EMC China Lab

What are the UK PSTI Regulations?

Views :
Update time : 2025-11-04

In December 2022, the United Kingdom passed the "Product Security and Telecommunications Infrastructure Act 2022" (PSTI Act), which officially came into effect on April 29, 2024. This regULation affects most connected products, requiring relevant businesses to strictly comply with the PSTI Act. So, what does the UK's PSTI Act entail, and how should relevant businesses comply? Let's explore this in depth with you!

 

What are the UK PSTI Regulations?(图1)


What is PSTI?

PSTI stands for The Product Security and Telecommunications Infrastructure, an important regulation concerning product security and telecommunications infrastructure. The Act mandates the security of internet-connected consumer products, aiming to protect consumers from hacking and cyberattacks.

 

The Act requires relevant manufacturers, importers, or distributors to comply with its requirements and stipulates that products must meet minimum security standards before being marketed in the UK.

 

Products CoveRED by PSTI

The PSTI Act stipulates that consumer products that can connect to the internet or other networks must comply with product security requirements. Common products include:

 

- Smartphones

- Internet-connected cameras, TVs, and speakers

- Internet-connected toys and baby monitors

- Internet-connected security products (smoke detectors, door locks, alarms, etc.)

- IoT hubs and bases connecting multiple devices

- Wearable fitness trackers

- Home automation and alarm systems

- Outdoor recreational products such as handheld GPS devices

- Smart home assistants

- Smart home appliances (washing machines, refrigerators, etc.)

 

Excluded products include:

- Certain products supplied in Northern Ireland

- Electric vehicle charging stations

- Medical devices

- Smart meter products

- Desktop computers, laptops, and tablets without cellular connectivity (unless specifically designed for children under 14)

 

How to Comply with the Requirements?

1. Product Security Requirements

 

The PSTI Act requires that manufacturers, importers, and distributors of connected products meet security requirements, which include the following three main aspects:

 

- Prohibition of default passwords

- Implementation of a method to manage vulnerability reports

- Transparency about the period during which the product will receive important security updates

 

Sellers can assess or demonstrate product compliance with the PSTI Act by referring to the cybersecurity standard for consumer IoT, ETSI EN 303 645.

 

2. Statement of Conformity Requirements

 

Connected products covered by the PSTI Act must also be accompanied by a Statement of Conformity (SOC), which must include the following information:

 

- Product information (type, batch number, etc.)

- Name and address of each manufacturer or their authorized representative

- SOC prepared by the manufacturer or their authorized representative

- Statement that the product meets the relevant security requirements of Schedule 1 of the PSTI Act or the conditions for meeting security requirements in Schedule 2 of the PSTI Act

- Product support duration specified by the manufacturer when the product is first supplied

- Signatory information (including the name, position, place, and date of signing)

 

In summary, the main documents sellers need to prepare are the ETSI en 303 645 test report and the Statement of Conformity.

 

Additionally, connected products covered by the PSTI Act may also involve CE and WEEE certifications. Sellers importing such products into the UK should prepare the relevant documents and files in advance to avoid any sales disruptions due to insufficient preparation.


Email:hello@jjrlab.com


Leave Your Message


Write your message here and send it to us


Related News
Read More >>
Infant Support Pillow 16 CFR 1243/1242 & ASTM Infant Support Pillow 16 CFR 1243/1242 & ASTM
12 .19.2025
Infant Support & Nursing Pillows must meet CPSC 2025 rules, including 16 CFR 1243/1242 & AST...
BRM Registration Card Under CFR Part 1130 Regulati BRM Registration Card Under CFR Part 1130 Regulati
12 .19.2025
Required for CFR Part 1130 infant products, the BRM Card supports CPC compliance and U.S. address ve...
How to get a D-U-N-S® Number for US FDA Registrati How to get a D-U-N-S® Number for US FDA Registrati
12 .18.2025
Get your D-U-N-S® Number for FDA registration. JJR LAB helps medical device firms apply fast, meet t...
Household Massage Devices Compliance in the China Household Massage Devices Compliance in the China
12 .18.2025
JJR LAB ensures household massage devices comply in China & Japan: CQC (GB4706.1/10), PSE (J/IEC...
Compliance for the Global In Vitro Diagnostic (IVD Compliance for the Global In Vitro Diagnostic (IVD
12 .18.2025
JJR LAB, ISO/IEC 17025 certified, offers one-stop IVD device compliance testing & certification ...
Compliance Guide for Nebulizers in European and Am Compliance Guide for Nebulizers in European and Am
12 .18.2025
JJR LAB provides CE/FDA nebulizer testing (IEC 60601, ISO 27427, ISO 18562, ISO 10993) covering perf...
Cybersecurity Certification Service for EU RED Dir Cybersecurity Certification Service for EU RED Dir
12 .18.2025
JJR Lab provides RED 3.3(d/e/f) compliance via EN18031-1/2/3 testing, offering asset review, securit...
ANATEL Certification Compliance Guide for Brazil M ANATEL Certification Compliance Guide for Brazil M
12 .18.2025
ANATEL compliance ensures RF/EMC/safety testing to Brazil standards; required for wireless/network d...

Leave Your Message