On December 4, 2025, the PSTI (Product Security and Telecommunications Infrastructure – relevant connectable products security requirements regulations) issued its latest revision: within the existing “security requirements” compliance framework, recognition of Japan’s JC-STAR STAR-1 and Singapore’s Cybersecurity Labelling Scheme (CLS) has been added, allowing them, under specified conditions, to serve as alternative “deemed-to-comply” pathways.
Japan JC-STAR STAR-1 is the entry-level label under Japan’s IoT product cybersecurity labeling scheme, used to demonstrate that a connected product meets a set of baseline security technical requirements. The Singapore Cybersecurity Labelling Scheme (CLS), operated by the Cyber Security Agency of Singapore (CSA), is a multi-tier (Level 1–4) cybersecurity labeling framework for consumer IoT devices: the higher the level, the more stringent the requirements and assessment.
This PSTI revision amends the provisions under Schedule 2 relating to the core security requirements for connectable products (covering “deemed-to-comply” conditions corresponding to password requirements, vulnerability disclosure channels, software/security update information, etc.). The regulatory text has been revised from a single-condition structure to a multi-path structure allowing compliance through Condition A / Condition B / Condition C. The two newly added pathways provide that, where a product holds a valid JC-STAR STAR-1 label or a Singapore CLS label (at any level), it may be deemed to satisfy the relevant requirements within the scope specified by the regulations, and may also be deemed to meet the requirement that the product be accompanied by a Statement of Compliance (SoC).
This revision indicates that while maintaining baseline security requirements for connectable products, the UK is accelerating alignment with mature cybersecurity labeling schemes in the Asia-Pacific region.
Relevant information
CRA Implementation Enters a Critical Phase
In August 2026, preparations for the implementation of the EU Cyber Resilience Act (CRA) entered a critical stage. With the reporting obligations set to take effect on September 11, 2026, drawing near, the European Commission and the European Union Agency for Cybersecurity (ENISA) have been intensively issuing implementation guidance and materials related to the single reporting platform.
Canada's ISED Officially Releases RSS-310 Issue 6: Major Updates to Radio Frequency Equipment Requirements
Innovation, Science and Economic Development Canada (ISED) has formally issued RSS-310, Issue 6, “Licence-Exempt Radio Apparatus: Category II Equipment,” replacing Issue 5, which has been in effect since 2020