ComparisonEU RED / UK PSTI

RED vs UK PSTI for connected radio products

A connected wireless product sold in both markets may need EU RED conformity and a separate UK PSTI product-security assessment.

RED controls EU radio-equipment market access. PSTI controls specified security and statement duties for relevant consumer connectable products supplied to UK consumers.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
14

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Many Wi-Fi, Bluetooth, cellular, and other connected consumer products sold in the EU and UK need both workstreams. EU RED applies to radio equipment and covers safety, EMC, spectrum, activated cybersecurity requirements, conformity assessment, the EU declaration, and CE marking. The RED cybersecurity category act applies to covered equipment from 1 August 2025 through 10 December 2027 and is repealed from 11 December 2027, with surveillance preserved for equipment placed on the Union market during that period. The UK PSTI product-security regime has applied since 29 April 2024 to a and imposes password, vulnerability-reporting, security-update transparency, statement-of-compliance, record, and corrective-action duties. Neither regime establishes compliance with the other.

Side-by-side comparison

RED vs UK PSTI for connected radio products

Use RED for EU radio-equipment conformity and PSTI for UK consumer connectable product security. Keep the legal conclusions and market deliverables separate.

Review all sources
First framework
EU RED

Binding EU radio-equipment law covering Article 3 requirements, conformity assessment, technical documentation, the EU declaration, CE marking, and market surveillance.

Second framework
UK PSTI

Binding UK product-security law for relevant consumer connectable products, with security requirements, statements, supply-chain checks, records, corrective action, and OPSS enforcement.

Comparison row 1

Scope

EU RED

Radio equipment made available on the EU market or put into service in the Union.

UK PSTI

Relevant consumer products that can connect to the internet or a network and are made available to UK consumers, subject to exclusions.

Operational implication

Write one scope record per market; do not infer either result from the other.

Comparison row 2

Security requirements

EU RED

Network protection, privacy and personal-data safeguards, and fraud protection for specified radio-equipment categories.

UK PSTI

Password controls, published vulnerability-reporting information, and published minimum security-update support information.

Operational implication

Some controls overlap, but the required legal evidence and wording differ.

Comparison row 3

Actors

EU RED

RED assigns duties to manufacturers, authorised representatives, importers, and distributors in the EU chain.

UK PSTI

PSTI assigns duties to UK manufacturers, importers, distributors, and, for specified failures, authorised representatives.

Operational implication

Map the real commercial chain in each market instead of copying role names.

Comparison row 4

Market documents

EU RED

RED technical documentation and an EU declaration of conformity support CE marking.

UK PSTI

Unless the Schedule 2A deemed-compliance conditions are met, a PSTI statement of compliance must accompany the product and include the Schedule 4 information.

Operational implication

A RED declaration does not replace the PSTI statement of compliance or deemed-compliance evidence.

Comparison row 5

Application dates

EU RED

The RED cybersecurity delegated requirements apply from 1 August 2025 through 10 December 2027; the category act is repealed from 11 December 2027, with surveillance preserved for equipment placed on the market during that period.

UK PSTI

The UK consumer connectable product security regime applies from 29 April 2024.

Operational implication

Both dates have passed; covered products need current evidence before market placement.

Comparison row 6

Reusable evidence

EU RED

Threat models, credential tests, update evidence, vulnerability records, privacy analysis, fraud controls, and RED conformity records.

UK PSTI

Password evidence, reporting-channel publication, response timing, update-support publication, statement or deemed-compliance evidence, actor checks, records, and failure actions.

Operational implication

Bridge shared controls at requirement level and keep each market's missing deliverables visible.

Practical decision rule

What should the team do for a dual-market product?

  • Complete separate RED and PSTI scope assessments for the exact market versions.
  • Build the RED conformity file and the PSTI statement or deemed-compliance evidence and supply-chain pack separately.
  • Reuse engineering controls only through a written mapping to each legal requirement.
  • Assign EU and UK release, authority-response, and corrective-action owners.
Section 1

Run separate EU and UK scope tests

RED applies when the finished product intentionally emits or receives radio waves for radio communication or radiodetermination and is made available on the EU market. Delegated Regulation (EU) 2022/30 activates RED Article 3(3)(d), (e), and (f) for specified radio-equipment categories from 1 August 2025 through 10 December 2027. Delegated Regulation (EU) 2026/339 repeals the category act from 11 December 2027 and preserves RED surveillance for covered equipment placed on the market during that period.

The PSTI Regulations apply to relevant consumer products that can connect to the internet or a network and are made available to UK consumers. A network-only product can still qualify when it can connect directly to an internet-connectable product using an Internet Protocol suite protocol, or when it can both connect directly to two or more products at once and connect directly to an internet-connectable product using a non-Internet Protocol suite protocol. The Act also treats certain input products designed to be used with a computer as meeting the second condition, so Bluetooth or hub-mediated operation needs the statutory test rather than a Wi-Fi-only shortcut.

Official guidance lists exclusions, including electric-vehicle charge points, medical devices, smart meters, specified non-cellular desktop, laptop, and tablet computers, certain products supplied in Northern Ireland, and vehicle categories added by the 2025 amendment. The computer exclusion does not cover a listed computer with cellular connectivity, and it does not cover one designed exclusively for children under 14. A product can be RED radio equipment but outside PSTI, or a PSTI product but outside RED.

  • Record the EU and UK product versions, radio technologies, network functions, intended users, sales channels, and supply-chain actors.
  • Complete the RED radio-equipment and Article 3(3) decision independently from the PSTI relevant-connectable-product and exclusion decision.
  • Do not use EU CE marking as evidence that the UK PSTI duties have been met; PSTI has its own statement and supply-chain requirements.
Section 2

Meet the three PSTI security requirements and statement duty

The PSTI security requirements address three outcomes, but a manufacturer is treated as complying where the product is currently assigned a non-expired Japan JC-STAR STAR-1 conformance label or currently awarded a non-expired label under any level of the Singapore Cybersecurity Labelling Scheme. Products must not use universal default passwords or easily guessable passwords in the prohibited way. Manufacturers must publish information that allows security issues to be reported and state when reporters can expect acknowledgement and status updates. Manufacturers must also publish the minimum period for which security updates will be provided, including an end date. The Regulations do not impose one universal minimum support duration; the manufacturer declares the period and must present it clearly.

A statement of compliance must accompany the product unless the Schedule 2A deemed-compliance conditions are met. The PSTI Act treats it as a document, and official guidance says it can be digital, but where a statement is required the manufacturer, importer, and distributor must ensure it accompanies the product and contains the required information. Schedule 4 covers product identification, manufacturer details, a compliance statement, the defined support period and end date, signatory details, and place and date of issue.

Where a statement is required, manufacturers and importers must retain it for whichever is longer: 10 years from issue or the defined support period. Investigation and compliance-failure records have their own 10-year retention duty. The record should identify the suspected failure, investigation outcome, confirmed failure, corrective steps, and whether those steps worked.

  • Test every password path in the product and associated software against the Regulations, including factory and privileged credentials.
  • Publish a durable vulnerability-reporting route and response timing information that security researchers can find without buying the product.
  • Publish the security-update support period before purchase where required and, unless the Schedule 2A deemed-compliance conditions are met, keep the statement of compliance with the supplied product.
Recommended next step

Build separate EU and UK evidence packs

Map shared security controls to RED and PSTI separately, with the correct product, market, legal source, actor, statement, owner, and review trigger.

Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Repeals the RED cybersecurity category act from 11 December 2027 and preserves surveillance for covered equipment placed on the market through 10 December 2027.
legislation.gov.uk
Referenced sections
  • Part 1 covers statements, records, investigations, and action following compliance failures.
legislation.gov.uk
Referenced sections
  • Binding UK product-security requirements source.
Related guides

Explore more topics

Are radio kits and evaluation boards covered by the RED? | RED FAQ
RED FAQ for radio kits, construction kits, amateur-radio kits, and custom-built professional R&D evaluation boards under Directive 2014/53/EU.
EU Radio Equipment Directive Timeline: RED, Cyber and USB-C Dates
Understand which RED dates changed market-access rules, including 2016 application, the 2017 transition cutoff, common-charger dates, and cybersecurity requirements from 1 August 2025.
EU RED Applicability Test for Radio Equipment
Decide whether Directive 2014/53/EU applies to a connected product, which RED requirements are triggered, and what evidence belongs in the technical file.
EU RED Common Charger FAQ: Which devices need USB-C?
FAQ on EU RED common charger scope, 28 December 2024 and 28 April 2026 dates, USB-C, USB Power Delivery, charger unbundling, labels, pictograms, and evidence.
EU RED Common Charger Obligations: USB-C scope, dates, labels
Check RED common-charger device categories, application dates, USB-C and USB Power Delivery specifications, charger unbundling, consumer pictograms, labels, and release evidence.
EU RED compliance evidence guide
Build a Radio Equipment Directive compliance file with Article 3 requirement mapping, harmonised-standard checks, conformity assessment evidence, EU declarations, CE marking, and RED source links.
EU RED Cybersecurity Product Categories: 2022/30 scope
Classify products under RED Delegated Regulation (EU) 2022/30, including exclusions, EN 18031 evidence, and the 1 August 2025 to 10 December 2027 transition.
EU RED FAQ: Scope, CE and USB-C
Answers to common EU RED questions on radio equipment scope, Article 3 requirements, cybersecurity, USB-C common charger rules, CE marking, and technical-file evidence.
EU RED Radio Equipment Scope: products and exclusions
Decide whether a product is radio equipment under Directive 2014/53/EU, with RED scope tests, exclusions, examples, and evidence records.
EU RED Requirements Map: CE and Article 3
Map Radio Equipment Directive requirements for radio products: Article 3 safety, EMC, spectrum, selected Article 3(3) duties, common charger rules, conformity assessment, CE marking, EU declaration, and technical documentation.
EU RED Scope and Classification
Classify products under the EU Radio Equipment Directive with cited tests for radio equipment scope, exclusions, Article 3 requirement buckets, cybersecurity, common charging, and evidence records.
EU RED Scope Classification Workflow
Classify products under the EU Radio Equipment Directive with a cited workflow for RED scope, exclusions, Article 3 requirements, standards, CE evidence, cybersecurity, and common-charger triggers.
RED Article 10 labelling, instructions, and restrictions
Apply RED Article 10 to product identifiers, manufacturer contacts, instructions, declaration statements, radio-frequency information, charging labels, and use restrictions.
RED Article 3 requirement selection workflow
Select the right RED Article 3 branches for radio equipment: safety, EMC, spectrum, delegated Article 3(3) duties, cybersecurity, common charging, evidence, and conformity assessment.
RED Article 3 Requirements: Safety, EMC, Spectrum and Cyber
Map Radio Equipment Directive Article 3(1), 3(2), and 3(3) requirements to safety, EMC, spectrum, interoperability, emergency, software, and cyber evidence.
RED Compliance Checklist for Radio Equipment
Use this RED release checklist for product scope, Article 3 requirements, technical documentation, EU declarations, CE marking, cybersecurity, common charging, and notified-body decisions.
RED compliance deadlines calendar: 2016 to 2027
Calendar EU Radio Equipment Directive launch dates through 2027: RED applicability, common charger, cybersecurity, standards, CE marking, declarations and retention.
RED conformity assessment and CE marking
EU Radio Equipment Directive guide to Article 17 conformity modules, notified-body triggers, technical documentation, EU declarations, and CE marking.
RED Conformity Assessment Template
Template fields for documenting RED Article 3 requirements, Article 17 route selection, harmonised standards, notified-body evidence, technical documentation, EU declaration, CE marking, cybersecurity, and common-charger checks.
RED Cyber Compliance Workflow for Article 3(3)(d/e/f)
A cited RED cybersecurity workflow for internet-connected radio equipment, privacy and data safeguards, payment-fraud features, evidence packs, and CE release gates.
RED Cybersecurity Delegated Act Guide | Article 3(3)(d/e/f)
Guide to RED Article 3(3)(d), (e), and (f) scope, EN 18031 evidence, the 1 August 2025 application date, and repeal of Delegated Regulation (EU) 2022/30 from 11 December 2027.
RED Cybersecurity Requirements for Radio Equipment
EU RED cybersecurity requirements under Article 3(3)(d), (e), and (f): scope, affected radio equipment, application date, standards, notified bodies, and evidence.
RED DoC and CE marking file: what to include
FAQ answer for Radio Equipment Directive declarations of conformity, CE marking evidence, technical documentation, notified-body records, and related labels.
RED EMC and LVD Safety Interplay for Radio Equipment
Explain how EU RED Article 3 applies LVD safety objectives and EMC requirements to radio equipment, with evidence, test-plan, and technical-file guidance.
RED Harmonised Standards and Test Plans: OJEU evidence guide
Build a Radio Equipment Directive standards matrix and test plan around OJEU-cited harmonised standards, Article 3 requirements, Article 17 route triggers, and Annex V technical-file evidence.
RED importer obligations FAQ | Directive 2014/53/EU
What importers must check before placing radio equipment on the EU market: conformity assessment, spectrum use, technical documentation, EU declaration, CE marking, traceability, instructions, restrictions, storage, corrective action, and authority cooperation.
RED notified body route selection under Article 17
Decide when RED radio equipment can use internal production control and when Article 17 requires Annex III EU-type examination or Annex IV full quality assurance.
RED Notified Body Trigger Workflow: Article 17 evidence guide
Decide when the EU Radio Equipment Directive needs a notified body by mapping Article 3 requirements, OJEU-cited harmonised standards, Annex III EU-type examination, and Annex IV full quality assurance evidence.
RED penalties, fines, and enforcement actions
EU Radio Equipment Directive penalties guide covering Article 46, Member State penalty rules, recalls, withdrawals, formal non-compliance, and enforcement evidence.
RED radio modules FAQ: host product assessment
FAQ on how Directive 2014/53/EU treats RF modules and host products, including module evidence, final-product responsibility, Article 3 assessment, technical documentation, instructions, antennas, software, and DoC records.
RED SAR and RF Exposure Evidence FAQ
What SAR and RF exposure evidence to keep under the EU Radio Equipment Directive, including Article 3(1)(a), foreseeable use, frequency, power, antenna, and standards evidence.
RED software update impact for radio equipment
Assess when firmware, app, and software updates can affect EU Radio Equipment Directive conformity, technical documentation, DoC, standards, and notified-body evidence.
RED standards not cited in the OJEU: can you use them?
FAQ answer for Radio Equipment Directive products when a standard is useful but not OJEU-cited, including presumption of conformity, Article 17 route selection, and technical-file evidence.
RED vs Cyber Resilience Act for radio equipment
Compare EU RED cybersecurity and Cyber Resilience Act duties for connected radio equipment, including scope, dates, evidence, reporting, and conformity routes.
RED vs EMC Directive: which law applies to radio equipment?
Decide when EU radio equipment uses RED instead of the EMC Directive and how to place EMC tests, declarations, fixed installations, and technical evidence.
RED vs ETSI EN 303 645: what the IoT standard proves
Compare binding EU RED cybersecurity duties with ETSI EN 303 645 consumer IoT standard, current editions, EN 18031, evidence reuse, and CE conformity.
RED vs LVD: electrical safety for radio equipment
Decide when EU radio equipment uses RED safety requirements instead of the Low Voltage Directive, including voltage limits, chargers, evidence, and declarations.
RED vs Market Surveillance Regulation for radio equipment
Compare RED product-conformity duties with Regulation (EU) 2019/1020 for responsible operators, online offers, customs controls, authority requests, and corrective action.
When do RED cybersecurity requirements apply to connected radio equipment? | RED FAQ
RED FAQ explaining when Article 3(3)(d), (e), and (f) cybersecurity requirements apply to internet-connected, childcare, toy, wearable, and payment-capable radio equipment.
Which receivers and transmitters are covered by RED? | Directive 2014/53/EU FAQ
RED scope FAQ for products that intentionally emit or receive radio waves for radio communication or radiodetermination, including receiver-only products, transmitters, accessory-dependent products, and common exclusions.
Wi-Fi and Bluetooth Products Under the EU RED
FAQ for assessing Wi-Fi, Bluetooth, BLE and other short-range wireless products under the EU Radio Equipment Directive, including Article 3, CE, technical file, cybersecurity and notified-body triggers.