UK PSTI Act Compliance Software | IoT Product Security & Statement of Compliance Automation | Certivo - Certivo

UK PSTI Act Compliance

Cybersecurity & Data Protection Laws

Product Security and Telecommunications Infrastructure Act 2022

Every Consumer Smart Product Sold in the UK Must Now Meet 3 Mandatory Security Requirements. Can You Prove Compliance Across Your Entire Product Line?

PSTI compliance requires every manufacturer, importer, and distributor of consumer connectable products to ban default passwords, publish vulnerability disclosure policies, and declare security update support periods. Enforcement is live. Fines reach £10 million or 4% of global turnover.

Certivo automates PSTI evidence collection from supplier security attestations to audit-ready Statements of Compliance.

3

Mandatory security requirements for every connectable product

£10M

Maximum penalty or 4% of global turnover (whichever is greater)

10 years

Minimum record retention period for compliance documentation

Regulation Overview

What is the UK PSTI Act?

The UK PSTI Act is the world's first national legislation mandating minimum cybersecurity requirements for consumer connectable products. For supply chain and product compliance teams, the Act requires documented evidence that every internet-connectable and network-connectable product meets three baseline security requirements before it can be sold in the UK.

The three mandatory requirements align with the first three provisions of the ETSI EN 303 645 standard: ban on universal default passwords, a published vulnerability disclosure policy, and transparency on security update support periods. Manufacturers must issue a Statement of Compliance (SoC) for every product. Importers and distributors must verify the SoC accompanies each product before making it available.

PSTI compliance requires security evidence from every component supplier whose software or firmware is embedded in a connectable product. When products span multiple tiers of supply, tracing compliance back to each contributor becomes a supply chain data challenge.

Key Components / Sub-Frameworks

OPSS Is Actively Enforcing PSTI—With Powers to Issue £10M Fines, Stop Notices, and Public Disclosure of Non-Compliance.

The PSTI Act has been fully enforceable since April 29, 2024. OPSS can issue Compliance Notices, Stop Notices, Recall Notices, and Monetary Penalties up to £10 million or 4% of global turnover—plus daily penalties of £20,000 for ongoing violations. Products already in distribution channels must also comply. Non-compliance is a criminal offence.

Key Compliance Requirements

Who Must Comply

Key Thresholds

All consumer connectable products

Internet-connectable or network-connectable products not specifically exempted

£10M or 4% global turnover

Maximum monetary penalty for non-compliance (whichever is greater)

£20,000/day

Daily penalty for ongoing violations following enforcement notice

10 years

Minimum retention period for Statement of Compliance and compliance records

Core Obligations

  1. Password Security
    Ban universal default passwords; each device requires unique password or user-defined password
    DEADLINE: From April 29, 2024 (live)

  2. Vulnerability Disclosure Policy
    Publish accessible mechanism for external vulnerability reporting
    DEADLINE: From April 29, 2024 (live)

  3. Security Update Transparency
    Declare minimum support period for security updates in clear, consumer-accessible language
    DEADLINE: From April 29, 2024 (live)

  4. Statement of Compliance
    Prepare SoC and ensure it accompanies every product sold
    DEADLINE: From April 29, 2024 (live)

  5. Record Retention
    Manufacturers and importers must retain SoC and investigation records
    DEADLINE: Minimum 10 years from date product is made available

PSTI-Specific Pain Points

The Default Password Discovery Problem

Your product portfolio spans 150 SKUs from 30 suppliers. OPSS requires proof that no product ships with a universal default password. Three suppliers use shared firmware with factory-set credentials. Two cannot confirm whether passwords are unique per device. Without component-level security attestations, you cannot verify compliance across your full range.

The Statement of Compliance Gap

Every connectable product needs a Statement of Compliance before it reaches consumers. The SoC must reference specific security requirements, include manufacturer details, and accompany the product. You have 80 product families, each with multiple firmware versions. Generating and managing SoCs at scale—while keeping them current with each update—overwhelms manual tracking.

The Supply Chain Blind Spot

PSTI holds you responsible for security requirements even when third-party firmware is embedded in your product. Your Tier 2 supplier provides a Wi-Fi module with its own software stack. Does it support vulnerability reporting? What is its security update commitment? Without structured supplier cybersecurity evidence, you inherit risk you cannot quantify.

The Multi-Market Compliance Collision

Your products ship to the UK and the EU. PSTI requires three security requirements now. The EU Cyber Resilience Act requires 21 essential requirements by December 2027. Both reference ETSI EN 303 645, but with different scopes and obligations. Managing parallel evidence streams across jurisdictions without a centralized compliance platform creates duplication, confusion, and gaps.

Certivo in Action

Certivo in Action—PSTI Workflow

GET EVIDENCE IN

Collect Security Attestations and Firmware Evidence from Every Supplier—Without the Chasing

CORA launches targeted campaigns to collect supplier cybersecurity declarations, password security confirmations, vulnerability disclosure evidence, and update commitments automatically.

MAKE SENSE OF IT

Know Instantly Which Products Meet All Three PSTI Security Requirements—and Which Don't

CORA parses supplier attestations, validates security evidence against PSTI's three mandatory requirements, and flags non-conformities automatically.

⚠️

PROVE COMPLIANCE OUT

Generate Statements of Compliance and Audit Packages in Hours, Not Weeks

Produce PSTI-ready Statements of Compliance, customer-facing security documentation, and OPSS-ready evidence packages instantly from validated supplier data.

One Supplier Submission. Validation Against All 3 PSTI Requirements. Statements of Compliance in Hours.

Certivo collects supplier cybersecurity evidence, extracts security attributes from any document format, validates against PSTI's mandatory requirements and ETSI EN 303 645 deemed compliance conditions, and generates audit-ready Statements of Compliance automatically. When OPSS updates enforcement guidance or new requirements are introduced, Certivo reassesses your portfolio—before enforcement notices arrive.

Features Tabs

Declaration Collection

Certivo's automated campaigns achieve 95% response rates vs. 20-30% with manual outreach.

Security Evidence Extraction

Every supplier attestation parsed to requirement level automatically—no manual data entry.

Requirement Monitoring

Always validated against current PSTI requirements—not your last compliance audit.

Statement of Compliance

Generate Statements of Compliance in hours instead of weeks of manual compilation.

Multi-Market Compliance

One supplier submission validates against PSTI and EU CRA simultaneously—no duplicate campaigns.

Related Regulations

Managing PSTI alongside related cybersecurity regulations eliminates duplicate supplier requests. Certivo validates one submission against multiple frameworks.

Industries Most Impacted



Electronics Manufacturing
Your Pain Point
Broad IoT product portfolios; embedded firmware from multiple suppliers; rapid product cycles


Consumer Goods
Your Pain Point
Smart home devices, wearables, connected toys; high SKU counts; consumer-facing update obligations


Industrial & Heavy Equipment
Your Pain Point
Connected sensors and controllers sold to UK consumers; legacy firmware challenges


Automotive Manufacturing
Your Pain Point
Connected vehicle accessories and aftermarket devices in scope (vehicles themselves exempted)


Medical Devices & Equipment
Your Pain Point
Medical devices exempted but connected wellness/health consumer products in scope


Semiconductor & High-Tech
Your Pain Point
Chips and modules with embedded firmware used in downstream connectable products


Aerospace & Defense
Your Pain Point
Connected consumer-facing products and accessories; dual-use components


Energy & Infrastructure
Your Pain Point
Smart meters exempted but connected energy management products in scope

Return on Investment

80%
Reduction in Compliance Labor
From Manual Evidence Chasing to Automated Attestation Management

CORA collects and validates supplier cybersecurity evidence automatically. Your team focuses on non-conformity resolution—not chasing security questionnaires and compiling Statements of Compliance manually.

4 hours
To Statement of Compliance
SoC Generation Acceleration

Generate complete, audit-ready Statements of Compliance in hours—not the weeks of manual compilation across suppliers, firmware versions, and product families.

Real-Time
Continuous Audit-Ready Documentation
Proactive PSTI Compliance Assurance

When OPSS updates guidance or the UK government expands PSTI requirements, Certivo reassesses your portfolio and flags gaps instantly. Stay enforcement-ready without quarterly scrambles.

Key Statistics

Frequently Asked Questions

What products and companies are subject to UK PSTI obligations?

Any manufacturer, importer, or distributor of consumer connectable products sold in the UK market must comply. This includes all internet-connectable and network-connectable products—smartphones, smart home devices, wearables, connected appliances, routers, and IoT products. Medical devices, smart meters, EV charge points, automotive vehicles, and computers without cellular connectivity are currently exempted.

What are the penalties for PSTI non-compliance?

OPSS can issue Compliance Notices, Stop Notices requiring products to be pulled from sale, Recall Notices, and Monetary Penalties up to £10 million or 4% of qualifying global turnover—whichever is greater. Daily penalties of up to £20,000 apply for ongoing violations. OPSS can also publicly disclose non-compliance. Failure to comply with an enforcement notice is a criminal offence.

How does Certivo manage PSTI Statements of Compliance at scale?

CORA collects supplier security attestations, validates evidence against all three PSTI requirements, and generates Statements of Compliance per product, product family, or firmware version. Certivo manages 10-year retention obligations, tracks SoC currency across product updates, and produces OPSS-ready evidence packages on demand—reducing generation time from weeks to hours.

What declaration formats does Certivo accept from suppliers?

Certivo accepts any format: PDF security attestations, ETSI EN 303 645 test reports, ISO/IEC 29147 documentation, Excel questionnaires, and freeform responses. CORA extracts security evidence regardless of format or language, eliminating the need to standardize supplier inputs across your global supply chain.

How does PSTI compliance relate to the EU Cyber Resilience Act and ETSI EN 303 645?

PSTI's three requirements are derived from ETSI EN 303 645 provisions 5.1-1, 5.1-2, 5.2-1, and 5.3-13. The EU CRA mandates 21 broader requirements by December 2027. Certivo validates one supplier submission against PSTI, CRA, and the full ETSI standard simultaneously—identifying where PSTI compliance satisfies CRA requirements and where additional evidence is needed, eliminating duplicate collection campaigns.