Which ETSI provisions map to the PSTI requirements?
The 2023 Regulations name V2.1.1, dated 19 June 2020. Schedule 2 maps the password requirement to provisions 5.1-1 and, where relevant, 5.1-2; vulnerability reporting to provision 5.2-1; and support-period information to provision 5.3-13, subject to the Schedule's additional conditions.
Only those mapped conditions create the original ETSI route. The rest of EN 303 645 can improve product security, but it is not automatically a binding PSTI requirement. A later ETSI edition does not replace V2.1.1 in the Regulations unless the law is amended.
From 4 December 2025, the amended Regulations also provide specified routes based on current Japan JC-STAR STAR-1 and Singapore Cybersecurity Labelling Scheme labels. They also add Schedule 2A conditions for with the manufacturer's statement-accompaniment duty. These are condition-specific alternatives, not recognition of every foreign certificate or a waiver of all PSTI duties.
- Record the exact EN 303 645 edition, provision, Schedule 1 requirement, and product or software scope.
- Treat ISO/IEC 29147:2018 as an alternative deemed-compliance route only for the specified vulnerability-disclosure paragraphs and additional Schedule 2 conditions.
- For a recognised label route, retain the scheme and specification version, product and software scope, label identifier, issue and expiry dates, and current public verification record.
- Check the current Regulations before reusing an assessment prepared against a different edition, product configuration, label status, or legal condition.
Specifies the standards, editions, provisions, alternatives, and additional conditions for deemed compliance.
Contains the provisions named in Schedule 2.
Adds specified current-label conditions and the Schedule 2A statement-accompaniment route from 4 December 2025.