E-Book24 chapters

# UK PSTI Act Compliance Handbook

A UK PSTI Act handbook for connected products: scope, default passwords, vulnerability disclosure, update periods and the Statement of Compliance. Most connected-device manufacturers encounter the UK's Product Security and Telecommunications Infrastructure Act the same way: as a vague compliance item flagged late, treated as paperwork rather than the concrete engineering and documentation programme it actually is. Since April 29, 2024, that vagueness carries real statutory risk — penalties up to £10 million or 4% of worldwide revenue, stop notices, and forced recalls. This book is built to remove the vagueness entirely. It walks through the PSTI Act from first principles to complete practical compliance: exactly which products count as "relevant connectable products" and which are excluded, the three statutory minimum security requirements and what each demands in genuine engineering terms, the deemed-compliance route through ETSI EN 303 645 and its specific provision mapping, how to build a genuine vulnerability disclosure process, how to set and communicate a defined security support period, exactly what the Statement of Compliance under Schedule 4 must contain and how long you must retain it, the distinct duties running across manufacturers, importers, distributors, and UK authorised representatives, how to build a real technical compliance file, what testing and assessment PSTI actually requires versus what's optional, how PSTI compares to the EU Cyber Resilience Act and RED cybersecurity rules, and exactly how OPSS enforcement works. Every chapter closes with a knowledge check drawn directly from the companion video course, and eight appendices turn the book's worksheets, checklists, and templates into tools you can put to work on your own product immediately. This book contains the use of artificial intelligence.

## What you'll learn

*   Determine whether your product is a "relevant connectable product" in scope of the PSTI Act
*   Implement all three minimum security requirements: passwords, disclosure, and update transparency
*   Use ETSI EN 303 645's deemed-compliance route and map your product against its specific provisions
*   Build a genuine vulnerability disclosure process and a defined, transparent security support period
*   Prepare a defensible Statement of Compliance under Schedule 4 and retain it correctly for ten years
*   Understand manufacturer, importer, distributor, and UK authorised representative duties precisely
*   Build and maintain a real technical compliance file that survives an OPSS or retailer audit
*   Navigate OPSS enforcement powers and compare PSTI against the EU Cyber Resilience Act and RED rules

$24.99

One-time purchase · Read in browser · No subscription

*   Determine whether your product is a "relevant connectable product" in scope of the PSTI Act
*   Implement all three minimum security requirements: passwords, disclosure, and update transparency
*   Use ETSI EN 303 645's deemed-compliance route and map your product against its specific provisions

Buy for $24.99

Secure checkout via Paddle

Not what you expected? Contact us within 14 days.

This book is included free when you enroll in the full course — [$149.00 for the complete video curriculum plus this book](/courses/18-uk-psti-act-iot-product-security-compliance).

Built from a regulatory graph already at work

1,601

users this week

658

guides

323

product types

9

markets

## Chapters

Read Chapter 1 free →

1

The PSTI Act: The Big Picture

Before any scoping question or requirement checklist, it's worth sitting with why this

2

Is Your Product In Scope? Scoping "Relevant Connectable Products"

This chapter is the one every later decision in this book depends on.

3

The Three Minimum Security Requirements

This chapter covers the three statutory minimum requirements in full — what each one

4

Deemed Compliance via ETSI EN 303 645

This chapter covers the deemed-compliance route in full: what the standard actually is, the

5

Default Passwords in Practice

This chapter turns the first requirement into genuine engineering practice: what counts as

6

Vulnerability Disclosure Policy and Reporting

This chapter builds a genuine vulnerability disclosure process from the ground up: what

7

Security Update Periods and the Defined Support Period

This chapter covers how to set, communicate, and maintain a defined security support period

8

The Statement of Compliance (Schedule 4)

This chapter covers exactly what Schedule 4 requires, common mistakes, retention rules, and

9

Supply Chain Duties

Compliance responsibility doesn't stop at the manufacturer.

10

Building the Technical Documentation and Compliance File

This chapter covers what a complete compliance file actually contains, how to keep it a

11

Testing and Assessment: What PSTI Actually Requires

This chapter covers the genuine distinction between mandatory statutory requirements and

12

PSTI vs. Other Regimes

For any manufacturer selling beyond the UK, this chapter compares PSTI against the EU Cyber

13

Enforcement: OPSS Powers, Notices, and Penalties

This chapter covers OPSS's risk-based enforcement approach, its five statutory powers, a

14

Common Failures and Working With Outside Help

This chapter consolidates the recurring failure patterns from across the book, covers Part

15

Full Walkthrough, Failure Cases, and Your Action Plan

This closing chapter walks a complete realistic connected product through the entire PSTI

16

Knowledge Checks

Every module in this book closes with a knowledge check in the companion video course.

17

Appendix A — Relevant Connectable Product Scoping & Exclusions Worksheet

18

Appendix B — Three Minimum Security Requirements Implementation Checklist

19

Appendix C — ETSI EN 303 645 Deemed Compliance Mapping Worksheet

20

Appendix D — Statement of Compliance Template (Schedule 4)

21

Appendix E — Supply Chain Duties & Authorised Representative Decision Guide

22

Appendix F — Compliance File & Evidence Tracker

23

Appendix G — PSTI vs. CRA vs. RED Cybersecurity Multi-Market Comparison Worksheet

24

Appendix H — OPSS Enforcement Response & Pre-Launch Compliance Sign-Off Checklist

Buy for $24.99

## Want the full video course?

This book's companion course covers the same material with video lessons and downloadable resources — and includes this book free.

[

![UK PSTI Act Compliance Course for IoT Products](/posters/18-uk-psti-act-iot-product-security-compliance.svg)

](/courses/18-uk-psti-act-iot-product-security-compliance)

Intermediate2h 24m

[

### UK PSTI Act Compliance Course for IoT Products

](/courses/18-uk-psti-act-iot-product-security-compliance)

Comply with the UK PSTI Act: scoping connectable products, the three security requirements, ETSI EN 303 645, support periods and the Statement of Compliance.

Includes the ebook, free

$149.00[View course →](/courses/18-uk-psti-act-iot-product-security-compliance)

Need more than one? The **All-Access Krono Vault** unlocks every course and book for one payment, or put your whole team on it with **Krono Team Vault**.

[See pricing](/pricing)

Short on time?

### Rather hand it over than learn it?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

[See services](/services)