Intermediate2h 21m

# UK Cyber Security and Resilience Bill Course

UK connected device cyber law explained: the PSTI Act's three security requirements, the Cyber Security and Resilience Bill, supply chain duties and compliance.

A smart plug ships with an admin password of "admin1234" set at the factory, identical across every unit sold — and it's illegal, not just careless. A camera manufacturer publishes no way to report a security flaw, and discovers the flaw from a journalist instead of a researcher. A component supplier feeding sensors into an NHS diagnostics pipeline gets a letter informing them they've just been designated a critical supplier under a law they'd never heard of, with new obligations attached. None of this is exotic. It's the ordinary result of treating UK connected-device law as one rule instead of the two real, separately-enforced systems it actually is. This course teaches UK cyber security compliance for connected device manufacturers from first principles to complete practical compliance. It starts with the Product Security and Telecommunications Infrastructure Act 2022 and its Regulations — the direct product law every manufacturer, importer, and distributor of a consumer connectable product must meet: the ban on easily-guessable default passwords, the vulnerability disclosure policy every product needs, and the minimum security update period every product must publicly disclose. You'll learn exactly how to classify a product into scope, build the statement of compliance and technical documentation OPSS expects, and what OPSS's compliance notices, recall powers, and penalties actually mean in practice. The course then turns to the Cyber Security and Resilience Bill — the legislation modernising the UK's Network and Information Systems Regulations 2018, currently moving through Parliament toward Royal Assent. You'll understand exactly how it expands regulatory scope to data centres, large load controllers, and managed service providers, and — critically for hardware manufacturers — how its new "designated critical supplier" power can pull a device or component maker into a second, separate regulatory regime the moment their product feeds into a regulated essential or important entity. Incident reporting timelines, the two-tier turnover-based penalty structure, and the NCSC's Cyber Assessment Framework round out the regulatory core. A concise comparison to the EU's parallel regime — the NIS2 Directive, the Radio Equipment Directive's cybersecurity requirements, and the Cyber Resilience Act — helps any manufacturer selling into both markets keep the two systems straight. The closing modules deliver a complete, realistic walkthrough of a connected device manufacturer building its compliance program from scratch, the common mistakes and edge cases that trip up even careful teams, and your own thirty, sixty, ninety-day compliance action plan. Built on Krono's regulatory database and current 2026 guidance, covering the Product Security and Telecommunications Infrastructure Act 2022 and the Product Security and Telecommunications Infrastructure (Security Requirements) Regulations 2023, and the Cyber Security and Resilience Bill as it stood in Parliament at the time of this course's production. This course contains the use of artificial intelligence for asthetic purposes.

*   Includes the ebook edition, free
*   8 downloadable resources included

## What you'll learn

*   Build the statement of compliance and technical documentation file OPSS actually expects to see
*   Understand the Cyber Security and Resilience Bill's expanded scope and the designated critical supplier power
*   Meet CSRB incident reporting timelines and understand the two-tier turnover-based penalty structure
*   Compare the UK regime to the EU's NIS2, RED cybersecurity requirements, and Cyber Resilience Act
*   Build a real, ongoing compliance program instead of treating registration as a one-time checkbox

## Requirements

*   ·No prior cyber security, legal, or engineering background required — the course builds every concept from first principles
*   ·A working knowledge of your own product's connectivity and update mechanism is helpful but not required
*   ·Manufacturers, importers, distributors, compliance teams, and hardware startups selling into the UK will all benefit

$199.00

One-time purchase · Lifetime access · No subscription

Less than one hour with a compliance consultant.

[First lesson free to preview: UK Cyber Security and Resilience Bill](#lesson-86dfab97-869e-4d03-a3a0-c42090fb0727)

*   Map the UK's cyber security regulatory landscape and know exactly which law — PSTI, CSRB, or both — applies to your product
*   Classify any connected product into or out of PSTI Act scope, and correctly apply its exemptions
*   Implement all three PSTI security requirements — password, vulnerability disclosure, and update-period rules — correctly

Includes the ebook edition, free — read it in your [library](/platform/books) after purchase.

Enroll — $199.00

Secure checkout via Paddle

Not what you expected? Contact us within 14 days.

Built from a regulatory graph already at work

1,599

users this week

658

guides

323

product types

9

markets

## Course content

19 modules·141 min total

UK Connected Device Cyber Law: The Big Picture

Preview8 min

The UK Regulatory Framework

9 min

PSTI Act 2022: Scope & Product Classification

9 min

Security Requirement 1: No Default Passwords

7 min

Security Requirement 2: Vulnerability Disclosure

8 min

Security Requirement 3: Minimum Security Update Period

8 min

Statement of Compliance & Technical Documentation

7 min

PSTI Enforcement: OPSS Powers & Penalties

7 min

The Cyber Security and Resilience Bill: Scope & Structure

9 min

CSRB's Newly Regulated Entities

8 min

Designated Critical Suppliers: When a Device Manufacturer Gets Pulled In

9 min

Incident Reporting Under CSRB

8 min

CSRB Enforcement & Penalties

7 min

The NCSC Cyber Assessment Framework

7 min

UK vs. EU: NIS2, RED & the Cyber Resilience Act

8 min

Full Walkthrough: A Connected Device Manufacturer's Compliance Program

7 min

Common Mistakes & Edge Cases

6 min

Your Compliance Action Plan

8 min

What's Next

0 min

Enroll — $199.00

Need more than one? The **All-Access Krono Vault** unlocks every course and book for one payment, or put your whole team on it with **Krono Team Vault**.

[See pricing](/pricing)

Short on time?

### Rather hand it over than learn it?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

[See services](/services)