Market Access

UK PSTI Compliance for Wi-Fi Microinverters: An Importer Checklist

A buyer-side checklist for defining PSTI scope, checking passwords, vulnerability reporting, support periods and the Statement of Compliance before a connected microinverter ships to the UK.

TMG Technical Team

TMG Technical Team

Compliance & Applications Engineering

7 min read Reviewed January 2, 2026
UK PSTI Compliance for Wi-Fi Microinverters: An Importer Checklist

A Wi-Fi microinverter quotation for the UK now needs a cybersecurity review as well as electrical, radio and grid-connection evidence. The UK's consumer connectable product security regime took effect on 29 April 2024. It creates duties for manufacturers, importers and distributors of products within scope, including a requirement for a Statement of Compliance to accompany the product.

That does not mean every solar inverter is automatically covered. A microinverter, gateway and app can form different product configurations, and the statutory result depends on connectability, consumer availability, territory and exclusions. Treat applicability as a documented gate—not a claim copied from a supplier brochure. This article is a procurement framework, not legal advice.

Decide scope before requesting a certificate

Freeze the product system being placed on the market. Record whether connectivity sits inside the microinverter, in a plug-in radio module or in a separate gateway, and whether the product can connect directly or indirectly to the internet or a network. Include the mobile app, cloud account, installer portal, APIs and firmware service where they control product security.

Document the exact model, suffix, hardware, firmware, supplied communications equipment, intended purchaser and UK sales territory. Name the manufacturer, importer, distributor, brand owner, cloud operator and security-contact owner. Record any claimed statutory exclusion and its supporting evidence.

The official UK product security guidance identifies manufacturers, importers and distributors as economic actors. A business that sells a product under its own name or trademark may carry manufacturer responsibilities. Northern Ireland treatment can differ where relevant EU rules apply, so do not approve one undifferentiated “UK pack” without checking the placement territory.

Map the three security requirements to evidence

PSTI evidence area Supplier question Procurement warning sign
Passwords and credentials How are device, installer and user credentials created and changed? Shared factory password across units
Vulnerability reporting Where can a researcher report a flaw, and when will receipt and status be communicated? Only a general sales inbox
Minimum security-update period What is the published end date or period for security updates? “Updates when necessary” with no defined period

Do not review only the customer login. Map service credentials, local access points, gateway pairing, installer accounts, cloud administration and recovery flows. If the design uses no password for one access path, record the mechanism and its compliance rationale instead of marking it “not applicable” without engineering support.

The vulnerability channel should be public and usable without becoming a customer. Retain its URL, contact method, acknowledgement commitment, status-update commitment and triage owner. Test the route during sample approval; a published mailbox that rejects external messages is not operational evidence.

For the support period, capture the public statement visible to buyers, its starting point, end date or minimum duration, covered components and installed-base notification method. The commercial warranty and security-update period are different promises. Neither should be inferred from the other.

Build a model-linked Statement of Compliance pack

The 2023 Security Requirements Regulations set out the security requirements and minimum contents for the Statement of Compliance. The statement may accompany the product digitally, but importer and distributor still need a controlled way to ensure the correct version reaches the customer.

Check for:

  1. Product type, batch or other identification resolving to the ordered model
  2. Manufacturer name and address and any relevant authorised representative
  3. Declaration of compliance with the applicable security requirements
  4. Any specified standard used for deemed compliance, with traceable version details
  5. Defined security-support period
  6. Signatory name, function, signature, place and issue date
  7. Stable delivery method, document revision and owner

The manufacturer must retain the statement for the longer of ten years from issue or the defined support period. Apply comparable control in the distributor file: link statement revision to model, firmware baseline, carton QR code or insert, and first shipment. A generic family PDF is weak evidence if it cannot be reconciled with the product label.

Review the complete connected system

Component Evidence to request
Microinverter firmware Version, authenticity control, update route and recovery behavior
Gateway or radio module Unique provisioning, pairing/reset behavior and network protocols
Mobile app Account creation, roles, recovery and ownership transfer
Cloud platform Service owner, access control, logs, availability and incident route
Installer portal/API Privileged roles, credential lifecycle and revocation
Update service Support period, staged deployment, rollback and end-of-support action

Use the Wi-Fi monitoring handover checklist for account ownership and installer-to-customer transfer. Use the firmware change-control guide to connect each release to approved hardware, security impact, rollback and fleet communication.

Keep PSTI separate from other approval routes

Review route Main question Not a substitute for
PSTI product security Is the relevant connected consumer product supported with compliant credentials, reporting and update-period information? Electrical safety, radio/EMC or grid approval
G98/G99 and DNO process May the exact installation follow the intended connection route? PSTI or privacy review
Electrical safety, EMC and radio rules Is the placed configuration compliant in those regulated areas? Site connection permission
UK GDPR and privacy Are personal data and account processing handled lawfully? Product-security conformity
Commercial cloud SLA Will monitoring meet the distributor's service expectation? Statutory compliance

For grid-market entry, use the UK G98 and ENA Connect Direct checklist. For EU sales, the RED EN 18031 checklist follows a separate legal route. Evidence may overlap technically, but declarations and responsible parties are not interchangeable.

Put cybersecurity controls into the RFQ

Request a connected-product architecture and data-flow diagram; credential provisioning and reset procedure; public vulnerability-disclosure URL; published security-update period; firmware history and hardware support matrix; update authenticity and recovery approach; exact-model Statement of Compliance; incident and recall contacts; change-notice rules; and an end-of-support plan.

For private label, settle the brand owner's role before artwork approval. A factory may operate engineering and cloud services, but the party presenting itself as manufacturer cannot assume every market-facing duty disappears by contract. The OEM microinverter manufacturer solution helps freeze brand, model, manuals, firmware, warranty and change control as one commercial configuration.

Use five hold points before shipment

  1. Scope gate: product boundary, consumer availability, territory, exclusions and economic-operator roles recorded
  2. Evidence gate: three security requirements and exact-model Statement of Compliance reviewed
  3. Sample gate: credentials, reset, pairing, reporting route and update behavior checked
  4. Production gate: hardware, firmware, gateway, app, cloud and documents under change control
  5. Shipment gate: statement delivery, support information, traceability and incident contacts reverified

Use a purchase-order clause such as:

Supply of the connected microinverter system for the UK is conditional on documented PSTI applicability, compliant credential design, an operational vulnerability-reporting route, a published minimum security-update period, an exact-product Statement of Compliance and prior written review of changes to hardware, firmware, gateway, app, cloud service or product documentation.

The Office for Product Safety and Standards is the enforcement authority and can use compliance, stop and recall notices as well as monetary penalties. Treat the file as a maintained control system rather than a document collected after production.

Next step for a UK Wi-Fi microinverter RFQ

Send the target territory, sales channel, brand arrangement, microinverter and gateway models, connection architecture, annual volume, required support period and G98/G99 route through TMG Contact. TMG can organize a product-boundary, evidence and sample-review matrix; final legal classification and market-placement decisions remain with the responsible economic operators and authorities.

Project Support

Turn the reading into a workable configuration.

Send your module datasheet, target market and operating requirements. We will help narrow down the suitable platform.