Auditen
Home / Frameworks / UK PSTI / How PSTI compares to the EU Cyber Resilience Act

How PSTI compares to the EU Cyber Resilience Act

Comparing PSTI and the EU CRA requires identifying overlapping security baselines while distinguishing between their different scopes and enforcement mechanisms. While UK PSTI focuses on baseline requirements for consumer connectable products, the EU CRA is a broader framework introducing risk-based tiers and mandatory CE marking for most products with digital elements.

What it means

In practice, this comparison is about mapping two different regulatory philosophies. The UK PSTI Act acts as a "security floor," targeting common vulnerabilities like default passwords and lack of update transparency specifically for the consumer market. It is designed to be straightforward and focused on preventing large-scale botnets and basic attacks.

The EU CRA is significantly more comprehensive, covering almost all products with digital elements regardless of whether they are for consumers or industrial use. It introduces a tiered risk system (Uncritical, Critical, Highly Critical) where higher-risk products face stricter conformity assessments and third-party audits before they can be placed on the market.

For an implementer, this means that while many technical controls overlap—such as vulnerability management and secure defaults—the administrative burden of the CRA is higher due to its integration with EU market access laws (CE marking) and more rigorous documentation requirements throughout the product lifecycle.

How to meet it

Evidence an auditor asks for

  • A product inventory identifying which devices fall under PSTI, CRA, or both, including their assigned risk tier under the CRA.
  • The public-facing Vulnerability Disclosure Policy and a log of vulnerabilities received, tracked, and patched.
  • Firmware configuration files or setup guides proving that default passwords are not used.
  • Customer-facing documentation (e.g., on the website or packaging) explicitly stating the security update support window for each product.
  • The EU Declaration of Conformity and associated technical files required for CE marking under the CRA.

Common pitfalls

  • Assuming that meeting EU CRA requirements automatically satisfies UK PSTI, ignoring specific UK reporting obligations to the OPSS.
  • Applying a generic security standard across all products instead of adopting the risk-based approach mandated by the CRA's different product classes.
  • Failing to maintain an accurate "End of Life" (EOL) schedule