Artifact GuideUKPSTI vs ETSI EN 303 645

UK PSTI vs ETSI EN 303 645

PSTI is binding UK law. ETSI EN 303 645 is a consumer-IoT security standard with a much broader control set. The UK Regulations use selected provisions of the 2020 edition in their deemed-compliance framework; a general ETSI claim does not replace the statutory assessment.

Use the standard to design and test the security baseline, then map the exact evidence to each PSTI requirement, statement, actor duty, and product version.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this comparison to separate the legal minimum under the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 from the broader technical baseline. First decide whether the product and actor fall within PSTI. Then test the three statutory security requirements and statement duties. Claim only where the exact Regulations permit it, and use the remaining provisions to manage security risks that PSTI's three requirements do not expressly cover.

Side-by-side comparison

PSTI law vs ETSI technical standard

The frameworks overlap in three security areas but have different jobs and different evidence claims.

Review all sources
First framework
UK PSTI

Binding duties for in-scope products and economic actors in the UK consumer market.

Second framework
ETSI EN 303 645

A broader technical baseline for consumer IoT security and data protection.

Comparison row 1

Legal force

UK PSTI

The Act and Regulations are binding. OPSS can investigate and use statutory enforcement powers.

ETSI EN 303 645

The standard is voluntary unless a law, contract, procurement rule, certification scheme, or other obligation gives it effect. The UK Regulations use selected V2.1.1 provisions in specified deemed-compliance conditions.

Operational implication

Describe the result as a statutory conclusion or a standards-conformance conclusion, never as an unspecified 'compliance' result.

Comparison row 2

Scope

UK PSTI

Relevant connectable products made available to UK consumers, subject to definitions, exceptions, and actor-specific intention or awareness tests.

ETSI EN 303 645

Consumer IoT products connected to network infrastructure and their interactions with associated services. The standard's technical scope does not decide UK market scope.

Operational implication

Complete the PSTI legal scope test even when a product is assessed against ETSI.

Comparison row 3

Coverage

UK PSTI

Specified requirements for passwords, vulnerability-reporting information, and security-update support-period information, plus statements and supply-chain duties.

ETSI EN 303 645

Thirteen security areas and data-protection provisions spanning credentials, disclosure, updates, secure storage and communications, attack surface, integrity, privacy, resilience, telemetry, deletion, maintenance, and input validation.

Operational implication

Use ETSI to cover a wider attack surface; use PSTI to verify the exact legal minimum and market duties.

Comparison row 4

Edition control

UK PSTI

The amended 2023 Regulations define as V2.1.1 dated 19 June 2020.

ETSI EN 303 645

ETSI published V3.1.3 in September 2024. Provision numbering and content changed, so a current-edition assessment needs an explicit mapping to V2.1.1 for UK statutory reliance.

Operational implication

Put the edition on every plan, test report, supplier claim, assessment, and legal conclusion.

Comparison row 5

Evidence and output

UK PSTI

A cited scope record, requirement evidence, statement of compliance, accompaniment record, actor checks, and retention record support the UK file.

ETSI EN 303 645

An implementation conformance statement, applicability reasons, design records, test results, vulnerability and update records, and edition-specific assessment support the ETSI claim.

Operational implication

Join both sets through stable product and release identifiers rather than merging them into one unqualified certificate.

Comparison row 6

Assessment method

UK PSTI

The legal conclusion maps product facts and evidence to the Act, Schedule 1, the exact Schedule 2 or 2A route, and actor-specific duties. OPSS retains enforcement authority.

ETSI EN 303 645

ETSI TS 103 701 V1.1.1 can assess EN 303 645 V2.1.1 through implementation information, conceptual checks, functional testing, and provision-level verdicts. It is not itself a PSTI approval.

Operational implication

Keep the technical assessment and legal approval linked but distinct, with stable identifiers for the tested device, software, services, evidence, reviewer, and date.

Practical decision rule

What should the team do next?

  • Confirm PSTI product and actor scope before selecting a standards route.
  • Choose and record the ETSI edition used for engineering; map V3.1.3 back to V2.1.1 wherever the UK Regulations require it.
  • If relying on a recognised foreign label, verify the exact Schedule 2 or 2A condition and preserve evidence that the label covers the product and is current.
  • Test every applicable ETSI provision and preserve reasons for conditional or feature-dependent exclusions.
  • Complete the remaining UK statement or Schedule 2A, supply-chain, retention, post-market, and OPSS-response records.
Section 2

What does ETSI add beyond the PSTI minimum?

covers 13 consumer-IoT security areas plus data-protection provisions. Beyond passwords, vulnerability reporting, and updates, it addresses secure storage of sensitive security parameters, secure communications, minimising exposed attack surfaces, software integrity, personal-data security, resilience to outages, telemetry, deletion of user data, installation and maintenance, and input validation.

The standard uses mandatory, recommended, conditional, and feature-dependent provisions in its implementation conformance statement. A provision marked not applicable needs a product-specific reason. Passing the three areas reflected in PSTI does not show conformance with the full standard, and full-standard evidence does not remove the need to meet PSTI's scope, actor, statement or valid Schedule 2A alternative, retention, post-market, and enforcement rules.

ETSI TS 103 701 V1.1.1 supplies an assessment method for EN 303 645 V2.1.1. It uses implementation information, conceptual assessment, functional testing, and verdicts. A report is useful only when it identifies the device under test, firmware, companion applications, associated services, interfaces, claimed provisions, evidence, test method, deviations, and verdicts. The PSTI legal file must still map those results to the current Regulations.

Does an certificate prove PSTI compliance?

No general certificate automatically proves PSTI compliance. The Regulations provide specific deemed-compliance conditions and name V2.1.1. Check the exact Schedule 2 or 2A condition, provision or recognised label, product scope, assessment evidence, current status, and amended text. PSTI scope, economic-actor duties, any remaining statement requirement, retention, post-market duties, and enforcement obligations still require their own assessment.

Should a new product use V2.1.1 or V3.1.3?

Use V3.1.3 when it is the chosen current engineering baseline, but keep a separate trace to V2.1.1 wherever a UK statutory deemed-compliance condition names that edition. Record both editions and the mapping between changed provisions. Do not silently substitute V3.1.3 in a legal conclusion based on the definition in the UK Regulations.

Is broader than PSTI?

Yes. PSTI's specified security requirements focus on passwords, vulnerability reporting, and the security-update support period. also covers areas such as secure storage, communications, attack surfaces, software integrity, data protection, resilience, telemetry, user-data deletion, installation, maintenance, and input validation. The broader standard does not replace PSTI's legal scope and supply-chain duties.

  • Freeze the product boundary: device hardware, firmware, preinstalled software, companion application, cloud service, communication interfaces, and update service.
  • Record the exact ETSI edition and every applicable provision in an implementation conformance statement.
  • Link design evidence and test results to the product version, configuration, interface, and provision assessed.
  • Maintain a separate PSTI legal matrix for scope, each Schedule 1 requirement, any Schedule 2 reliance, statement content, accompaniment, and retention.
  • For a recognised label route, retain the scheme, specification version, covered product, label identifier, issue and expiry dates, public verification record, and evidence that the label remains current at the legal decision point.
  • Review both maps when credentials, interfaces, associated services, update delivery, support periods, vulnerability processes, label status, standard editions, or the product's consumer-market facts change.
Primary sources

References and citations

etsi.org
Referenced sections
  • Defines the assessment approach and evidence and verdict structure for EN 303 645 V2.1.1.
Related guides

Explore more topics

UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a UK PSTI statement is required, the Schedule 4 fields, supply-chain checks, retention, digital accompaniment, and the December 2025 label route.
UK PSTI Act: vulnerability disclosure policy requirements and template
Publish a free, clear, accessible English reporting route plus expected acknowledgement and status-update times, and retain evidence that the information remained available.
UK PSTI applicability test: product, market, and actor scope
Apply the UK PSTI tests in order: connectivity, current exceptions, UK consumer availability, supply facts, and the manufacturer, importer, or distributor trigger.
UK PSTI compliance checklist for product release
Use a release checklist with scope, role, security-control, statement, records, and compliance-failure evidence for UK consumer connectable products.
UK PSTI compliance: duties, evidence, and response
Build a UK PSTI compliance process covering product scope, supply-chain roles, the three security requirements, statements, records, and post-market failures.
UK PSTI default password requirements
Apply the UK PSTI password rule to each relevant password, test unique-per-product generation, and keep reset and release evidence for the shipped model.
UK PSTI Default Password Rules
PSTI requires each covered password to be user-defined or unique per product. Unique credentials must not use prohibited predictable generation methods.
UK PSTI ETSI Evidence and Deemed Compliance
ETSI EN 303 645 and TS 103 701 can structure technical evidence, but the standards-based PSTI route depends on the exact mapped provisions and additional Schedule 2 conditions.
UK PSTI Excepted Products and Boundaries
An internet- or network-connectable product is outside the relevant-product definition only when a current Schedule 3 exception applies; record the exact category and facts rather than relying on a broad sector label.
UK PSTI Importer and Distributor Duties
Importers and distributors have their own statement, stop-supply, remediation, and notification duties; importers also have statutory investigation and 10-year investigation-record duties.
UK PSTI Manufacturer, Importer and Distributor Roles
Distinguish manufacturer, importer, distributor, and authorised-representative duties per product and supply route, including rebranding, imports, statement checks, stop-supply decisions, and compliance failures.
UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties
OPSS can use compliance, stop, and recall notices alongside monetary and other measures; notice recipients should preserve the notice, product scope, supply records, corrective actions, representations, and appeal dates.
UK PSTI password and security update policy requirements
Implement the UK PSTI password rule and publish a defined security support period with the required end date, access conditions, and change controls.
UK PSTI Product Security Deadlines and Compliance Calendar Guide
Track the UK PSTI regime's commencement and amendment dates, product-specific support periods, record retention, and OPSS response and appeal windows.
UK PSTI Product Security FAQ
Get direct, sourced answers on product scope, exceptions, roles, passwords, vulnerability reporting, update-period information, statements, records, and OPSS enforcement.
UK PSTI Product Security Importer and Distributor Duties Guide
Identify the pre-supply checks, statement or deemed-compliance evidence, stop-supply decisions, notification and remediation duties required of UK importers and distributors, plus importer-specific investigation and record duties.
UK PSTI Product Security Minimum Support Period and Update Transparency Guide
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in clear language, without implying that PSTI sets one duration for every product.
UK PSTI Product Security OPSS Enforcement and Penalties Guide
Understand OPSS investigations, compliance, stop and recall notices, monetary penalties, forfeiture, court orders, representations, appeals, and evidence needed to respond.
UK PSTI Product Security OPSS Notices Guide
Prepare for compliance, stop, and recall notices by understanding their effects, representation and appeal routes, product records, and corrective-action evidence.
UK PSTI Product Security Penalties and Fines Guide
Understand the maximum fixed and daily PSTI penalties, how OPSS sets an amount, representation and appeal rights, and separate court-ordered sanctions.
UK PSTI product security requirements
Read the three Schedule 1 security requirements and the surrounding manufacturer, importer, distributor, statement, record, and failure-response duties.
UK PSTI Relevant Connectable Product Scope
A product is relevant when it is internet-connectable or network-connectable and not excepted, then the UK consumer-use and supply facts determine whether the Part 1 duties engage.
UK PSTI relevant connectable product scope test
Decide whether one product meets the UK PSTI connectivity definition, falls within a current exception, and reaches the separate UK-consumer duty tests.
UK PSTI relevant connectable products: categories and exceptions
Understand which connected product categories can enter UK PSTI scope, how the statutory tests work, and why examples never replace the current exception schedule.
UK PSTI Scope Classifier Workflow
Decide whether a product falls within the UK PSTI product-security regime by checking connectivity, consumer supply, exceptions, actor roles, and product-specific evidence.
UK PSTI security requirements in practice
Implement the three UK PSTI security requirements through product specifications, release tests, public information, approvals, and post-release evidence.
UK PSTI Security Update Support Periods
PSTI does not prescribe a universal minimum number of support years. The manufacturer sets and publishes a product-specific minimum period and end date; preserve the published commitment and assess any later change against the current Regulations.
UK PSTI Security Update Transparency
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in language understandable without technical knowledge.
UK PSTI Statement of Compliance Evidence Pack
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
UK PSTI Statement of Compliance Template
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
UK PSTI Statement of Compliance Workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
UK PSTI Statement of Compliance: Contents, Delivery, and Records
A statement must contain the prescribed information and accompany the product unless a current deemed-compliance route applies; a digital method is possible, but each business must ensure that it meets the Act.
UK PSTI Support Period Evidence Workflow
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
UK PSTI to ETSI Evidence Mapping
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
UK PSTI vs Australia Smart Device Rules
Compare UK PSTI with Australia's Cyber Security Act smart-device rules by scope, duties, statements, security controls, retention, dates, and enforcement.
UK PSTI vs EU Cyber Resilience Act
Decide whether UK PSTI, the EU Cyber Resilience Act, or both apply, then compare actors, exclusions, security work, documents, reporting, and dates.
UK PSTI vs EU Cyber Resilience Act (CRA)
Compare UK PSTI and the EU Cyber Resilience Act by scope, security duties, support periods, conformity assessment, reporting, evidence, and application dates.
UK PSTI Vulnerability Disclosure Requirements
Publish a clear reporting route plus expected acknowledgement and status-update times. PSTI requires the information and timescales to be available; it does not prescribe one universal response deadline for every report.
UK PSTI Vulnerability Disclosure Workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.