EMC China Lab

What is the UK PSTI Regulation?

Views :
Update time : 2025-04-09

uk psti RegULation Overview

The Product Security and Telecommunications Infrastructure Act 2022 (psti Act), enacted in the UK, officially comes into force on April 29, 2024. The regulation mandates that manufacturers, importers, and distributors of IoT products must comply with specific cybersecurity requirements. Violations can result in fines up to £10 million or 4% of the company’s global turnover, and a daily penalty of £20,000 for continuous non-compliance.

 

Key Compliance Requirements

1. No Universal Default Passwords

- Each product must have a unique password, or allow the user to define one.

- The use of a common or hardcoded default password is strictly prohibited.

- Passwords must not include encryption keys, pairing PINs, or API keys.

 

Reference Standards:

ETSI EN 303 645 (Sections 5.1-1 and 5.1-2)

 

2. Vulnerability Disclosure Policy

- Manufacturers must provide at least one channel for users or external parties to report security vulnerabilities.

- The reporting mechanism must be accessible, clear, and free to use, without requiring personal information.

- Users must receive status updates on their reports until the issue is resolved.

 

Reference Standards:

ETSI EN 303 645 (Section 5.2-1), ISO/IEC 29147:2018 (Clause 6.2)

 

3. Transparency of Support Period for Security Updates

- Companies must publish the defined support period during which security updates will be provided.

- Once published, shortening this support period is not allowed.

- This information must be made available in a clear and transparent way.

 

Reference Standards:

ETSI EN 303 645 (Section 5.3-13)

 

Scope of Products CoveRED by PSTI

Included Products:

- Connected security-related devices: smoke detectors, fire alarms, smart locks

- Smart home and automation devices: smart doorbells, alarm systems, IoT hubs

- Consumer electronics: smartphones, smart assistants, wearables

- Connected appliances: smart fridges, washing machines, coffee makers

- Other devices: connected cameras (IP and CCTV), game controllers, and similar products

 

Exempted Products:

- Products sold in Northern Ireland

- Smart meters, EV charging points, medical devices

- Computers and tablets intended for use by individuals aged 14 and above

 

JJR Testing Laboratory Services

JJR Laboratory in China is fully equipped with comprehensive testing capabilities and offers uk psti certification and testing services.

Feel free to contact us for more information or to get started!


Email:hello@jjrlab.com


Leave Your Message


Write your message here and send it to us


Related News
Read More >>
2026 FCC Certification and Compliance 2026 FCC Certification and Compliance
03 .15.2026
AIoT growth makes FCC compliance critical for global sellers. Using FCC Part 15 and CE standards, JJ...
What are the requirements of UL 62368-1:2025? What are the requirements of UL 62368-1:2025?
03 .15.2026
UL 62368-1:2025 updates AV/ICT safety: new component certification, coin-cell protection, power limi...
Electric Bicycle Certification in New South Wales, Electric Bicycle Certification in New South Wales,
03 .15.2026
NSW phases e-bike and e-scooter battery rules: Feb 2025 meet AS/EN/UL standards; Aug 2025 approval r...
What is the European Accessibility Act (EAA)? What is the European Accessibility Act (EAA)?
03 .14.2026
What is the European Accessibility Act (EAA)? : EU law from 28 June 2025 requiring digital products ...
Compliance Guidelines for India IS/IEC 62368-1:202 Compliance Guidelines for India IS/IEC 62368-1:202
03 .14.2026
ndia Compliance Guidelines for IS/IEC 62368-1:2023 replace IS13252-1 and IS616 and include XR device...
16 CFR Part 1512 Compliance Testing Laboratory 16 CFR Part 1512 Compliance Testing Laboratory
03 .13.2026
US bicycle market entry requires 16 CFR Part 1512 compliance. JJR Lab, CPSC-accredited, provides tes...
Electromagnetic Compatibility and Interference Tes Electromagnetic Compatibility and Interference Tes
03 .13.2026
EMC testing ensures devices work without interference by checking EMI emissions and EMS immunity und...
What is 21 CFR Part 11 Compliance and Regulations What is 21 CFR Part 11 Compliance and Regulations
03 .13.2026
21 CFR Part 11 is an FDA rule defining how electronic records and e-signatures must be managed so th...

Leave Your Message