Regulations / United Kingdom

Regulations by jurisdiction

United Kingdom: what binds a connected product

Post-Brexit, the UK runs its own consumer IoT regime, PSTI, built on the same ETSI standard the EU cites. It is narrower than the CRA and already in force.

FrameworkApplies whenWho demands itIn forcePenalties
UK PSTI ActConsumer connectable products sold in the UKMarket access, mandatoryRegime in force 29 Apr 2024Up to GBP 10M or 4% of worldwide revenue
ETSI EN 303 645Consumer IoT; referenced by market-access rules in the EU, UK, Singapore, Australia and FinlandProduct baseline behind several national regimes; not itself enforceablev3.1.3 currentNone; penalties come from the law that cites it

UK PSTI Act

Three requirements: no universal default passwords, a published vulnerability disclosure policy, and a published minimum security-update period.

ETSI EN 303 645

13 outcome-focused provisions: credentials, updates, secure storage, communication, attack surface, resilience, telemetry, personal data, and more.

Comparisons

Check your own product

The IoT security scorecard and the requirements generator resolve these frameworks for your product archetype and markets. Educational reference, not legal advice.

← All jurisdictions

© 2026 Yoel Frischoff / TheRoad. All rights reserved. · About the Book · Press · Teaching · Glossary · References · Privacy · Terms · Accessibility