A product sold in both the UK and EU may need two assessments. PSTI sets a focused UK baseline for consumer connectable products; the CRA covers a broader range of hardware and software and adds lifecycle, conformity-assessment, CE-marking, documentation, and incident-reporting duties.
Meeting PSTI does not establish CRA conformity. Reuse technical evidence only after mapping it to each regime's product scope, actor, requirement, timing, and document.
Use this comparison to decide whether the UK's Product Security and Telecommunications Infrastructure (PSTI) Act 2022, the EU Cyber Resilience Act (CRA), or both apply to a product. The CRA calls its regulated hardware and software category . Start with separate scope findings. Then assign the manufacturer, importer, and distributor duties, map shared security evidence, and keep each regime's declaration, reporting, retention, and market-surveillance records distinct.
Side-by-side comparison
PSTI vs CRA: the operational crosswalk
Use each row as a separate decision. A shared control does not remove either regime's scope, documentation, or reporting test.
Relevant internet-connectable or network-connectable products made available to UK consumers. The Act and Regulations include statutory exceptions and actor-specific knowledge or intention tests.
whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Hardware, software, and qualifying remote data processing can be covered.
Three specified areas: passwords, a published route for reporting security issues, and publication of the minimum security-update period. The detailed conditions sit in Schedule 1 of the 2023 Regulations.
Use CRA work to widen the engineering baseline, but verify the exact PSTI wording rather than treating a broad CRA control as proof of the narrower UK rule.
A statement of compliance must accompany the product, subject to the Act and any deemed-compliance route. Manufacturers and importers retain it for the longer of 10 years from issue or the stated support period.
Manufacturers prepare technical documentation and an EU declaration of conformity, complete the applicable conformity assessment, and affix CE marking. Technical documentation and the declaration are generally kept for 10 years after market placement or for the support period, whichever is longer.
The manufacturer publishes at least one contact route for security reports and information about response times. PSTI does not create the CRA's EU-level early-warning and notification sequence.
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security through the CRA process and within the staged deadlines in .
Manufacturers, importers, distributors, and authorised representatives have distinct UK duties for security requirements, statements, supply checks, compliance failures, notifications, and records.
Manufacturers, importers, distributors, authorised representatives, persons making a substantial modification, and open-source software stewards have role-specific CRA duties. A modifier can assume manufacturer obligations.
Map each legal entity and market role for the actual supply and modification chain; a shared group security team does not replace role-specific accountability.
PSTI does not divide products into CRA-style default, important, or critical classes. The UK decision is whether the product, actor, and consumer-market facts trigger the specified duties or an exception.
Annexes III and IV identify important class I, important class II, and critical products. Article 32 links the category and use of applicable standards or certification to internal-control or third-party assessment routes.
A known or reasonably discoverable compliance failure triggers actor-specific investigation, reasonable steps, notification, and record duties. Changes to credentials, reporting routes, support information, or supply facts can require a new assessment.
Manufacturers handle vulnerabilities through the support period, take corrective action for non-conformity, and apply reporting from 11 September 2026. A substantial modification can make the modifier responsible as a manufacturer.
Join release, vulnerability, incident, corrective-action, and modification records to both legal decision trees and reopen the relevant approval when a trigger occurs.
The CRA entered into force on 10 December 2024. Conformity-body provisions apply from 11 June 2026, reporting duties from 11 September 2026, and most provisions from 11 December 2027.
Relevant internet-connectable or network-connectable products made available to UK consumers. The Act and Regulations include statutory exceptions and actor-specific knowledge or intention tests.
whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Hardware, software, and qualifying remote data processing can be covered.
Three specified areas: passwords, a published route for reporting security issues, and publication of the minimum security-update period. The detailed conditions sit in Schedule 1 of the 2023 Regulations.
Use CRA work to widen the engineering baseline, but verify the exact PSTI wording rather than treating a broad CRA control as proof of the narrower UK rule.
A statement of compliance must accompany the product, subject to the Act and any deemed-compliance route. Manufacturers and importers retain it for the longer of 10 years from issue or the stated support period.
Manufacturers prepare technical documentation and an EU declaration of conformity, complete the applicable conformity assessment, and affix CE marking. Technical documentation and the declaration are generally kept for 10 years after market placement or for the support period, whichever is longer.
The manufacturer publishes at least one contact route for security reports and information about response times. PSTI does not create the CRA's EU-level early-warning and notification sequence.
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security through the CRA process and within the staged deadlines in .
Manufacturers, importers, distributors, and authorised representatives have distinct UK duties for security requirements, statements, supply checks, compliance failures, notifications, and records.
Manufacturers, importers, distributors, authorised representatives, persons making a substantial modification, and open-source software stewards have role-specific CRA duties. A modifier can assume manufacturer obligations.
Map each legal entity and market role for the actual supply and modification chain; a shared group security team does not replace role-specific accountability.
Comparison row 6
Classification and assessment
UK PSTI
PSTI does not divide products into CRA-style default, important, or critical classes. The UK decision is whether the product, actor, and consumer-market facts trigger the specified duties or an exception.
Annexes III and IV identify important class I, important class II, and critical products. Article 32 links the category and use of applicable standards or certification to internal-control or third-party assessment routes.
Keep the UK scope result and the CRA class and conformity-route result as separate approvals tied to the same product version.
Comparison row 7
Post-market triggers
UK PSTI
A known or reasonably discoverable compliance failure triggers actor-specific investigation, reasonable steps, notification, and record duties. Changes to credentials, reporting routes, support information, or supply facts can require a new assessment.
Manufacturers handle vulnerabilities through the support period, take corrective action for non-conformity, and apply reporting from 11 September 2026. A substantial modification can make the modifier responsible as a manufacturer.
Join release, vulnerability, incident, corrective-action, and modification records to both legal decision trees and reopen the relevant approval when a trigger occurs.
Comparison row 8
Application dates
UK PSTI
PSTI Part 1 and the 2023 Regulations have applied since 29 April 2024.
The CRA entered into force on 10 December 2024. Conformity-body provisions apply from 11 June 2026, reporting duties from 11 September 2026, and most provisions from 11 December 2027.
For a product already supplied to UK consumers, close any PSTI gap now because the regime is already in force.
For any EU product with digital elements, classify the product, confirm exclusions, select the conformity route, and build Annex I evidence before the 2027 general application date.
Before 11 September 2026, establish CRA detection, legal triage, reporting clocks, submission ownership, and user-notification procedures.
When both regimes apply, use one engineering control library and two legal compliance maps.
PSTI applies to relevant connectable products made available to UK consumers, subject to statutory exceptions. Its current security requirements address passwords, reporting security issues, and publication of the minimum security-update period. The product must also be accompanied by a statement of compliance unless a statutory deemed-compliance route applies.
The CRA is Regulation (EU) 2024/2847. It generally applies to made available on the EU market where their intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. It covers hardware and software, including remote data-processing solutions on which the product depends, but contains exclusions and special rules for areas such as certain medical, automotive, aviation, marine, defence, and free and open-source software.
A connected home camera can be a representative product within both regimes. Standalone commercial software can fall within the CRA even when it is not a UK consumer connectable product. Free and open-source software supplied outside a commercial activity falls outside the CRA's main product duties, while open-source software stewards have a separate role. A sectoral exclusion must be matched to its exact conditions; regulation under another law is not a general exemption.
The CRA entered into force on 10 December 2024. Chapter IV on notification of conformity-assessment bodies has applied since 11 June 2026, reporting duties apply from 11 September 2026, and the Regulation generally applies from 11 December 2027. PSTI Part 1 and the 2023 Regulations have applied since 29 April 2024.
A shared product-security system can support both regimes: product and software inventories, threat and risk assessments, secure-development records, password tests, vulnerability intake, coordinated disclosure, update engineering, support-period decisions, release records, supplier controls, and corrective-action logs. The CRA normally needs more lifecycle evidence because manufacturers must perform a cybersecurity risk assessment, meet the essential requirements in Annex I, prepare technical documentation and an EU declaration of conformity, follow the applicable conformity-assessment route, and affix CE marking.
Keep legal outputs separate. A UK statement of compliance is not an EU declaration of conformity. An ETSI assessment used for UK technical evidence is not automatically a CRA presumption of conformity. Under the CRA, that presumption depends on applicable harmonised standards, common specifications, or a European cybersecurity certification scheme within the conditions set by the Regulation.
The CRA classification decision changes the assessment route. Products outside Annexes III and IV can normally use internal control. Important class I products may use internal control only when the manufacturer fully applies applicable harmonised standards, common specifications, or a qualifying certification scheme; otherwise a third-party route is required. Important class II and critical products use the stricter routes in Article 32. Record the exact Annex category and current implementing or delegated measures rather than using a general risk label.
Does PSTI compliance mean the product complies with the CRA?
No. PSTI and the CRA have different scope tests, legal outputs, lifecycle duties, and enforcement systems. PSTI evidence may support CRA work, especially for passwords, vulnerability disclosure, and support periods, but the CRA assessment must also cover its Annex I essential requirements, cybersecurity risk assessment, technical documentation, conformity route, EU declaration of conformity, CE marking, and applicable reporting duties.
Can one manufacturer support period be used for both regimes?
The same operational period may be used only if it satisfies both legal tests. PSTI requires publication of the minimum period for which security updates will be provided. Under CRA Article 13, the manufacturer must determine a support period that reflects the time the product is expected to be in use, considering specified factors; it is generally at least five years unless the product is expected to be used for less than five years. Record the reasoning and present the period as each regime requires.
Create one product boundary that lists the device, embedded software, companion applications, cloud functions, and remote processing, then record how each regime treats them.
Keep a requirement-to-evidence matrix with separate UK and EU citations. Link the same test report to both only where it tests the same control and product version.
Record the CRA product class and conformity route. Most products may use internal control, while important or critical products can require another route depending on their class, applicable standards, and Article 32.
Keep the UK statement of compliance, EU technical documentation, EU declaration of conformity, CE-marking record, and reporting records as controlled but distinct documents.
Reassess both regimes when intended use, consumer positioning, connectivity, remote processing, software components, legal entities, market route, support period, or a post-market modification changes.