Artifact GuideUK and EUPSTI vs CRA

UK PSTI vs EU Cyber Resilience Act

A product sold in both the UK and EU may need two assessments. PSTI sets a focused UK baseline for consumer connectable products; the CRA covers a broader range of hardware and software and adds lifecycle, conformity-assessment, CE-marking, documentation, and incident-reporting duties.

Meeting PSTI does not establish CRA conformity. Reuse technical evidence only after mapping it to each regime's product scope, actor, requirement, timing, and document.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this comparison to decide whether the UK's Product Security and Telecommunications Infrastructure (PSTI) Act 2022, the EU Cyber Resilience Act (CRA), or both apply to a product. The CRA calls its regulated hardware and software category . Start with separate scope findings. Then assign the manufacturer, importer, and distributor duties, map shared security evidence, and keep each regime's declaration, reporting, retention, and market-surveillance records distinct.

Side-by-side comparison

PSTI vs CRA: the operational crosswalk

Use each row as a separate decision. A shared control does not remove either regime's scope, documentation, or reporting test.

Review all sources
First framework
UK PSTI

A UK regime for relevant connectable products made available to consumers, enforced by the Office for Product Safety and Standards.

Second framework
EU CRA

An EU product-safety-style regime for hardware and software made available on the EU market.

Comparison row 1

Product scope

UK PSTI

Relevant internet-connectable or network-connectable products made available to UK consumers. The Act and Regulations include statutory exceptions and actor-specific knowledge or intention tests.

EU CRA

whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Hardware, software, and qualifying remote data processing can be covered.

Operational implication

Define the complete product and service boundary, then write a separate, cited scope conclusion for each market.

Comparison row 2

Security duties

UK PSTI

Three specified areas: passwords, a published route for reporting security issues, and publication of the minimum security-update period. The detailed conditions sit in Schedule 1 of the 2023 Regulations.

EU CRA

Annex I covers secure design and development, risk-based security, default configuration, vulnerability reduction, confidentiality, integrity, availability, attack-surface reduction, security logging where appropriate, updates, vulnerability handling, and related processes.

Operational implication

Use CRA work to widen the engineering baseline, but verify the exact PSTI wording rather than treating a broad CRA control as proof of the narrower UK rule.

Comparison row 3

Required product documents

UK PSTI

A statement of compliance must accompany the product, subject to the Act and any deemed-compliance route. Manufacturers and importers retain it for the longer of 10 years from issue or the stated support period.

EU CRA

Manufacturers prepare technical documentation and an EU declaration of conformity, complete the applicable conformity assessment, and affix CE marking. Technical documentation and the declaration are generally kept for 10 years after market placement or for the support period, whichever is longer.

Operational implication

Do not relabel the UK statement as an EU declaration. Control both documents against the exact product and release.

Comparison row 4

Vulnerability and incident reporting

UK PSTI

The manufacturer publishes at least one contact route for security reports and information about response times. PSTI does not create the CRA's EU-level early-warning and notification sequence.

EU CRA

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security through the CRA process and within the staged deadlines in .

Operational implication

Use one detection and triage process, but maintain a CRA reporting decision tree, clocks, submission evidence, and user-notification assessment.

Comparison row 5

Economic operators

UK PSTI

Manufacturers, importers, distributors, and authorised representatives have distinct UK duties for security requirements, statements, supply checks, compliance failures, notifications, and records.

EU CRA

Manufacturers, importers, distributors, authorised representatives, persons making a substantial modification, and open-source software stewards have role-specific CRA duties. A modifier can assume manufacturer obligations.

Operational implication

Map each legal entity and market role for the actual supply and modification chain; a shared group security team does not replace role-specific accountability.

Comparison row 6

Classification and assessment

UK PSTI

PSTI does not divide products into CRA-style default, important, or critical classes. The UK decision is whether the product, actor, and consumer-market facts trigger the specified duties or an exception.

EU CRA

Annexes III and IV identify important class I, important class II, and critical products. Article 32 links the category and use of applicable standards or certification to internal-control or third-party assessment routes.

Operational implication

Keep the UK scope result and the CRA class and conformity-route result as separate approvals tied to the same product version.

Comparison row 7

Post-market triggers

UK PSTI

A known or reasonably discoverable compliance failure triggers actor-specific investigation, reasonable steps, notification, and record duties. Changes to credentials, reporting routes, support information, or supply facts can require a new assessment.

EU CRA

Manufacturers handle vulnerabilities through the support period, take corrective action for non-conformity, and apply reporting from 11 September 2026. A substantial modification can make the modifier responsible as a manufacturer.

Operational implication

Join release, vulnerability, incident, corrective-action, and modification records to both legal decision trees and reopen the relevant approval when a trigger occurs.

Comparison row 8

Application dates

UK PSTI

PSTI Part 1 and the 2023 Regulations have applied since 29 April 2024.

EU CRA

The CRA entered into force on 10 December 2024. Conformity-body provisions apply from 11 June 2026, reporting duties from 11 September 2026, and most provisions from 11 December 2027.

Operational implication

Treat CRA reporting readiness as a live 2026 workstream even though most product obligations apply in 2027.

Practical decision rule

Which workstream should start first?

  • For a product already supplied to UK consumers, close any PSTI gap now because the regime is already in force.
  • For any EU product with digital elements, classify the product, confirm exclusions, select the conformity route, and build Annex I evidence before the 2027 general application date.
  • Before 11 September 2026, establish CRA detection, legal triage, reporting clocks, submission ownership, and user-notification procedures.
  • When both regimes apply, use one engineering control library and two legal compliance maps.
Section 1

How the regimes differ

PSTI applies to relevant connectable products made available to UK consumers, subject to statutory exceptions. Its current security requirements address passwords, reporting security issues, and publication of the minimum security-update period. The product must also be accompanied by a statement of compliance unless a statutory deemed-compliance route applies.

The CRA is Regulation (EU) 2024/2847. It generally applies to made available on the EU market where their intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. It covers hardware and software, including remote data-processing solutions on which the product depends, but contains exclusions and special rules for areas such as certain medical, automotive, aviation, marine, defence, and free and open-source software.

A connected home camera can be a representative product within both regimes. Standalone commercial software can fall within the CRA even when it is not a UK consumer connectable product. Free and open-source software supplied outside a commercial activity falls outside the CRA's main product duties, while open-source software stewards have a separate role. A sectoral exclusion must be matched to its exact conditions; regulation under another law is not a general exemption.

The CRA entered into force on 10 December 2024. Chapter IV on notification of conformity-assessment bodies has applied since 11 June 2026, reporting duties apply from 11 September 2026, and the Regulation generally applies from 11 December 2027. PSTI Part 1 and the 2023 Regulations have applied since 29 April 2024.

Section 2

What work can be shared?

A shared product-security system can support both regimes: product and software inventories, threat and risk assessments, secure-development records, password tests, vulnerability intake, coordinated disclosure, update engineering, support-period decisions, release records, supplier controls, and corrective-action logs. The CRA normally needs more lifecycle evidence because manufacturers must perform a cybersecurity risk assessment, meet the essential requirements in Annex I, prepare technical documentation and an EU declaration of conformity, follow the applicable conformity-assessment route, and affix CE marking.

Keep legal outputs separate. A UK statement of compliance is not an EU declaration of conformity. An ETSI assessment used for UK technical evidence is not automatically a CRA presumption of conformity. Under the CRA, that presumption depends on applicable harmonised standards, common specifications, or a European cybersecurity certification scheme within the conditions set by the Regulation.

The CRA classification decision changes the assessment route. Products outside Annexes III and IV can normally use internal control. Important class I products may use internal control only when the manufacturer fully applies applicable harmonised standards, common specifications, or a qualifying certification scheme; otherwise a third-party route is required. Important class II and critical products use the stricter routes in Article 32. Record the exact Annex category and current implementing or delegated measures rather than using a general risk label.

Does PSTI compliance mean the product complies with the CRA?

No. PSTI and the CRA have different scope tests, legal outputs, lifecycle duties, and enforcement systems. PSTI evidence may support CRA work, especially for passwords, vulnerability disclosure, and support periods, but the CRA assessment must also cover its Annex I essential requirements, cybersecurity risk assessment, technical documentation, conformity route, EU declaration of conformity, CE marking, and applicable reporting duties.

Can one manufacturer support period be used for both regimes?

The same operational period may be used only if it satisfies both legal tests. PSTI requires publication of the minimum period for which security updates will be provided. Under CRA Article 13, the manufacturer must determine a support period that reflects the time the product is expected to be in use, considering specified factors; it is generally at least five years unless the product is expected to be used for less than five years. Record the reasoning and present the period as each regime requires.

  • Create one product boundary that lists the device, embedded software, companion applications, cloud functions, and remote processing, then record how each regime treats them.
  • Keep a requirement-to-evidence matrix with separate UK and EU citations. Link the same test report to both only where it tests the same control and product version.
  • Record the CRA product class and conformity route. Most products may use internal control, while important or critical products can require another route depending on their class, applicable standards, and Article 32.
  • Keep the UK statement of compliance, EU technical documentation, EU declaration of conformity, CE-marking record, and reporting records as controlled but distinct documents.
  • Reassess both regimes when intended use, consumer positioning, connectivity, remote processing, software components, legal entities, market route, support period, or a post-market modification changes.
Primary sources

References and citations

Related guides

Explore more topics

UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a UK PSTI statement is required, the Schedule 4 fields, supply-chain checks, retention, digital accompaniment, and the December 2025 label route.
UK PSTI Act: vulnerability disclosure policy requirements and template
Publish a free, clear, accessible English reporting route plus expected acknowledgement and status-update times, and retain evidence that the information remained available.
UK PSTI applicability test: product, market, and actor scope
Apply the UK PSTI tests in order: connectivity, current exceptions, UK consumer availability, supply facts, and the manufacturer, importer, or distributor trigger.
UK PSTI compliance checklist for product release
Use a release checklist with scope, role, security-control, statement, records, and compliance-failure evidence for UK consumer connectable products.
UK PSTI compliance: duties, evidence, and response
Build a UK PSTI compliance process covering product scope, supply-chain roles, the three security requirements, statements, records, and post-market failures.
UK PSTI default password requirements
Apply the UK PSTI password rule to each relevant password, test unique-per-product generation, and keep reset and release evidence for the shipped model.
UK PSTI Default Password Rules
PSTI requires each covered password to be user-defined or unique per product. Unique credentials must not use prohibited predictable generation methods.
UK PSTI ETSI Evidence and Deemed Compliance
ETSI EN 303 645 and TS 103 701 can structure technical evidence, but the standards-based PSTI route depends on the exact mapped provisions and additional Schedule 2 conditions.
UK PSTI Excepted Products and Boundaries
An internet- or network-connectable product is outside the relevant-product definition only when a current Schedule 3 exception applies; record the exact category and facts rather than relying on a broad sector label.
UK PSTI Importer and Distributor Duties
Importers and distributors have their own statement, stop-supply, remediation, and notification duties; importers also have statutory investigation and 10-year investigation-record duties.
UK PSTI Manufacturer, Importer and Distributor Roles
Distinguish manufacturer, importer, distributor, and authorised-representative duties per product and supply route, including rebranding, imports, statement checks, stop-supply decisions, and compliance failures.
UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties
OPSS can use compliance, stop, and recall notices alongside monetary and other measures; notice recipients should preserve the notice, product scope, supply records, corrective actions, representations, and appeal dates.
UK PSTI password and security update policy requirements
Implement the UK PSTI password rule and publish a defined security support period with the required end date, access conditions, and change controls.
UK PSTI Product Security Deadlines and Compliance Calendar Guide
Track the UK PSTI regime's commencement and amendment dates, product-specific support periods, record retention, and OPSS response and appeal windows.
UK PSTI Product Security FAQ
Get direct, sourced answers on product scope, exceptions, roles, passwords, vulnerability reporting, update-period information, statements, records, and OPSS enforcement.
UK PSTI Product Security Importer and Distributor Duties Guide
Identify the pre-supply checks, statement or deemed-compliance evidence, stop-supply decisions, notification and remediation duties required of UK importers and distributors, plus importer-specific investigation and record duties.
UK PSTI Product Security Minimum Support Period and Update Transparency Guide
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in clear language, without implying that PSTI sets one duration for every product.
UK PSTI Product Security OPSS Enforcement and Penalties Guide
Understand OPSS investigations, compliance, stop and recall notices, monetary penalties, forfeiture, court orders, representations, appeals, and evidence needed to respond.
UK PSTI Product Security OPSS Notices Guide
Prepare for compliance, stop, and recall notices by understanding their effects, representation and appeal routes, product records, and corrective-action evidence.
UK PSTI Product Security Penalties and Fines Guide
Understand the maximum fixed and daily PSTI penalties, how OPSS sets an amount, representation and appeal rights, and separate court-ordered sanctions.
UK PSTI product security requirements
Read the three Schedule 1 security requirements and the surrounding manufacturer, importer, distributor, statement, record, and failure-response duties.
UK PSTI Relevant Connectable Product Scope
A product is relevant when it is internet-connectable or network-connectable and not excepted, then the UK consumer-use and supply facts determine whether the Part 1 duties engage.
UK PSTI relevant connectable product scope test
Decide whether one product meets the UK PSTI connectivity definition, falls within a current exception, and reaches the separate UK-consumer duty tests.
UK PSTI relevant connectable products: categories and exceptions
Understand which connected product categories can enter UK PSTI scope, how the statutory tests work, and why examples never replace the current exception schedule.
UK PSTI Scope Classifier Workflow
Decide whether a product falls within the UK PSTI product-security regime by checking connectivity, consumer supply, exceptions, actor roles, and product-specific evidence.
UK PSTI security requirements in practice
Implement the three UK PSTI security requirements through product specifications, release tests, public information, approvals, and post-release evidence.
UK PSTI Security Update Support Periods
PSTI does not prescribe a universal minimum number of support years. The manufacturer sets and publishes a product-specific minimum period and end date; preserve the published commitment and assess any later change against the current Regulations.
UK PSTI Security Update Transparency
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in language understandable without technical knowledge.
UK PSTI Statement of Compliance Evidence Pack
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
UK PSTI Statement of Compliance Template
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
UK PSTI Statement of Compliance Workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
UK PSTI Statement of Compliance: Contents, Delivery, and Records
A statement must contain the prescribed information and accompany the product unless a current deemed-compliance route applies; a digital method is possible, but each business must ensure that it meets the Act.
UK PSTI Support Period Evidence Workflow
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
UK PSTI to ETSI Evidence Mapping
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
UK PSTI vs Australia Smart Device Rules
Compare UK PSTI with Australia's Cyber Security Act smart-device rules by scope, duties, statements, security controls, retention, dates, and enforcement.
UK PSTI vs ETSI EN 303 645
See how binding UK PSTI duties relate to ETSI EN 303 645, which edition the UK Regulations name, what the standard adds, and what evidence to retain.
UK PSTI vs EU Cyber Resilience Act
Decide whether UK PSTI, the EU Cyber Resilience Act, or both apply, then compare actors, exclusions, security work, documents, reporting, and dates.
UK PSTI Vulnerability Disclosure Requirements
Publish a clear reporting route plus expected acknowledgement and status-update times. PSTI requires the information and timescales to be available; it does not prescribe one universal response deadline for every report.
UK PSTI Vulnerability Disclosure Workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.