EMC China Lab

UK PSTI Statement of Compliance

Views :
Update time : 2024-10-28

Product Security and Telecommunications Infrastructure Act (PSTI), UK

The UK Government passed the Product Security and Telecommunications Infrastructure Act 2022 (referred to as the "PSTI" Act), which will come into effect on April 29, 2024. This legislation mandates all companies involved in the consumer IoT supply chain to comply with minimum security requirements. These security standards are based on the UK’s Code of Practice for Consumer IoT Security / ETSI EN 303 645 standards, alongside guidelines from the National Cyber Security Centre, the UK's authority on cybersecurity threats. Manufacturers, importers, and distributors of related products must adhere to the PSTI Act’s security protocols, with non-compliance potentially resulting in fines of up to £10 million or 4% of global turnover.

 UK PSTI Statement of Compliance(图1)

Importance of IoT Security for Devices

- Recent global cybersecurity incidents have highlighted serious IoT security threats across industries.

- Many countries are now implementing mandatory IoT security regulations.

- Real-world scenarios reveal multiple security challenges.

- Cybersecurity regulations establish standardized security protocols for connected devices.

 

UK PSTI Act Overview

Required Measures:

 

- No Universal Default Passwords: Devices must not use universal, default passwords.

- Mandatory Reporting of Security Issues: Security vulnerabilities must be reported promptly.

- Pre-Sale Security Information: Manufacturers must inform consumers of the product’s security update support period on their websites before purchase.

 

Applicable Devices:

 

- Smart home/voice assistant devices

- Smartphones

- Connected cameras (IP and CCTV); wearables

- IoT hubs and gateways linking multiple devices

- Home automation devices, smart doorbells, and alarm systems

 

Additional Compliance Frameworks:

- RED-DA and UK PSTI: These frameworks address connection standards and security for wireless devices.

- ETSI EN 303 645: A network security standard for wireless devices, covering most RED-DA (RED Articles 3.3) requirements and fully aligned with UK PSTI law.

- CEN/CENELEC Standards Harmonization: Efforts are underway to develop harmonized standards relevant to the RED-DA.

- Connectivity Requirements: All connected devices, regardless of wireless support, are regulated under these frameworks.

- Legal Reference Framework: The UK PSTI Act references the ETSI EN 303 645 framework.


Email:hello@jjrlab.com


Leave Your Message


Write your message here and send it to us


Related News
Read More >>
10993 Biocompatibility Testing 10993 Biocompatibility Testing
12 .04.2024
JJR Laboratory offers ISO 10993 biocompatibility testing for medical devices, ensuring safety by ass...
How to Get a Biocompatibility Testing Report? How to Get a Biocompatibility Testing Report?
12 .04.2024
JJR Laboratory provides biocompatibility testing, including cytotoxicity, toxicity, and irritation t...
Is the EU CE-RED Certification Mandatory? Is the EU CE-RED Certification Mandatory?
12 .04.2024
The EU CE-RED certification is mandatory for wireless products entering the European market. JJR Lab...
EU CE/RED Certification Process EU CE/RED Certification Process
12 .04.2024
JJR Laboratory offers CE/RED certification services, ensuring wireless products meet EU standards fo...
CE Certification: RED Radio Equipment Directive an CE Certification: RED Radio Equipment Directive an
12 .04.2024
The CE RED Directive ensures wireless device safety and compliance. JJR Labs provides RED testing an...
How to Apply for Wireless CE Certification? How to Apply for Wireless CE Certification?
12 .04.2024
JJR Lab offers wireless CE-RED certification services, including EMC, LVD, and RF testing for wirele...
FCC Certification and Documentation Requirements FCC Certification and Documentation Requirements
12 .03.2024
FCC certification ensures product safety in wireless and non-wireless devices. JJR Lab offers FCC ID...
FCC Certification Requires a U.S. Local Agent FCC Certification Requires a U.S. Local Agent
12 .03.2024
FCC requires a U.S. local agent for equipment authorization. China JJR Laboratory offers agent servi...

Leave Your Message