PSTI IoT Compliance
for Connected IoT Products

Navigating
the PSTI Regulation Act

Find out how to build cyber security resilience into your IoT products and comply with the PSTI Act and Regulations.

Research by Viakoo revealed that 55% of IoT cyber incidents could have been prevented with better security. In the past year, 50% of companies faced an IoT cyber incident, with 44% being serious and 22% threatening operations. The Product Security and Telecommunications Infrastructure (PSTI) Act addresses the growing need for IoT security. This whitepaper explores the PSTI Act, its importance, required IoT security regulations, and the necessity of designing devices with embedded security.

The Product Security and Telecommunications Infrastructure (PSTI) Act, passed by the UK Parliament in 2022, regulates security for connected consumer products. Effective from April 29, 2024, the UK’s regime is governed by the PSTI Act 2022 and the PSTI Regulations 2023. The Office for Product Safety and Standards (OPSS) enforces these regulations, ensuring consumer and business protection from product-related harm, and has the authority to take action against non-compliance.

A pivotal legislative framework designed to address the evolving landscape of digital security."

  1. A unique password for every product
  2. Manufacturers to provide guidance on reporting product security issues
  3. Consumers to be made aware of minimum security update periods

Smart consumer devices and products have, in the past, been compromised at scale by cyber criminals. The objective of the PSTI Act and new Regulations is to prevent such security breaches in smart devices.

Some of the issues that require attention that are covered as part of the ETSI EN 303 645 standard are:

  • Strengthening default passwords.
  • Vulnerabilities to hacking
  • Exposure to physical tampering
  • Secure data processing and sending

There has always been a best practise, but nothing has been enforced."

Part 1 of the Act indicates that obligations are imposed upon manufacturers, importers and distributors of these products, defined as follows:

IoT infrastructure PSTI-compliant

Is your IoT PSTI-compliant?

Contact us to arrange a security consultation with one of our specialists today.

That obligations are imposed upon manufactors, importers and distributors of these products."