Regulations / United Kingdom
Regulations by jurisdiction
United Kingdom: what binds a connected product
Post-Brexit, the UK runs its own consumer IoT regime, PSTI, built on the same ETSI standard the EU cites. It is narrower than the CRA and already in force.
| Framework | Applies when | Who demands it | In force | Penalties |
|---|---|---|---|---|
| UK PSTI Act | Consumer connectable products sold in the UK | Market access, mandatory | Regime in force 29 Apr 2024 | Up to GBP 10M or 4% of worldwide revenue |
| ETSI EN 303 645 | Consumer IoT; referenced by market-access rules in the EU, UK, Singapore, Australia and Finland | Product baseline behind several national regimes; not itself enforceable | v3.1.3 current | None; penalties come from the law that cites it |
UK PSTI Act
Three requirements: no universal default passwords, a published vulnerability disclosure policy, and a published minimum security-update period.
ETSI EN 303 645
13 outcome-focused provisions: credentials, updates, secure storage, communication, attack surface, resilience, telemetry, personal data, and more.
Comparisons
- PSTI vs ETSI EN 303 645 — PSTI's three requirements are lifted from the first three provisions of ETSI EN 303 645.
Check your own product
The IoT security scorecard and the requirements generator resolve these frameworks for your product archetype and markets. Educational reference, not legal advice.
← All jurisdictions