Compare / PSTI vs ETSI EN 303 645
Regulation comparison
PSTI vs ETSI EN 303 645
PSTI's three requirements are lifted from the first three provisions of ETSI EN 303 645. The standard goes on for ten more. A product that only meets PSTI has done the minimum the UK asks and nothing about updates, storage, communications or resilience.
| UK PSTI Act | ETSI EN 303 645 | |
|---|---|---|
| Applies when | Consumer connectable products sold in the UK | Consumer IoT; referenced by market-access rules in the EU, UK, Singapore, Australia and Finland |
| Who demands it | Market access, mandatory | Product baseline behind several national regimes; not itself enforceable |
| What it is | Act plus 2023 regulations | Standard |
| Scope | Three requirements: no universal default passwords, a published vulnerability disclosure policy, and a published minimum security-update period | 13 outcome-focused provisions: credentials, updates, secure storage, communication, attack surface, resilience, telemetry, personal data, and more |
| In force | Regime in force 29 Apr 2024 | v3.1.3 current |
| Penalties | Up to GBP 10M or 4% of worldwide revenue | None; penalties come from the law that cites it |
| Authoritative text | PSTI text ↗ | ETSI EN 303 645 text ↗ |
What a product team should do
Treat PSTI as the floor and the full ETSI standard as the design target; the same product then satisfies Singapore's and Australia's labelling schemes, which cite the same standard.
Check your own product
The IoT security scorecard grades a product against these frameworks in 19 questions, and the requirements generator turns the applicable ones into PRD-ready requirements. Both cite the same provisions this page does. The full map is on the regulatory landscape reference.
Sources: UK PSTI Act (official text) and ETSI EN 303 645 (official text). Educational reference, not legal advice. See Chapter 18 and Chapter 19 of Tangibles.
← All comparisons