UK Product Security and Telecommunications Infrastructure Act 2022
The Product Security and Telecommunications Infrastructure (PSTI) Act 2022 is a UK law designed to improve the cybersecurity of connectable and consumer products. It exists to prevent large-scale cyber attacks by mandating basic security requirements for devices that can connect to the internet or other wireless networks.
Who it applies to
- Manufacturers of "connectable" and "consumer" products sold on the UK market.
- Importers who bring connectable products into the UK from overseas.
- Distributors responsible for ensuring that the products they supply meet legal requirements.
- Organisations producing any device capable of connecting to a network, regardless of whether its primary function is "smart" connectivity.
How it works
The PSTI Act functions as a set of statutory security requirements rather than a voluntary certification scheme. It mandates specific outcomes—such as the prohibition of universal default passwords and the requirement for manufacturers to publish a vulnerability disclosure policy—that must be integrated into the product lifecycle.
Compliance is primarily achieved through self-assessment and internal documentation. There is no official government body that issues a "PSTI Certificate"; instead, organisations must maintain evidence that their products meet the legal requirements to avoid enforcement actions.
The Office for Product Safety and Standards (OPSS) and other relevant authorities monitor compliance. If a product is found to be non-compliant, the regulator can issue notices requiring the manufacturer to correct the deficiency or face significant financial penalties.
Getting started
- Conduct an inventory of all products sold in the UK to identify which qualify as "connectable" or "consumer" devices under the Act.
- Audit current password configurations to ensure no device uses a universal default password (e.g., "admin" or "1234").
- Establish and publish a clear vulnerability disclosure policy that allows security researchers to report flaws safely.
- Determine the minimum period for which security updates will be provided for each product and make this information transparent to consumers before purchase.
- Compile a technical file for each product containing evidence of how the specific PSTI requirements have been met.
Controls & requirements
- Which consumer connectable products are in scope
- The ban on universal default passwords
- The vulnerability disclosure policy requirement
- Transparency about security update support periods
- The statement of compliance
- Duties on manufacturers, importers and distributors
- OPSS enforcement and penalties
- How PSTI compares to the EU Cyber Resilience Act
Common misconceptions
- It only applies to "Smart Home" devices; in reality, it covers any connectable product, including industrial or medical devices if they are sold as consumer products.
- There is a formal government certification process to follow; compliance is actually based on meeting the legal mandates and maintaining documentation for regulatory inspection.