As the UK sharpens its focus on cybersecurity for connected products, the Product Security and Telecommunications Infrastructure (PSTI) Act has reshaped the regulatory landscape for manufacturers, importers, and distributors of consumer-connected devices. For organizations serving global markets, understanding this regulation is essential for compliance and protecting product integrity, consumer trust, and brand reputation.
Enacted in December 2022, the PSTI Act aims to improve the baseline cybersecurity of internet-connectable products sold in the UK. It responds to the increasing risk posed by poorly secured devices—from smart TVs to industrial IoT gateways—that can be exploited to launch wide-scale cyberattacks.
The Act mandates that manufacturers build security into the design and development of consumer IoT products and maintain transparency with users and regulators regarding known risks.
As of April 29, 2024, the following requirements are enforceable:
These initial requirements reflect the baseline security provisions outlined in the ETSI EN 303 645 standard, which has become a global benchmark for IoT security.
The PSTI Act applies to:
Exemptions exist for select product categories, but manufacturers must still navigate overlapping regulations like the EU Cyber Resilience Act and CE RED.
The following products are excluded from the UK PSTI regulations:
Non-compliance with the PSTI Act can result in:
Enforcement is managed by the UK’s Office for Product Safety and Standards (OPSS), which has been empowered to investigate and act on breaches of the Act.
Finite State provides a comprehensive platform and expert services to support end-to-end compliance with global cybersecurity regulations, including the PSTI Act. Here's how we help:
Many connected devices lack accessible source code. Finite State’s advanced binary analysis and firmware unpacking capabilities allow manufacturers to:
To meet transparency and long-term support requirements, Finite State enables manufacturers:
Finite State’s penetration testing services are tailored for connected devices and validate resilience against real-world attack scenarios. We help you:
With former government cybersecurity leaders on staff, Finite State delivers policy-driven consulting to align with evolving regulations such as the PSTI Act, EU CRA, NIS2, and Cyber Trust Mark. This includes:
The UK’s PSTI Act reflects a growing international trend toward stronger regulation of connected devices. While not the most comprehensive framework globally, it signals that governments are no longer treating IoT security as optional. For connected product manufacturers, compliance isn’t just about avoiding penalties—it’s about earning trust, reducing liability, and building more resilient products.
Partner with Finite State to future-proof your security and regulatory strategy. Book a demo to learn more