Compare / PSTI vs ETSI EN 303 645

Regulation comparison

PSTI vs ETSI EN 303 645

PSTI's three requirements are lifted from the first three provisions of ETSI EN 303 645. The standard goes on for ten more. A product that only meets PSTI has done the minimum the UK asks and nothing about updates, storage, communications or resilience.

UK PSTI ActETSI EN 303 645
Applies whenConsumer connectable products sold in the UKConsumer IoT; referenced by market-access rules in the EU, UK, Singapore, Australia and Finland
Who demands itMarket access, mandatoryProduct baseline behind several national regimes; not itself enforceable
What it isAct plus 2023 regulationsStandard
ScopeThree requirements: no universal default passwords, a published vulnerability disclosure policy, and a published minimum security-update period13 outcome-focused provisions: credentials, updates, secure storage, communication, attack surface, resilience, telemetry, personal data, and more
In forceRegime in force 29 Apr 2024v3.1.3 current
PenaltiesUp to GBP 10M or 4% of worldwide revenueNone; penalties come from the law that cites it
Authoritative textPSTI text ↗ETSI EN 303 645 text ↗

What a product team should do

Treat PSTI as the floor and the full ETSI standard as the design target; the same product then satisfies Singapore's and Australia's labelling schemes, which cite the same standard.

Check your own product

The IoT security scorecard grades a product against these frameworks in 19 questions, and the requirements generator turns the applicable ones into PRD-ready requirements. Both cite the same provisions this page does. The full map is on the regulatory landscape reference.

Sources: UK PSTI Act (official text) and ETSI EN 303 645 (official text). Educational reference, not legal advice. See Chapter 18 and Chapter 19 of Tangibles.

← All comparisons

© 2026 Yoel Frischoff / TheRoad. All rights reserved. · About the Book · Press · Teaching · Glossary · References · Privacy · Terms · Accessibility