifact rather than only an editable office file. Record the first-supply date and final supply date used for retention calculations. The supplier portal can be a convenience, but the UK importer should not lose its evidence when a commercial relationship ends.

Investigate potential compliance failures quickly

OPSS enforcement guidance says manufacturers and importers must investigate potential compliance failures and take action when they are aware, or ought to be aware, of them. Build an intake route for shared passwords, missing support information, unreachable disclosure contacts, unsigned statements, unexpected services or software changes.

Preserve the first-information date and affected product population. Escalate to qualified legal and security owners without waiting for a complete root-cause report. Separate temporary containment from the final conclusion. A distribution hold may be appropriate while facts are checked, but the correct action and notification duties depend on the circumstances.

Prepare notification and corrective-action ownership

OPSS guidance explains that relevant persons have duties to notify certain parties, including OPSS, about compliance failures. Do not assume the overseas factory will make a UK notification. Maintain current contacts, approval authority and the information needed to describe the failure, known risk, affected products and action taken.

A corrective plan may involve software updates, revised credentials, customer instructions, updated statements, stock correction or other measures. The responsible business and advisers should decide the response. Keep distributors and fulfilment providers in the contact map so affected units can be identified without uncontrolled public messaging.

Open rear electronics of a connected digital photo frame beside a controlled software support timeline
Long-term support needs a maintained relationship between hardware revisions, software releases and the party able to deliver a security fix.

Make firmware updates safe and supportable

Ask how the frame verifies update authenticity and integrity, protects signing keys, handles interrupted installation and reports failure. Confirm whether updates are automatic, user-initiated or staged, and how customers who remain offline are treated. These are technical design questions requiring competent security review.

Link every released build to source, configuration, test evidence, approval and supported models. Avoid uncontrolled retailer-specific forks. If a critical vulnerability is discovered, the team should be able to identify affected units, create and validate a fix, deploy it in stages and communicate accurately without turning the update channel into a new risk.

Control the app and cloud supplier

A connected frame may depend on a white-label app or shared cloud service that the frame factory does not own. The UK brand needs direct visibility of service ownership, security contacts, update policy, hosting, authentication, data flows, incident notice and exit arrangements. “Includes free app” is not a support specification.

Set contractual notification times that allow the manufacturer and importer to investigate promptly. Require change notice for SDKs, endpoints, identity providers and hosting architecture. Plan for app-store policy changes and service closure. The customer should not lose security updates because the original component purchase order has ended.

Test the ordinary customer experience

Security controls fail when users cannot understand them. Test first use, account invitation, family sharing, password change, device transfer, reset, lost-phone recovery, deletion and end-of-support messaging. Use participants unfamiliar with the engineering project and record where instructions create unsafe shortcuts.

Do not collect real family photographs for testing when synthetic media is sufficient. Verify that diagnostic logs and support tools minimise personal data and have controlled access. PSTI is a product-security regime; privacy, UK GDPR, electrical safety, radio compliance and consumer law still require separate assessment.

Supplier handover checklist

  • Product scope is assessed from actual connectivity and intended use
  • Manufacturer, importer, distributor and authorised representative roles are mapped
  • Model, hardware, firmware, app, cloud and power-supply identities are controlled
  • Universal and easily guessable default passwords are excluded
  • Factory, debug and service access is hardened for production
  • Vulnerability disclosure information is public and monitored
  • Acknowledgement and status-update responsibilities are assigned
  • Defined security-update period is funded and published consistently
  • Statement of compliance contains the required product-specific information
  • The statement accompanies the correct product
  • Manufacturer and importer copies are retained
  • Potential compliance failures enter a fast investigation route
  • OPSS and supply-chain notification ownership is named
  • Firmware signing, testing, rollout and recovery are controlled
  • App and cloud providers have support and incident commitments
  • Privacy, radio, electrical and consumer duties remain separate workstreams

Experience scope and project limits

Editorial review: Jessica, Founder & Project Advisor at DOREMI Display. Updated 13 September 2026. Jessica's practical scope covers B2B display-frame briefs, materials, samples, packaging, production coordination, quality discussions and supplier-to-buyer handover. She is not presented as OPSS, DSIT, a UK market-surveillance authority, cybersecurity laboratory, legal adviser or statement-of-compliance approver.

This guide is educational sourcing preparation. It does not confirm that a particular frame is a relevant connectable product or that a security design, statement, update period or corrective action complies with UK law. Review the actual product, legal roles and current official requirements with qualified advisers before making it available in the UK.

Public sources used for this guide