EMC China Lab

UK PSTI Compliance Overview

Views :
Update time : 2024-10-25

Introduction to uk psti Cybersecurity Law  

Starting April 29, 2024, the UK will enforce the cybersecurity provisions under the Product Security and Telecommunications Infrastructure (psti) Act of 2023, impacting consumer-connected devices across England, Scotland, Wales, and Northern Ireland. With less than four months until implementation, manufacturers exporting to the UK shoULd expedite PSTI complianCE certification to ensure smooth market entry.

 

PSTI Act Details  

The UK’s Consumer Connectable Product Security Scheme will take effect on April 29, 2024, mandating minimum security requirements for connectable products. These standards align with the UK's IoT security guidelines, the globally recognized ETSI EN 303 645, and recommendations from the UK’s National Cyber Security Centre. The scheme will also require other supply chain businesses to prevent the sale of insecure consumer products within the UK.

 

PSTI Act Legislation Includes:  

- Part 1 of the 2022 Product Security and Telecommunications Infrastructure (PSTI) Act  

- 2023 Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations  

 

PSTI Act Timeline  

- Approved: December 2022  

- Draft Published: April 2023  

- Enacted into Law: September 14, 2023  

- Enforcement Date: April 29, 2024  

 

Key PSTI Documents  

1. UK PSTI Act Overview (https://www.gov.uk/government/publications/the-uk-product-security-and-telecommunications-infrastructure-product-security-regime)  

2. 2022 Product Security and Telecommunications Infrastructure Act (https://www.legislation.gov.uk/ukpga/2022/46/part/1/enacted)  

3. 2023 PSTI Security Regulations (https://www.legislation.gov.uk/uksi/2023/1007/contents/made)  

 

Scope of Products under PSTI  

The PSTI Act covers Internet-connectable products, including but not limited to smart TVs, IP cameras, routers, and smart home products.  

Exceptions (Schedule 3 Excepted Products) include:  

- Desktop computers, laptops, tablets (without cellular connectivity), medical devices, smart meters, EV chargers, and Bluetooth single-point devices. While these products may have cybersecurity requirements, they fall outside PSTI scope and may be governed by other laws.

 

PSTI Compliance Requirements  

The PSTI Act's security requirements focus on:  

1. Secure default passwords  

2. Vulnerability reporting and management  

3. Software updates  

 

Compliance can be demonstrated through direct assessment under the PSTI Act or by meeting standards outlined in ETSI EN 303 645, fulfilling all three requirements.

 

ETSI EN 303 645 IoT Security Standards  

Thirteen categories include:  

1. Default password security  

2. Vulnerability management  

3. Software updates  

4. Secure storage of sensitive data  

5. Communication security  

6. Minimizing exposure  

7. Data protection  

8. Software integrity  

9. System resilience  

10. Telemetry checks  

11. Data deletion  

12. Simplified device setup  

13. Input validation  

 

PSTI and ETSI en 303 645 testing Process  

To demonstrate PSTI compliance, manufacturers must meet minimum standards for passwords, software maintenance, and vulnerability reporting. Evaluation reports and self-declaration of compliance are requiRED. ETSI EN 303 645 is recommended as a dual compliance measure, supporting both PSTI and upcoming EU ce red cybersecurity directives, effective August 1, 2025.

 

Service Advantages  

- R&D phase cybersecurity consulting and evaluation  

- CE RED directive cybersecurity consulting and evaluation  

- California SB-327 compliance consulting  

- UK PSTI compliance consulting  

- fcc voluntary cybersecurity certification consulting  

- Cybersecurity consulting for Brazil, Singapore, and global markets


Email:hello@jjrlab.com


Leave Your Message


Write your message here and send it to us


Related News
Read More >>
 RCM AS/NZS CISPR 32:2023 Testing for Power Adapte RCM AS/NZS CISPR 32:2023 Testing for Power Adapte
02 .02.2026
JJR provides CMS/EMC testing per AS/NZS CISPR 32:2023 via a CNAS & ISO/IEC 17025 accredited lab,...
How to get Australia SAA Compliance? How to get Australia SAA Compliance?
02 .02.2026
Entering the AU/NZ market requires SAA compliance based on AS/NZS standards, with testing by CMS, CN...
Does Canada Require RoHS Compliance Does Canada Require RoHS Compliance
02 .02.2026
Canada controls hazardous substances under CEPA. RoHS testing to IEC standards is recommended. CMS, ...
EU CE LVD, EMC, RoHS Directives Compliance Guide EU CE LVD, EMC, RoHS Directives Compliance Guide
02 .02.2026
EU CE LVD, EMC, RoHS compliance guide covering standards, testing and DoC, with CMS, CNAS, ISO/IEC 1...
Quick Guide to the CE-LVD Low Voltage Directive Quick Guide to the CE-LVD Low Voltage Directive
02 .02.2026
CE-LVD ensures electrical products meet EU safety rules within voltage limits, tested to EN standard...
Global Certification Guide for Lithium Batteries Global Certification Guide for Lithium Batteries
02 .01.2026
Lithium battery certifications in Thailand, Korea, India, Australia, and Saudi Arabia. CMS/CNAS/ISO/...
Compliance of Amazon 18650 Lithium Battery Product Compliance of Amazon 18650 Lithium Battery Product
02 .01.2026
Amazon 18650 batteries face removal; sellers must meet UN38.3, UL, FCC, MSDS standards. JJR CMS, CNA...
What is CE Certification and EU Authorized Represe What is CE Certification and EU Authorized Represe
02 .01.2026
CE Certification requires an EU Authorized Representative. JJR labs (CMS, CNAS, ISO/IEC 17025) provi...

Leave Your Message