PSTI Act Security for UK Businesses: 7 Engineering Checks for Connected Products
The UK's Product Security and Telecommunications Infrastructure (PSTI) Act 2022 sets clear security standards for connected products. For UK businesses, this means engineering robust, secure-by-design solutions from day one to protect consumers and avoid significant penalties.
By Krapton Engineering9 min readSecurity

The UK's digital landscape is evolving, and with it, the expectations for product security. For UK businesses developing or selling internet-connected devices, the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 is a critical piece of legislation that cannot be overlooked. This Act, which came into force with specific regulations in April 2024, mandates a secure-by-design approach, impacting everything from initial product conception to ongoing maintenance.
TL;DR: The PSTI Act 2022 requires manufacturers, importers, and distributors of connected products in the UK to implement robust security measures from design to end-of-life. UK businesses must embed security by default, manage vulnerabilities effectively, and provide clear transparency on support periods to ensure compliance and avoid significant fines.
Key takeaways
- The PSTI Act 2022 introduces three core security requirements for connected products sold in the UK.
- Organisations must implement 'security by default' and ensure strong authentication mechanisms.
- A robust vulnerability disclosure policy is mandatory, alongside a transparent support period.
- Failure to comply can lead to substantial fines from the Office for Product Safety and Standards (OPSS).
- Krapton embeds PSTI-aligned security practices into our custom software development processes for UK clients.
Understanding the PSTI Act 2022 for UK Businesses
The Product Security and Telecommunications Infrastructure Act 2022, specifically Part 1, aims to enhance the cyber security of 'connectable' products available to consumers in the UK. This isn't just about smart home devices; it extends to any product that can connect to the internet or other network, directly or indirectly. This includes smart TVs, baby monitors, security cameras, smart appliances, and even some industrial IoT devices if they are marketed to consumers.
The Act places obligations on manufacturers, importers, and distributors. As of 2026, the specific product security requirements are detailed in the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023. These regulations outline three key security requirements that every relevant product must meet. You can find the full legislation on legislation.gov.uk.
From an engineering perspective, this means a shift from reactive security patching to proactive, secure-by-design development. For UK businesses involved in product development, this is a commercial imperative, not just a regulatory hurdle, as non-compliance can result in fines of up to £10 million or 4% of global turnover, whichever is greater, alongside product recalls.
The 3 Core PSTI Security Requirements and Engineering Impact
The PSTI Act mandates three specific security requirements, drawing heavily from the ETSI EN 303 645 standard and NCSC guidance. For engineers, these translate into concrete tasks and architectural decisions:
- No default passwords: Products must not be supplied with universal default passwords or weak, easily guessable default passwords.
- Vulnerability disclosure policy: Manufacturers must provide a public point of contact for reporting security vulnerabilities and commit to addressing them in a timely manner.
- Minimum security update period: Manufacturers must clearly inform consumers about the minimum period during which the product will receive security updates.
These requirements impact not only the software and hardware design but also the entire product lifecycle, including manufacturing, packaging, and marketing materials. Understanding these core tenets is the first step towards achieving software security services that align with UK regulations.
7 Engineering Checks for PSTI Act Compliance
Here’s a practical checklist for engineering teams at UK businesses to ensure their connected products meet PSTI Act requirements:
1. Eliminate Default Passwords and Implement Strong Authentication
This is arguably the most straightforward but critical requirement. Products must force users to set a strong, unique password on first use. Password policies should enforce complexity, length, and ideally, prevent common patterns.
Vulnerable Pattern:
{
"device_id": "ABC123",
"username": "admin",
"password": "password123" // Universal default, or easily guessable
}Hardened Pattern:
// On device first boot or factory reset
function initialSetup() {
if (!userHasSetPassword) {
redirectToPasswordCreationScreen();
// Enforce strong password rules (min length, complexity, no common defaults)
// Store password securely (hashed and salted)
}
}
In a recent client engagement for a smart home device, we implemented a mandatory multi-factor authentication (MFA) setup flow during initial device pairing, significantly exceeding the basic password requirement and providing a stronger security posture. This involved generating a unique pairing code displayed on the device, verified via a mobile app, before allowing any network configuration.
2. Establish a Clear Vulnerability Disclosure Policy (VDP)
The PSTI Act requires a public-facing VDP. This isn't just a legal document; it's an engineering commitment. Your team needs a process for receiving, triaging, and acting on vulnerability reports. This includes:
- A dedicated, monitored email address (e.g., security@yourcompany.co.uk).
- Clear guidelines for researchers on how to report vulnerabilities.
- A defined internal incident response plan for reported issues.
- Commitment to acknowledging reports and providing updates.
The National Cyber Security Centre (NCSC) provides excellent guidance on vulnerability disclosure, which is highly recommended for UK businesses.
3. Define and Communicate Minimum Security Update Periods
Consumers need to know how long their product will receive security patches. This requires a long-term strategy for firmware updates, OS support, and component lifecycles. Engineers must consider:
- Software Architecture: Design for over-the-air (OTA) updates that are secure, reliable, and can be applied without significant user intervention.
- Component Obsolescence: Factor in the lifespan of third-party libraries, operating systems (e.g., embedded Linux distributions), and hardware components.
- Version Control & Release Management: A robust system to track and deliver security patches for multiple product versions.
This commitment should be clearly stated in product documentation and marketing materials. Our team often advises clients on building robust custom software development solutions that support long-term maintainability and secure update mechanisms.
4. Implement Secure Software Development Lifecycle (SSDLC) Practices
PSTI compliance is best achieved by integrating security throughout your development process. This includes:
- Threat Modelling: Identify potential attack vectors early in the design phase.
- Secure Coding Guidelines: Adhere to industry best practices (e.g., OWASP Top 10 for web components).
- Automated Security Testing: Integrate Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) into your CI/CD pipelines.
- Regular Penetration Testing: Engage third-party experts to find vulnerabilities before release.
For UK businesses, this proactive approach minimises costly retrofits and reputational damage down the line. We often integrate QA and software testing with a strong security focus from the outset.
5. Secure Data Handling and Privacy by Design
While the PSTI Act focuses on product security, connected products often handle personal data, bringing them under the scope of UK GDPR and the Data Protection Act 2018. Engineers must ensure:
- Data Minimisation: Collect only the data absolutely necessary.
- Encryption: Encrypt data at rest and in transit (TLS 1.2+ for network communication).
- Access Control: Implement robust authentication and authorisation for all data access.
- Privacy by Design: Embed privacy considerations into the architecture from the start, as recommended by the Information Commissioner's Office (ICO.org.uk).
This is general information, not legal advice. Always consult with legal professionals for specific compliance guidance related to UK GDPR.
6. Harden the Supply Chain for Components and Software
A connected product is only as secure as its weakest link. For UK businesses, securing the supply chain means:
- Third-Party Component Vetting: Assess the security posture of all hardware and software components, including open-source libraries.
- Software Bill of Materials (SBOM): Maintain an up-to-date list of all software components, their versions, and known vulnerabilities.
- Secure Manufacturing Processes: Ensure that devices are provisioned and configured securely during production, preventing tampering.
On a production rollout for a new smart energy meter, our team encountered a critical dependency vulnerability in an older firmware library. This highlighted the importance of continuous SCA scanning and having a robust process to update vulnerable components, even those from third-party suppliers, throughout the product's entire lifecycle.
7. Plan for End-of-Life and Secure Decommissioning
Security obligations don't end when a product is decommissioned. Engineers should design for:
- Secure Factory Reset: Ensure user data can be completely and securely wiped from the device.
- Firmware Obsolescence: Have a plan for communicating when security updates will cease and advise users on safe disposal or decommissioning.
This shows a commitment to consumer safety even beyond the active support period, building trust in your brand.
When NOT to use this approach
While a secure-by-design approach is paramount for connected products, some niche scenarios might have different priorities. For instance, a highly specialised, isolated industrial control system with no internet connectivity and strict physical access controls might prioritise real-time performance and deterministic behaviour over frequent OTA security updates. However, for any product that touches the consumer market in the UK, or has any form of network connectivity, PSTI compliance is non-negotiable.
PSTI Compliance and Your Supplier Relationships
For UK businesses that import or distribute connected products, the PSTI Act also imposes duties. Importers must ensure that the products they bring into the UK market meet the requirements, and distributors must not make products available if they suspect non-compliance. This means:
| Role | PSTI Act Obligation | Engineering/Procurement Impact |
|---|---|---|
| Manufacturer | Meet all 3 security requirements, maintain VDP, state support period. | Deep integration of SSDLC, robust update infrastructure, secure-by-design. |
| Importer | Ensure manufacturer compliance, provide contact info. | Thorough due diligence on foreign manufacturers, request compliance documentation. |
| Distributor | Not make non-compliant products available. | Verify compliance statements, understand product security claims. |
Procurement teams need to integrate PSTI compliance checks into their supplier vetting processes, requesting evidence of security measures and vulnerability management plans. This can include asking for a Software Bill of Materials (SBOM) and details of their security update mechanisms.
FAQ
What types of products does the PSTI Act cover in the UK?
The PSTI Act covers 'connectable' products, meaning any product that can connect to the internet or a network, directly or indirectly. This includes smart home devices, IoT gadgets, smart TVs, and even some children's toys, provided they are available to consumers in the UK.
What are the penalties for non-compliance with the PSTI Act in the UK?
Non-compliance with the PSTI Act can result in significant penalties. The Office for Product Safety and Standards (OPSS) can issue fines of up to £10 million or 4% of a company's global annual turnover, whichever is higher, along with potential product recall notices.
Does the PSTI Act apply to businesses that only import or distribute products in the UK?
Yes, the PSTI Act applies to manufacturers, importers, and distributors. Importers must ensure that products comply, and distributors must not supply products they know or suspect to be non-compliant. Due diligence is crucial across the supply chain.
How does PSTI Act security relate to Cyber Essentials for UK SMEs?
While distinct, PSTI Act security complements Cyber Essentials. PSTI focuses on the security of the product itself, whereas Cyber Essentials certifies an organisation's basic IT security hygiene. Achieving Cyber Essentials can demonstrate a foundational commitment to security that supports PSTI-compliant product development.
Build Secure Connected Products for the UK Market
Navigating the PSTI Act 2022 requires more than just policy documents; it demands a deep engineering understanding and a commitment to secure development practices. For UK businesses, this is an opportunity to build trust with consumers and gain a competitive edge in the connected product market. Our engineering team specialises in secure-by-design development, helping clients build robust and compliant solutions.
Get a security-minded engineering team — book a free consultation with Krapton to discuss your connected product security strategy and how we can help you achieve PSTI Act compliance.


