Information Center
Information Center
Knowledge Center
2023-06-30

The UK Product Security and Telecommunications Infrastructure (Product Security) regime

Share:

In December 2022, the UK passed the Product Security and Telecommunications Infrastructure Act 2022, referred to as PSTI.

The Act consists of two main parts.


PART 1 Product security

For the requirements of Part 1 of the Product Security and Telecommunications Infrastructure Act 2022, the Department for Science, Innovation and Technology (DSIT) has formulated the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 [draft], which will require manufacturers of UK consumer-connectable products to comply with minimum security requirements. This draft has yet to be passed by the British Parliament.

 

PART 2 Telecommunications infrastructure

Because many of the connected products on the market today suffer from fundamental cybersecurity flaws, as these products become more globally pervasive, they become easier targets for cybercriminals and can have significant risk for consumers and infrastructure. Therefore, the product must have basic protective measures.

 

This security regime is expected to come into effect on April 29, 2024. And from that date, companies involved in the supply chain of these products will need to comply with this legislative framework. A grace period of 12 months is expected from the date of publication until implementation.

 

The new cybersecurity regime is mandatory and applies to all connected consumer products made available to UK consumers, regardless of how they are sold. Typical products include IoT appliances such as smartphones, tablets, laptops, connected toys, connected monitors, smart doorbells, washing machines and refrigerators.

 

The security requirements in the regulation, the main requirements are derived from and related to the three major principles of the Code of Practice for Consumer IoT Security and the requirements of the ETSI EN 303 645 standard.

 

According to the Act, the use of easy-to-guess preset passwords will be banned, and relevant manufacturers must be more transparent about product security update periods and establish a better public reporting system for product vulnerabilities. If the operator violates the regulations, depending on the circumstances, it may face a fine of up to 10 million pounds or 4% of the global turnover, and if it continues to violate the regulations, it may face a daily fine of up to 20,000 pounds.

 

As this regulation is still under review, we will continue to monitor any updates.

 

What to do now?

It is suggested to consider the key safety priorities established in the code as a reference frame for product design.

Perform ETSI EN 303 645 test.

 



Relevant information

Canada ISED Update No.2 | RSS Gen Issue 6: Analysis of General Compliance Standards for Radio Frequency Equipment
2026-08-21

Canada ISED Update No.2 | RSS Gen Issue 6: Analysis of General Compliance Standards for Radio Frequency Equipment

Last week, we mentioned that Innovation, Science and Economic Development Canada (ISED) released RSS 310 Issue 6: Licence Exempt Radio Frequency Devices...

CRA Implementation Enters a Critical Phase
2026-08-21

CRA Implementation Enters a Critical Phase

In August 2026, preparations for the implementation of the EU Cyber Resilience Act (CRA) entered a critical stage. With the reporting obligations set to take effect on September 11, 2026, drawing near, the European Commission and the European Union Agency for Cybersecurity (ENISA) have been intensively issuing implementation guidance and materials related to the single reporting platform.

Canada's ISED Officially Releases RSS-310 Issue 6: Major Updates to Radio Frequency Equipment Requirements
2026-08-03

Canada's ISED Officially Releases RSS-310 Issue 6: Major Updates to Radio Frequency Equipment Requirements

Innovation, Science and Economic Development Canada (ISED) has formally issued RSS-310, Issue 6, “Licence-Exempt Radio Apparatus: Category II Equipment,” replacing Issue 5, which has been in effect since 2020

Privacy Preference Center

We use cookies to allow our website to function properly, personalize content and advertisements, provide social media features, and analyze traffic. We also share information about your use of our website with our social media, advertising, and analytics partners.

View Privacy Policy

Manage consent settings

Necessary Cookies

Uniformly activate

The operation of the website relies on these cookies, and you cannot disable them in the system. These cookies are typically set based on your actions (i.e., service requests), such as setting privacy preferences, logging in, or filling out forms. You can configure your browser to block or prompt you about these cookies, but this may cause certain website functionalities to not work.

Select Language