Intermediate2h 24m

# UK PSTI Act Compliance Course for IoT Products

Comply with the UK PSTI Act: scoping connectable products, the three security requirements, ETSI EN 303 645, support periods and the Statement of Compliance.

Shipping a connectable product into the UK with a default password, no vulnerability disclosure channel, or a vague support period isn't a minor oversight anymore — it's a breach of statutory law, backed by penalties up to £10 million or 4% of worldwide revenue. The Product Security and Telecommunications Infrastructure Act has been legally mandatory since April 2024, and most hardware teams still treat it as a vague awareness item rather than the concrete engineering and documentation programme it actually requires. This course teaches the UK PSTI Act from first principles to complete practical compliance: exactly which products count as "relevant connectable products" and which are excluded, the three statutory minimum security requirements and what each one actually demands in engineering terms, the deemed-compliance route through ETSI EN 303 645 and its specific provision mapping, how to build a genuine vulnerability disclosure process, how to set and communicate a defined security support period, exactly what the Statement of Compliance under Schedule 4 must contain and how long you must retain it, the distinct duties running across manufacturers, importers, distributors, and UK authorised representatives, how to build and maintain a real technical compliance file, what testing and assessment PSTI actually requires versus what's optional, how PSTI compares to the EU Cyber Resilience Act and RED cybersecurity rules for multi-market products, and exactly how OPSS enforcement works — its five powers, a realistic enforcement sequence, and the appeals process. Every module ends with a knowledge check, and the final module walks a realistic connected product through the full compliance process end to end, covers three genuine failure cases, and turns what you've learned into your own action plan and compliance calendar. Common failure patterns are covered as they occur throughout the course, not just listed once at the end. Built on Krono's regulatory database and the current PSTI Act 2022, the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, and current OPSS guidance. This course contains the use of artificial intelligence for asthetic purposes.

*   Includes the ebook edition, free
*   8 downloadable resources included

## What you'll learn

*   Build a genuine vulnerability disclosure process and a defined, transparent security support period
*   Prepare a defensible Statement of Compliance under Schedule 4 and retain it correctly for ten years
*   Understand manufacturer, importer, distributor, and UK authorised representative duties precisely
*   Build and maintain a real technical compliance file that survives an OPSS or retailer audit
*   Navigate OPSS enforcement powers and compare PSTI against the EU Cyber Resilience Act and RED rules

## Requirements

*   ·No prior UK regulatory or legal experience required — the course starts from first principles
*   ·Some familiarity with connected hardware or IoT product development is helpful but not essential
*   ·Founders, compliance leads, hardware engineers, and product managers will all benefit

$149.00

One-time purchase · Lifetime access · No subscription

Less than one hour with a compliance consultant.

[First lesson free to preview: UK PSTI Act](#lesson-5e11f137-d783-42a4-9b66-9a026496a313)

*   Determine whether your product is a "relevant connectable product" in scope of the PSTI Act
*   Implement all three minimum security requirements: passwords, disclosure, and update transparency
*   Use ETSI EN 303 645's deemed-compliance route and map your product against its specific provisions

Includes the ebook edition, free — read it in your [library](/platform/books) after purchase.

Enroll — $149.00

Secure checkout via Paddle

Not what you expected? Contact us within 14 days.

Built from a regulatory graph already at work

1,600

users this week

658

guides

323

product types

9

markets

## Course content

16 modules·144 min total

The PSTI Act: The Big Picture

Preview12 min

Is Your Product In Scope? Scoping Relevant Connectable Products

13 min

The Three Minimum Security Requirements

6 min

Deemed Compliance via ETSI EN 303 645

8 min

Default Passwords in Practice

9 min

Vulnerability Disclosure Policy and Reporting

9 min

Security Update Periods and the Defined Support Period

9 min

The Statement of Compliance (Schedule 4)

8 min

Supply Chain Duties

10 min

Building the Technical Documentation and Compliance File

9 min

Testing and Assessment: What PSTI Actually Requires

11 min

PSTI vs. Other Regimes

11 min

Enforcement: OPSS Powers, Notices, and Penalties

9 min

Common Failures and Working With Outside Help

9 min

Full Walkthrough, Failure Cases, and Your Action Plan

11 min

What's Next

0 min

Enroll — $149.00

Need more than one? The **All-Access Krono Vault** unlocks every course and book for one payment, or put your whole team on it with **Krono Team Vault**.

[See pricing](/pricing)

Short on time?

### Rather hand it over than learn it?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

[See services](/services)

## You might also need

[

![IoT Cybersecurity Compliance Course: EN 18031 & CRA](/posters/08-cybersecurity-compliance-connected-electronics.svg)

](/courses/08-cybersecurity-compliance-connected-electronics)

Intermediate2h 49m

[

### IoT Cybersecurity Compliance Course: EN 18031 & CRA

](/courses/08-cybersecurity-compliance-connected-electronics)

Cybersecurity compliance for connected electronics: RED Delegated Regulation 2022/30, EN 18031-1/-2/-3, the CRA transition, plus UK and US rules.

$149.00[View course →](/courses/08-cybersecurity-compliance-connected-electronics)

[

![UKCA Marking Course for Electronics Products](/posters/09-ukca-marking-for-electronics-products.svg)

](/courses/09-ukca-marking-for-electronics-products)

Beginner2h 37m

[

### UKCA Marking Course for Electronics Products

](/courses/09-ukca-marking-for-electronics-products)

Learn UKCA marking for electronics: which UK regulations apply, designated standards, conformity routes, the UK DoC and labelling rules for GB.

$149.00[View course →](/courses/09-ukca-marking-for-electronics-products)

[

![FCC Cyber Trust Mark Course: IoT Security Labeling](/posters/12-fcc-cyber-trust-mark-iot-security.svg)

](/courses/12-fcc-cyber-trust-mark-iot-security)

Intermediate1h 52m

[

### FCC Cyber Trust Mark Course: IoT Security Labeling

](/courses/12-fcc-cyber-trust-mark-iot-security)

Earn the FCC Cyber Trust Mark for IoT devices: program scope, the NIST IR 8425 baseline, technical implementation, testing, labeling and a US security strategy.

$149.00[View course →](/courses/12-fcc-cyber-trust-mark-iot-security)

[

![UK Radio Equipment Regulations 2017 Course](/posters/16-uk-radio-equipment-regulations-wireless-compliance.svg)

](/courses/16-uk-radio-equipment-regulations-wireless-compliance)

Intermediate2h 22m

[

### UK Radio Equipment Regulations 2017 Course

](/courses/16-uk-radio-equipment-regulations-wireless-compliance)

Comply with the UK Radio Equipment Regulations 2017: scoping, the essential requirements, designated standards, conformity routes, UKCA marking and the UK DoC.

$149.00[View course →](/courses/16-uk-radio-equipment-regulations-wireless-compliance)