Auditen
Home / Frameworks / UK PSTI

UK Product Security and Telecommunications Infrastructure Act 2022

The Product Security and Telecommunications Infrastructure (PSTI) Act 2022 is a UK law designed to improve the cybersecurity of connectable and consumer products. It exists to prevent large-scale cyber attacks by mandating basic security requirements for devices that can connect to the internet or other wireless networks.

Who it applies to

  • Manufacturers of "connectable" and "consumer" products sold on the UK market.
  • Importers who bring connectable products into the UK from overseas.
  • Distributors responsible for ensuring that the products they supply meet legal requirements.
  • Organisations producing any device capable of connecting to a network, regardless of whether its primary function is "smart" connectivity.

How it works

The PSTI Act functions as a set of statutory security requirements rather than a voluntary certification scheme. It mandates specific outcomes—such as the prohibition of universal default passwords and the requirement for manufacturers to publish a vulnerability disclosure policy—that must be integrated into the product lifecycle.

Compliance is primarily achieved through self-assessment and internal documentation. There is no official government body that issues a "PSTI Certificate"; instead, organisations must maintain evidence that their products meet the legal requirements to avoid enforcement actions.

The Office for Product Safety and Standards (OPSS) and other relevant authorities monitor compliance. If a product is found to be non-compliant, the regulator can issue notices requiring the manufacturer to correct the deficiency or face significant financial penalties.

Getting started

  1. Conduct an inventory of all products sold in the UK to identify which qualify as "connectable" or "consumer" devices under the Act.
  2. Audit current password configurations to ensure no device uses a universal default password (e.g., "admin" or "1234").
  3. Establish and publish a clear vulnerability disclosure policy that allows security researchers to report flaws safely.
  4. Determine the minimum period for which security updates will be provided for each product and make this information transparent to consumers before purchase.
  5. Compile a technical file for each product containing evidence of how the specific PSTI requirements have been met.

Controls & requirements

Common misconceptions

  • It only applies to "Smart Home" devices; in reality, it covers any connectable product, including industrial or medical devices if they are sold as consumer products.
  • There is a formal government certification process to follow; compliance is actually based on meeting the legal mandates and maintaining documentation for regulatory inspection.