ComparisonGLOBALETSI EN 303 645

ETSI EN 303 645 vs UK PSTI

A practical crosswalk for teams that already have ETSI EN 303 645 consumer IoT evidence and need to decide what can, and cannot, be reused for a UK PSTI review.

The UK regime has applied since 29 April 2024. It takes four provisions from EN 303 645 into law, but its scope, duty holders, statement of compliance, and enforcement rules remain separate.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

compliance is narrower than full ETSI EN 303 645 coverage but legally mandatory for in-scope consumer connectable products supplied to UK consumers. Since 29 April 2024, the regime has required compliant password design, published vulnerability-reporting information, published minimum security-update periods, and a statement of compliance that accompanies the product. The 2023 Regulations base those security requirements on EN 303 645 provisions 5.1-1, 5.1-2, 5.2-1, and 5.3-13. Existing ETSI evidence can support the technical case, but it does not replace the PSTI scope, supply-chain, statement, recordkeeping, and enforcement analysis.

Side-by-side comparison

ETSI EN 303 645 vs UK PSTI: what can be reused?

Compare ETSI EN 303 645 evidence against review needs without assuming that an ETSI assessment proves UK legal scope, duties, timing, or enforcement exposure.

Review all sources
First framework
ETSI EN 303 645

This side supports cited consumer IoT baseline provisions, implementation conformance statements, IXIT evidence, and TS 103 701 assessment records.

Second framework
UK PSTI

A mandatory UK regime for relevant consumer connectable products, with three security requirements, supply-chain duties, a statement of compliance, and OPSS enforcement.

Comparison row 1

Scope and covered activity

ETSI EN 303 645

ETSI EN 303 645 covers consumer IoT devices connected to network infrastructure and their interactions with associated services; devices primarily intended for manufacturing, healthcare, or other industrial applications are outside the ETSI scope described here.

UK PSTI

PSTI covers relevant internet-connectable or network-connectable products intended mainly for consumers or likely to be used by consumers. The Regulations except specified products, including certain medical devices, smart meters, EV charge points, vehicles, desktop computers, laptop computers, and tablet computers without cellular-network capability; these computer categories are not excepted where the manufacturer's intended purpose is exclusively for children under 14. Product and territorial exceptions depend on the facts.

Operational implication

An ETSI scope record is a useful starting artifact, but the crosswalk should keep a separate PSTI scope decision with its own source citation.

Comparison row 2

Who must act

ETSI EN 303 645

ETSI TS 103 701 separates the Supplier Organization, which can be the developer, manufacturer, vendor, or distributor of the DUT, from the Test Laboratory that carries out conformance assessment.

UK PSTI

PSTI assigns duties to manufacturers, importers, and distributors. Manufacturers carry the security-requirement and statement duties. Importers and distributors must ensure the required statement accompanies the product, or for the current deemed-compliance routes be satisfied that the statutory label conditions are met, and must not supply a product where they know or believe there is a manufacturer security-requirement failure. They must also investigate and act on suspected failures. Authorised representatives have specified duties when appointed.

Operational implication

Use ETSI assessment contacts to route evidence, but record each PSTI duty holder separately. A Test Laboratory verdict does not transfer or discharge a supply-chain actor's statutory duty.

Comparison row 3

Trigger or threshold

ETSI EN 303 645

ETSI work starts with a consumer IoT product boundary and the provisions claimed for that product. Conditional and feature-based provisions depend on the device, mechanisms, and capabilities described in the ICS and IXIT.

UK PSTI

The duties apply when a relevant connectable product is made available to consumers in the UK. The regime came into force on 29 April 2024. Scope depends on connectability, consumer use, supply-chain role, territory, and any exception, not on an ETSI ICS status.

Operational implication

A release gate should show two trigger facts: the ETSI provision/assessment trigger and the separately sourced trigger.

Comparison row 4

Core obligations

ETSI EN 303 645

ETSI EN 303 645 includes baseline consumer IoT provisions for passwords, vulnerability reporting, software updates, secure storage, secure communication, attack-surface minimization, software integrity, personal-data security, resilience, telemetry, user-data deletion, installation, maintenance, and input validation.

UK PSTI

Schedule 1 prohibits universal default and easily guessable passwords, requires publication of at least one point of contact and expected acknowledgement and status-update timing for security reports, and requires publication of the minimum security-update period. These requirements are based on EN 303 645 provisions 5.1-1, 5.1-2, 5.2-1, and 5.3-13.

Operational implication

Map those four ETSI provisions to the three PSTI requirements. Keep the remaining EN 303 645 provisions as voluntary baseline evidence unless another legal or contractual requirement applies.

Comparison row 5

Evidence and records

ETSI EN 303 645

ETSI evidence should include product identification, an ICS, IXIT information, public vulnerability-disclosure and support-period information where relevant, conceptual and functional test records, external evidence references, and verdicts.

UK PSTI

PSTI evidence should include the scope and exception decision, password design, published vulnerability-reporting information, published minimum security-update period, the Schedule 4 statement of compliance, proof that it accompanies the product, and supply-chain investigation and corrective-action records where relevant.

Operational implication

Keep one matrix with columns for source, claim, artifact, product version, owner, ETSI status, PSTI status, and unresolved issue.

Comparison row 6

Timing and cadence

ETSI EN 303 645

ETSI EN 303 645 uses timing concepts such as acknowledgement and status-update timelines in the vulnerability disclosure policy, timely action on vulnerabilities, timely security updates, periodic checks for updates, and a published defined support period.

UK PSTI

PSTI has applied since 29 April 2024. The manufacturer must publish a minimum security-update period and the vulnerability-reporting acknowledgement and status-update timing. A copy of the statement of compliance must generally be retained for 10 years from issue or for the stated support period, whichever is longer.

Operational implication

Separate operational timing from statutory records. Align the published PSTI support period with the product record, statement of compliance, vulnerability process, and any longer contractual commitment.

Comparison row 7

Enforcement or assurance route

ETSI EN 303 645

ETSI TS 103 701 describes a conformance assessment methodology with test groups, conceptual and functional tests, external evidence, and PASS/FAIL verdicts. It also states that the document is independent from an assurance scheme.

UK PSTI

OPSS enforces the product-security regime. It can issue compliance, stop, and recall notices, seek forfeiture, and impose monetary penalties. The statutory maximum is GBP 10 million or 4% of qualifying worldwide revenue, whichever is greater, with an additional daily penalty available for continuing non-compliance.

Operational implication

Use ETSI assessment results as technical assurance evidence. Keep a separate PSTI compliance record that can support the statutory security, statement, supply, and corrective-action duties.

Comparison row 8

Overlap and reuse

ETSI EN 303 645

Reusable ETSI artifacts are strongest when they are product-versioned and traceable: ICS status, IXIT fields, password-generation evidence, vulnerability policy, update mechanism, support-period publication, user-data deletion checks, telemetry review, and interface inventory.

UK PSTI

Reuse password, vulnerability-disclosure, and support-period evidence where it matches the statutory product and requirement. Create new records for PSTI scope, exceptions, duty holders, the statement of compliance, proof that it accompanies the product, and supply-chain actions.

Operational implication

Reuse reduces duplicate work only when the cited claim is the same. Otherwise, keep a bridge note explaining what the ETSI evidence does and does not prove.

Comparison row 9

Practical decision rule

ETSI EN 303 645

Use ETSI EN 303 645 as the controlling source when the question is whether a consumer IoT product has mapped, implemented, justified, or assessed ETSI baseline provisions.

UK PSTI

Use the PSTI Act and 2023 Regulations when the question is UK legal scope, duty holder, security requirement, statement content, supply trigger, recordkeeping, enforcement, or penalty.

Operational implication

Before release, label every row as ETSI evidence, PSTI evidence, shared evidence, or unresolved.

Practical decision rule

How should teams decide whether to prioritize ETSI EN 303 645 or UK PSTI compliance work?

  • Prioritize for supplying an in-scope product to UK consumers: the regime is mandatory, subject to its product and territorial exceptions, and its security requirements were built from ETSI EN 303 645 provisions 5.1-1, 5.1-2, 5.2-1, and 5.3-13.
  • Use ETSI EN 303 645 as a broader security baseline for products sold in the EU, UK, and other markets simultaneously, and keep TS 103 701 conformance evidence to support any EN 303 645 claims.
  • Keep separate compliance records for each regime because the statement of compliance and authorized signatory requirements differ between and a voluntary EN 303 645 assessment.
  • Escalate when products use password-reset or credential-management flows, universal default passwords, or software update suppression, as these are PSTI-critical areas with direct EN 303 645 equivalents.
Section 1

What this comparison can support

ETSI EN 303 645 is useful because it is specific about consumer IoT baseline topics: default passwords, vulnerability reporting, software updates, secure storage, secure communications, attack-surface reduction, software integrity, personal-data security, resilience, telemetry review, user-data deletion, installation, maintenance, and input validation.

ETSI TS 103 701 adds an assessment structure. It identifies the Device Under Test, Supplier Organization, Test Laboratory, Implementation Conformance Statement, Implementation eXtra Information for Testing, test groups, verdicts, and use of external evidence.

Those artifacts can shorten a review, but they do not by themselves prove UK legal scope, satisfy the statement-of-compliance duty, or allocate responsibilities across the supply chain. The manufacturer, importer, and distributor must each perform the checks and actions assigned by the PSTI Act.

  • Use the ETSI column to identify reusable product-security controls and evidence records.
  • Use the column to record the statutory requirement, responsible actor, product and supply facts, statement field, and evidence used.
  • Do not turn ETSI recommendations, conditions, or assessment verdicts into UK legal claims unless the PSTI source supports that translation.
Section 2

ETSI evidence that is worth mapping first

Start with evidence that describes the shipped product and can be read without tribal knowledge: product model, consumer IoT scope, associated services, authentication mechanisms, software components, update mechanisms, vulnerability disclosure policy, support period, telemetry data, deletion functionality, user instructions, and exposed interfaces.

For assessment work, keep the ICS and IXIT records close to the product version. ETSI TS 103 701 uses those records to plan tests and check whether claimed provisions, non-applicability positions, and implementation details are coherent.

  • Scope record: consumer IoT device, associated services, software version, product model, and excluded industrial or non-consumer uses.
  • Security-control record: passwords, vulnerability intake, update mechanism, secure communication, attack-surface controls, software integrity, and input validation.
  • User-facing record: update-support period, security setup guidance, vulnerability reporting channel, data-deletion instructions, and security-relevant notices.
  • Assessment record: ICS claim, IXIT evidence, conceptual test result, functional test result, external evidence reference, and final verdict.
Section 3

What UK PSTI adds to the ETSI evidence pack

PSTI covers relevant internet-connectable or network-connectable products intended mainly for consumers or likely to be used by consumers. The Regulations except specified products, including certain medical devices, smart meters, EV charge points, vehicles, desktop computers, laptop computers, and tablet computers without cellular-network capability, with a limited child-focused exception. Products supplied in Northern Ireland can also fall outside this regime where the Windsor Framework condition in the Regulations is met.

Manufacturers must comply with the security requirements, investigate and act on compliance failures, ensure a statement of compliance accompanies the product, and retain required records. Importers and distributors must not make the product available where the territorial or consumer-product condition applies and they know or believe that the manufacturer has failed to comply with a relevant security requirement; they also have their own investigation, notification, and corrective-action obligations.

The statement of compliance must identify the product by type and batch; name and address each manufacturer and any authorised representative; declare who prepared the statement and whether the manufacturer relies on Schedule 1 requirements or a deemed-compliance route; state the support period that was correct when the manufacturer first supplied the product; and include the signatory's signature, name, function, place, and date of issue. If a deemed-compliance route relies on a specified standard, the statement must include its identification number, version, and issue date where applicable.

Since 4 December 2025, specified current labels under Japan JC-STAR STAR-1 or any level of the Singapore Cybersecurity Labelling Scheme can satisfy conditions for deemed compliance with the security requirements and the requirement for a statement to accompany the product. This is a statutory alternative with scheme and label conditions, not a general exemption from all PSTI duties.

  • Scope the product from its connectability, intended consumer use, actual likely consumer use, UK supply facts, and any specific exception.
  • Identify every manufacturer, importer, distributor, and authorised representative involved in the UK supply chain.
  • Map the four cited EN 303 645 provisions to the three Schedule 1 security requirements without treating the rest of EN 303 645 as UK law.
  • Prepare the Schedule 4 statement of compliance, make it accompany the product, and retain the required copy for the statutory period.
  • Reassess the UK record before a new model, batch, manufacturer, importer, distribution route, intended use, connectivity design, support-period commitment, or relied-on overseas label changes.
Section 4

Crosswalk review checklist

This checklist is relevant when moving from ETSI evidence to a review. Each item should produce a record that says whether the artifact is reusable, needs adaptation, or is not supported by the available cited sources.

  • Name the product version, model designation, software version, associated services, and support-period statement used for the ETSI evidence pack.
  • List the ETSI provisions claimed as fulfilled, not fulfilled, or not applicable, including the justification for each recommendation treated as not applicable or not fulfilled.
  • Attach the ICS and IXIT entries used for passwords, vulnerability disclosure, updates, interfaces, telemetry, deletion, user decisions, and input validation.
  • Record whether each ETSI artifact is technical evidence only, legal-scope evidence, customer-facing evidence, or not reusable for without a separate source.
  • Escalate rows where the source is missing, the role is unclear, the product scope differs, or the public statement would imply a legal conclusion not supported by this evidence.
Primary sources

References and citations

Related guides

Explore more topics

ETSI EN 303 645 Applicability and Scope
Decide whether a connected product is in scope of ETSI EN 303 645, define the consumer IoT evidence boundary, and document N/A justifications for assessment.
ETSI EN 303 645 compliance: ICS, IXIT, evidence
Plan ETSI EN 303 645 compliance evidence for consumer IoT products with scope, ICS, IXIT, TS 103 701 assessment steps, verdict risks, and cited controls.
ETSI EN 303 645 consumer IoT products: what is in scope?
Decide whether a device and its associated services are in scope of ETSI EN 303 645 V3.1.3 and document the DUT, ICS, IXIT, and assessment boundary.
ETSI EN 303 645 Current Version Tracker
Track ETSI EN 303 645 version evidence, ETSI deliverable status checks, TS 103 701 assessment alignment, and change triggers for consumer IoT security work.
ETSI EN 303 645 CVD Workflow for IoT Vulnerability Reports
Cited workflow for ETSI EN 303 645 vulnerability disclosure: public policy contents, reporting contact, acknowledgement and status timelines, timely action, and TS 103 701 evidence.
ETSI EN 303 645 Data Protection Provisions
Guide to ETSI EN 303 645 data protection provisions for consumer IoT, including security, consent, telemetry, deletion, minimization, aggregation, and anonymization.
ETSI EN 303 645 default passwords: what must consumer IoT teams do?
ETSI EN 303 645 default password guidance for consumer IoT: unique or user-defined passwords, pre-installed password generation, change mechanisms, brute-force controls, and TS 103 701 evidence.
ETSI EN 303 645 FAQ: Consumer IoT Security Questions
Practical answers to common ETSI EN 303 645 questions on consumer IoT scope, associated services, passwords, updates, vulnerability disclosure, telemetry, deletion, and assessment evidence.
ETSI EN 303 645 ICS and IXIT Evidence Template
Build a cited ICS and IXIT evidence template for ETSI EN 303 645 consumer IoT assessments, with clear separation between EN provisions and TS 103 701 test information.
ETSI EN 303 645 implementation checklist
This ETSI EN 303 645 implementation checklist helps scope a consumer IoT product, record Annex B support statuses, map IXIT evidence, and avoid weak conformance claims.
ETSI EN 303 645 Implementation Evidence Guide
Build ETSI EN 303 645 implementation evidence from Annex B support/detail records, TS 103 701 ICS and IXIT inputs, test verdicts, and scoped external evidence.
ETSI EN 303 645 IoT Applicability Workflow
Decide whether ETSI EN 303 645 applies to a consumer IoT product, what associated services belong in scope, and how to record justified non-applicability.
ETSI EN 303 645 personal data deletion FAQ for consumer IoT
What ETSI EN 303 645 says about deleting user data and personal data from consumer IoT devices, associated services, apps, and evidence records.
ETSI EN 303 645 requirements: consumer IoT provision map
Map ETSI EN 303 645 consumer IoT requirements to product scope, Annex B ICS entries, TS 103 701 evidence, and implementation owners.
ETSI EN 303 645 Secure Update Evidence Workflow
Build secure-update evidence for ETSI EN 303 645 using provision 5.3, Annex B support/detail records, and TS 103 701 ICS, IXIT, and test-plan inputs.
ETSI EN 303 645 Secure Update Workflow
Map ETSI EN 303 645 secure-update provisions into a practical workflow for consumer IoT update mechanisms, support-period disclosures, and TS 103 701 evidence.
ETSI EN 303 645 Secure Updates and Vulnerability Disclosure
Source-backed guide to ETSI EN 303 645 clauses 5.2 and 5.3 for consumer IoT vulnerability disclosure, security updates, support periods, and assessment evidence.
ETSI EN 303 645 support period: what must consumer IoT teams publish?
ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.
ETSI EN 303 645 telemetry: what should consumer IoT teams evidence?
ETSI EN 303 645 telemetry guidance for consumer IoT teams: security anomaly examination, IXIT 24-TelData evidence, personal-data minimization, and consumer telemetry disclosures.
ETSI EN 303 645 test evidence: what should consumer IoT teams keep?
ETSI EN 303 645 test evidence guidance for consumer IoT teams: ICS support claims, IXIT detail, TS 103 701 test plans, verdicts, and external evidence checks.
ETSI EN 303 645 vs EU CRA for Consumer IoT
Compare ETSI EN 303 645 consumer IoT evidence with the EU Cyber Resilience Act's scope, manufacturer duties, application dates, and conformity requirements.
ETSI EN 303 645 vs RED Cybersecurity Delegated Act
Compare ETSI EN 303 645 consumer IoT evidence with the RED cybersecurity requirements, EN 18031 standards, application date, and conformity routes.
ETSI EN 303 645 vulnerability disclosure requirements for consumer IoT
What ETSI EN 303 645 requires for consumer IoT vulnerability disclosure policies, report handling, status updates, timely action, and TS 103 701 evidence.
ETSI TS 103 701 Test Evidence Workflow for EN 303 645
Build an ETSI TS 103 701 test evidence workflow for EN 303 645 consumer IoT assessments: DUT identification, ICS, IXIT, test plans, verdicts, and external evidence.
How should teams handle constrained devices under ETSI EN 303 645 for consumer IoT products?
How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.