A practical crosswalk for teams that already have ETSI EN 303 645 consumer IoT evidence and need to decide what can, and cannot, be reused for a UK PSTI review.
The UK regime has applied since 29 April 2024. It takes four provisions from EN 303 645 into law, but its scope, duty holders, statement of compliance, and enforcement rules remain separate.
compliance is narrower than full ETSI EN 303 645 coverage but legally mandatory for in-scope consumer connectable products supplied to UK consumers. Since 29 April 2024, the regime has required compliant password design, published vulnerability-reporting information, published minimum security-update periods, and a statement of compliance that accompanies the product. The 2023 Regulations base those security requirements on EN 303 645 provisions 5.1-1, 5.1-2, 5.2-1, and 5.3-13. Existing ETSI evidence can support the technical case, but it does not replace the PSTI scope, supply-chain, statement, recordkeeping, and enforcement analysis.
Side-by-side comparison
ETSI EN 303 645 vs UK PSTI: what can be reused?
Compare ETSI EN 303 645 evidence against review needs without assuming that an ETSI assessment proves UK legal scope, duties, timing, or enforcement exposure.
This side supports cited consumer IoT baseline provisions, implementation conformance statements, IXIT evidence, and TS 103 701 assessment records.
Second framework
UK PSTI
A mandatory UK regime for relevant consumer connectable products, with three security requirements, supply-chain duties, a statement of compliance, and OPSS enforcement.
ETSI EN 303 645 covers consumer IoT devices connected to network infrastructure and their interactions with associated services; devices primarily intended for manufacturing, healthcare, or other industrial applications are outside the ETSI scope described here.
PSTI covers relevant internet-connectable or network-connectable products intended mainly for consumers or likely to be used by consumers. The Regulations except specified products, including certain medical devices, smart meters, EV charge points, vehicles, desktop computers, laptop computers, and tablet computers without cellular-network capability; these computer categories are not excepted where the manufacturer's intended purpose is exclusively for children under 14. Product and territorial exceptions depend on the facts.
ETSI TS 103 701 separates the Supplier Organization, which can be the developer, manufacturer, vendor, or distributor of the DUT, from the Test Laboratory that carries out conformance assessment.
PSTI assigns duties to manufacturers, importers, and distributors. Manufacturers carry the security-requirement and statement duties. Importers and distributors must ensure the required statement accompanies the product, or for the current deemed-compliance routes be satisfied that the statutory label conditions are met, and must not supply a product where they know or believe there is a manufacturer security-requirement failure. They must also investigate and act on suspected failures. Authorised representatives have specified duties when appointed.
Use ETSI assessment contacts to route evidence, but record each PSTI duty holder separately. A Test Laboratory verdict does not transfer or discharge a supply-chain actor's statutory duty.
ETSI work starts with a consumer IoT product boundary and the provisions claimed for that product. Conditional and feature-based provisions depend on the device, mechanisms, and capabilities described in the ICS and IXIT.
The duties apply when a relevant connectable product is made available to consumers in the UK. The regime came into force on 29 April 2024. Scope depends on connectability, consumer use, supply-chain role, territory, and any exception, not on an ETSI ICS status.
Schedule 1 prohibits universal default and easily guessable passwords, requires publication of at least one point of contact and expected acknowledgement and status-update timing for security reports, and requires publication of the minimum security-update period. These requirements are based on EN 303 645 provisions 5.1-1, 5.1-2, 5.2-1, and 5.3-13.
Map those four ETSI provisions to the three PSTI requirements. Keep the remaining EN 303 645 provisions as voluntary baseline evidence unless another legal or contractual requirement applies.
ETSI evidence should include product identification, an ICS, IXIT information, public vulnerability-disclosure and support-period information where relevant, conceptual and functional test records, external evidence references, and verdicts.
PSTI evidence should include the scope and exception decision, password design, published vulnerability-reporting information, published minimum security-update period, the Schedule 4 statement of compliance, proof that it accompanies the product, and supply-chain investigation and corrective-action records where relevant.
ETSI EN 303 645 uses timing concepts such as acknowledgement and status-update timelines in the vulnerability disclosure policy, timely action on vulnerabilities, timely security updates, periodic checks for updates, and a published defined support period.
PSTI has applied since 29 April 2024. The manufacturer must publish a minimum security-update period and the vulnerability-reporting acknowledgement and status-update timing. A copy of the statement of compliance must generally be retained for 10 years from issue or for the stated support period, whichever is longer.
Separate operational timing from statutory records. Align the published PSTI support period with the product record, statement of compliance, vulnerability process, and any longer contractual commitment.
ETSI TS 103 701 describes a conformance assessment methodology with test groups, conceptual and functional tests, external evidence, and PASS/FAIL verdicts. It also states that the document is independent from an assurance scheme.
OPSS enforces the product-security regime. It can issue compliance, stop, and recall notices, seek forfeiture, and impose monetary penalties. The statutory maximum is GBP 10 million or 4% of qualifying worldwide revenue, whichever is greater, with an additional daily penalty available for continuing non-compliance.
Use ETSI assessment results as technical assurance evidence. Keep a separate PSTI compliance record that can support the statutory security, statement, supply, and corrective-action duties.
Reusable ETSI artifacts are strongest when they are product-versioned and traceable: ICS status, IXIT fields, password-generation evidence, vulnerability policy, update mechanism, support-period publication, user-data deletion checks, telemetry review, and interface inventory.
Reuse password, vulnerability-disclosure, and support-period evidence where it matches the statutory product and requirement. Create new records for PSTI scope, exceptions, duty holders, the statement of compliance, proof that it accompanies the product, and supply-chain actions.
Reuse reduces duplicate work only when the cited claim is the same. Otherwise, keep a bridge note explaining what the ETSI evidence does and does not prove.
Use ETSI EN 303 645 as the controlling source when the question is whether a consumer IoT product has mapped, implemented, justified, or assessed ETSI baseline provisions.
Use the PSTI Act and 2023 Regulations when the question is UK legal scope, duty holder, security requirement, statement content, supply trigger, recordkeeping, enforcement, or penalty.
ETSI EN 303 645 covers consumer IoT devices connected to network infrastructure and their interactions with associated services; devices primarily intended for manufacturing, healthcare, or other industrial applications are outside the ETSI scope described here.
PSTI covers relevant internet-connectable or network-connectable products intended mainly for consumers or likely to be used by consumers. The Regulations except specified products, including certain medical devices, smart meters, EV charge points, vehicles, desktop computers, laptop computers, and tablet computers without cellular-network capability; these computer categories are not excepted where the manufacturer's intended purpose is exclusively for children under 14. Product and territorial exceptions depend on the facts.
ETSI TS 103 701 separates the Supplier Organization, which can be the developer, manufacturer, vendor, or distributor of the DUT, from the Test Laboratory that carries out conformance assessment.
PSTI assigns duties to manufacturers, importers, and distributors. Manufacturers carry the security-requirement and statement duties. Importers and distributors must ensure the required statement accompanies the product, or for the current deemed-compliance routes be satisfied that the statutory label conditions are met, and must not supply a product where they know or believe there is a manufacturer security-requirement failure. They must also investigate and act on suspected failures. Authorised representatives have specified duties when appointed.
Use ETSI assessment contacts to route evidence, but record each PSTI duty holder separately. A Test Laboratory verdict does not transfer or discharge a supply-chain actor's statutory duty.
ETSI work starts with a consumer IoT product boundary and the provisions claimed for that product. Conditional and feature-based provisions depend on the device, mechanisms, and capabilities described in the ICS and IXIT.
The duties apply when a relevant connectable product is made available to consumers in the UK. The regime came into force on 29 April 2024. Scope depends on connectability, consumer use, supply-chain role, territory, and any exception, not on an ETSI ICS status.
Schedule 1 prohibits universal default and easily guessable passwords, requires publication of at least one point of contact and expected acknowledgement and status-update timing for security reports, and requires publication of the minimum security-update period. These requirements are based on EN 303 645 provisions 5.1-1, 5.1-2, 5.2-1, and 5.3-13.
Map those four ETSI provisions to the three PSTI requirements. Keep the remaining EN 303 645 provisions as voluntary baseline evidence unless another legal or contractual requirement applies.
ETSI evidence should include product identification, an ICS, IXIT information, public vulnerability-disclosure and support-period information where relevant, conceptual and functional test records, external evidence references, and verdicts.
PSTI evidence should include the scope and exception decision, password design, published vulnerability-reporting information, published minimum security-update period, the Schedule 4 statement of compliance, proof that it accompanies the product, and supply-chain investigation and corrective-action records where relevant.
ETSI EN 303 645 uses timing concepts such as acknowledgement and status-update timelines in the vulnerability disclosure policy, timely action on vulnerabilities, timely security updates, periodic checks for updates, and a published defined support period.
PSTI has applied since 29 April 2024. The manufacturer must publish a minimum security-update period and the vulnerability-reporting acknowledgement and status-update timing. A copy of the statement of compliance must generally be retained for 10 years from issue or for the stated support period, whichever is longer.
Separate operational timing from statutory records. Align the published PSTI support period with the product record, statement of compliance, vulnerability process, and any longer contractual commitment.
ETSI TS 103 701 describes a conformance assessment methodology with test groups, conceptual and functional tests, external evidence, and PASS/FAIL verdicts. It also states that the document is independent from an assurance scheme.
OPSS enforces the product-security regime. It can issue compliance, stop, and recall notices, seek forfeiture, and impose monetary penalties. The statutory maximum is GBP 10 million or 4% of qualifying worldwide revenue, whichever is greater, with an additional daily penalty available for continuing non-compliance.
Use ETSI assessment results as technical assurance evidence. Keep a separate PSTI compliance record that can support the statutory security, statement, supply, and corrective-action duties.
Reusable ETSI artifacts are strongest when they are product-versioned and traceable: ICS status, IXIT fields, password-generation evidence, vulnerability policy, update mechanism, support-period publication, user-data deletion checks, telemetry review, and interface inventory.
Reuse password, vulnerability-disclosure, and support-period evidence where it matches the statutory product and requirement. Create new records for PSTI scope, exceptions, duty holders, the statement of compliance, proof that it accompanies the product, and supply-chain actions.
Reuse reduces duplicate work only when the cited claim is the same. Otherwise, keep a bridge note explaining what the ETSI evidence does and does not prove.
Use ETSI EN 303 645 as the controlling source when the question is whether a consumer IoT product has mapped, implemented, justified, or assessed ETSI baseline provisions.
Use the PSTI Act and 2023 Regulations when the question is UK legal scope, duty holder, security requirement, statement content, supply trigger, recordkeeping, enforcement, or penalty.
How should teams decide whether to prioritize ETSI EN 303 645 or UK PSTI compliance work?
Prioritize for supplying an in-scope product to UK consumers: the regime is mandatory, subject to its product and territorial exceptions, and its security requirements were built from ETSI EN 303 645 provisions 5.1-1, 5.1-2, 5.2-1, and 5.3-13.
Use ETSI EN 303 645 as a broader security baseline for products sold in the EU, UK, and other markets simultaneously, and keep TS 103 701 conformance evidence to support any EN 303 645 claims.
Keep separate compliance records for each regime because the statement of compliance and authorized signatory requirements differ between and a voluntary EN 303 645 assessment.
Escalate when products use password-reset or credential-management flows, universal default passwords, or software update suppression, as these are PSTI-critical areas with direct EN 303 645 equivalents.
ETSI EN 303 645 is useful because it is specific about consumer IoT baseline topics: default passwords, vulnerability reporting, software updates, secure storage, secure communications, attack-surface reduction, software integrity, personal-data security, resilience, telemetry review, user-data deletion, installation, maintenance, and input validation.
ETSI TS 103 701 adds an assessment structure. It identifies the Device Under Test, Supplier Organization, Test Laboratory, Implementation Conformance Statement, Implementation eXtra Information for Testing, test groups, verdicts, and use of external evidence.
Those artifacts can shorten a review, but they do not by themselves prove UK legal scope, satisfy the statement-of-compliance duty, or allocate responsibilities across the supply chain. The manufacturer, importer, and distributor must each perform the checks and actions assigned by the PSTI Act.
Use the ETSI column to identify reusable product-security controls and evidence records.
Use the column to record the statutory requirement, responsible actor, product and supply facts, statement field, and evidence used.
Do not turn ETSI recommendations, conditions, or assessment verdicts into UK legal claims unless the PSTI source supports that translation.
Start with evidence that describes the shipped product and can be read without tribal knowledge: product model, consumer IoT scope, associated services, authentication mechanisms, software components, update mechanisms, vulnerability disclosure policy, support period, telemetry data, deletion functionality, user instructions, and exposed interfaces.
For assessment work, keep the ICS and IXIT records close to the product version. ETSI TS 103 701 uses those records to plan tests and check whether claimed provisions, non-applicability positions, and implementation details are coherent.
Scope record: consumer IoT device, associated services, software version, product model, and excluded industrial or non-consumer uses.
Use the ETSI EN 303 645 evidence pack as the technical baseline, then isolate the UK PSTI questions that need separate source confirmation before public claims are made.
PSTI covers relevant internet-connectable or network-connectable products intended mainly for consumers or likely to be used by consumers. The Regulations except specified products, including certain medical devices, smart meters, EV charge points, vehicles, desktop computers, laptop computers, and tablet computers without cellular-network capability, with a limited child-focused exception. Products supplied in Northern Ireland can also fall outside this regime where the Windsor Framework condition in the Regulations is met.
Manufacturers must comply with the security requirements, investigate and act on compliance failures, ensure a statement of compliance accompanies the product, and retain required records. Importers and distributors must not make the product available where the territorial or consumer-product condition applies and they know or believe that the manufacturer has failed to comply with a relevant security requirement; they also have their own investigation, notification, and corrective-action obligations.
The statement of compliance must identify the product by type and batch; name and address each manufacturer and any authorised representative; declare who prepared the statement and whether the manufacturer relies on Schedule 1 requirements or a deemed-compliance route; state the support period that was correct when the manufacturer first supplied the product; and include the signatory's signature, name, function, place, and date of issue. If a deemed-compliance route relies on a specified standard, the statement must include its identification number, version, and issue date where applicable.
Since 4 December 2025, specified current labels under Japan JC-STAR STAR-1 or any level of the Singapore Cybersecurity Labelling Scheme can satisfy conditions for deemed compliance with the security requirements and the requirement for a statement to accompany the product. This is a statutory alternative with scheme and label conditions, not a general exemption from all PSTI duties.
Scope the product from its connectability, intended consumer use, actual likely consumer use, UK supply facts, and any specific exception.
Identify every manufacturer, importer, distributor, and authorised representative involved in the UK supply chain.
Map the four cited EN 303 645 provisions to the three Schedule 1 security requirements without treating the rest of EN 303 645 as UK law.
Prepare the Schedule 4 statement of compliance, make it accompany the product, and retain the required copy for the statutory period.
Reassess the UK record before a new model, batch, manufacturer, importer, distribution route, intended use, connectivity design, support-period commitment, or relied-on overseas label changes.
This checklist is relevant when moving from ETSI evidence to a review. Each item should produce a record that says whether the artifact is reusable, needs adaptation, or is not supported by the available cited sources.
Name the product version, model designation, software version, associated services, and support-period statement used for the ETSI evidence pack.
List the ETSI provisions claimed as fulfilled, not fulfilled, or not applicable, including the justification for each recommendation treated as not applicable or not fulfilled.
Attach the ICS and IXIT entries used for passwords, vulnerability disclosure, updates, interfaces, telemetry, deletion, user decisions, and input validation.
Record whether each ETSI artifact is technical evidence only, legal-scope evidence, customer-facing evidence, or not reusable for without a separate source.
Escalate rows where the source is missing, the role is unclear, the product scope differs, or the public statement would imply a legal conclusion not supported by this evidence.
Introduces conditional deemed-compliance routes for current Japan JC-STAR STAR-1 and Singapore Cybersecurity Labelling Scheme labels from 4 December 2025.