Writing · Connected products

PSTI: the UK product security law that already applies to you

If you sell a connected product to UK consumers, the deadline was April 2024. Here is what it asks, and why doing the CRA work anyway is the sensible answer.

When I talk to UK companies about the EU Cyber Resilience Act, the most common reaction is relief that it is an EU law with a 2027 date. The second most common is surprise when I mention that the UK has had its own product security law in force since April 2024, that it applies to them today, and that they have never heard of it. This piece is for the second group.

What PSTI is

PSTI is the product security part of the Product Security and Telecommunications Infrastructure Act 2022, brought into force by regulations on 29 April 2024. It applies to consumer connectable products made available to consumers in the UK: anything that can connect to the internet or to a network, sold for consumer use. An e-scooter with an app, a smart doorbell, a connected kettle, a fitness tracker, a games console, a baby monitor. Some categories are excluded because other rules cover them, medical devices and smart meters among them, and desktop and laptop computers are largely outside it; if in doubt, check the exclusions rather than assume.

The duties fall on the manufacturer first, but importers and distributors have duties too, so a UK company bringing in a product made elsewhere is caught as the importer. Enforcement is by the Office for Product Safety and Standards, which can require products to be withdrawn or recalled and can fine up to £10 million or four per cent of worldwide revenue, whichever is higher.

The three requirements, and the statement

Compared with the CRA, PSTI is short. It asks for three things and a piece of paper.

No universal default passwords. Every unit must ship with a password that is unique to it or set by the user, and the unique ones must not be derivable from public information or from a counter. The days of admin, admin are over, and so are the days of a password printed on a sticker that is the same on every unit in the batch.

A way to report security issues. You must publish how someone can tell you about a vulnerability, and the timescales in which they will get an acknowledgement and status updates. A generic contact address is not enough; a named route with response times is.

A published minimum security update period. You must state, in a place a buyer can see before purchase, the minimum period for which the product will receive security updates. The law does not set how long that period must be, which is a real difference from the CRA, but it must be stated and it must be kept.

The statement of compliance. A statement, from the manufacturer, that the product meets the requirements, which must accompany the product and which importers and distributors must not sell without. It is a short document, but it is a legal statement with a name on it.

The technical standard behind all of this is ETSI EN 303 645, the consumer IoT security baseline. If you meet the relevant provisions of that standard you are treated as meeting the requirements, and it is the document to hand your engineers.

Why most companies have missed it

PSTI arrived without a compliance deadline campaign, in the same year as a general election, and it is a piece of telecommunications legislation with product security bolted on. Companies with a regulatory function found it; companies of fifty to three hundred people with an engineering team and no compliance department mostly did not. In the readiness conversations I have had, the default-password requirement is usually met by accident, because unique credentials are now common in modern platforms, and the other two are usually missed entirely: there is no published disclosure route and no stated update period, because nobody knew to publish them.

The fix for those two is a page on the website and a line in the product listing. It is a day's work. The statement of compliance is an afternoon. If you sell to UK consumers and have not done these, do them this month; they are the least effort per unit of legal exposure of anything in product security.

Why to do the CRA work anyway

A UK company selling only to UK consumers is not caught by the CRA. That is true today and worth saying plainly. It is also, in my experience, a weaker position than it looks, for three reasons.

First, the overlap. PSTI is roughly a third of the CRA: the password rule, the disclosure route and the stated update period are three of the CRA's obligations in lighter form. The remaining two-thirds, the ones that take longest, are the update capability behind the stated period, the bill of materials, the vulnerability process with a named owner, the testing, the documentation and the conformity route. If you do the CRA work you have done PSTI; if you do PSTI alone you have done the easy third.

Second, the market. Your customers, your distributors and your competitors sell into the EU or plan to. An EU distributor will ask for CRA conformity from December 2027, an acquirer or lender will ask before then, and a customer who sells your product on will ask as soon as their own compliance team notices. The first EU sale brings the CRA with it, and the reporting duties from the first day.

Third, the direction of travel. PSTI was written to align with the same standard the CRA draws on, the UK has said it will keep its regime in step with international standards, and every revision so far has moved towards more, not less. Building to PSTI's minimum is building to a floor that is being raised.

So the advice I give UK companies is the same whichever side of the Channel they sell on: do the three PSTI items now, this month, because they are quick and they are the law; then work through the CRA's eight in the order that takes longest, because that is where the real security is and where your market is going. The CRA Readiness Check on this site covers both; each question notes where PSTI already asks for the same thing.

Three things worth taking seriously

For anyone selling a connected product to UK consumers: publish the disclosure route with response times and the minimum update period this month, remove any universal default password from the next build, and write the statement of compliance. Then you are legal.

For importers and distributors: you may not sell a product without the manufacturer's statement of compliance. Ask for it; if it does not exist, you are the one holding the exposure.

For boards: ask whether the company's consumer products carry a statement of compliance and a stated update period. It is a yes-or-no question, and the answer has been required since April 2024.

I am an engineer, not a lawyer. This is the engineer's map of PSTI, not legal advice; the exclusions and the detail of the requirements are in the regulations and in ETSI EN 303 645.


Does your product listing state a minimum security update period? If you had to look, that is the answer.

See where you stand against PSTI and the CRA in ten minutes with the CRA Readiness Check, or talk it through with me first.

© 2026 Catherine Ives-Yim. All rights reserved.

Catherine Ives-Yim

Catherine Ives-Yim

Chartered Engineer and independent technical adviser, with a lifetime at the bleeding edge of embedded systems, connected products, data platforms and AI-assisted engineering, who has advised clients across the UK, Europe, the Middle East, the Far East, North America and Africa. Based in Leeds.