Section 11: Duties to take action in relation to compliance failure

Product Security and Telecommunications Infrastructure Act 2022 · 2022 c. 46View on legislation.gov.uk

Part 1: Product security — CHAPTER 2: Duties of relevant persons, etc

This section applies if, at any time after a relevant connectable product has been made available in the United Kingdom—

a manufacturer of the product becomes aware, or ought to be aware, of a compliance failure in relation to the product, and
the manufacturer is aware, or ought to be aware, that the product is or will be a UK consumer connectable product.

The manufacturer must, as soon as is practicable, take all reasonable steps to—

prevent the product from being made available to customers in the United Kingdom (where it has not already been so made available);
remedy the compliance failure.

The persons referred to in subsection (3) are—

the enforcement authority;
any other manufacturer of the product of which the manufacturer is aware;
any importer or distributor to whom the manufacturer supplied the product;
in a case where specified conditions are met, any customer in the United Kingdom to whom the manufacturer supplied the product.

The notification under subsection (3) must include the following information—

details of the compliance failure;
any risks of which the manufacturer is aware that are posed by the compliance failure;
any steps taken by the manufacturer to remedy the compliance failure and whether or not those steps have been successful.

When the manufacturer notifies a person within subsection (4)(b) or (c) of the compliance failure, the manufacturer must also inform the person whether or not the manufacturer has notified the enforcement authority of the compliance failure.

Where the manufacturer became aware of the compliance failure as a result of being contacted about it by a relevant person in accordance with this Chapter, the manufacturer does not need to notify the relevant person of the compliance failure.

In this section "compliance failure" means a failure by a manufacturer of the product to comply with a relevant security requirement relating to the product.

About this text

This legislation text comes from legislation.gov.uk. Contains public sector information licensed under the Open Government Licence v3.0. These source and reuse terms cover the legislation text, not Remedy's commentary.

Reuse reviewed 21 August 2026 under Open Government Licence v3.0.