PSTI is binding UK law. ETSI EN 303 645 is a consumer-IoT security standard with a much broader control set. The UK Regulations use selected provisions of the 2020 edition in their deemed-compliance framework; a general ETSI claim does not replace the statutory assessment.
Use the standard to design and test the security baseline, then map the exact evidence to each PSTI requirement, statement, actor duty, and product version.
Use this comparison to separate the legal minimum under the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 from the broader technical baseline. First decide whether the product and actor fall within PSTI. Then test the three statutory security requirements and statement duties. Claim only where the exact Regulations permit it, and use the remaining provisions to manage security risks that PSTI's three requirements do not expressly cover.
Side-by-side comparison
PSTI law vs ETSI technical standard
The frameworks overlap in three security areas but have different jobs and different evidence claims.
The standard is voluntary unless a law, contract, procurement rule, certification scheme, or other obligation gives it effect. The UK Regulations use selected V2.1.1 provisions in specified deemed-compliance conditions.
Consumer IoT products connected to network infrastructure and their interactions with associated services. The standard's technical scope does not decide UK market scope.
Specified requirements for passwords, vulnerability-reporting information, and security-update support-period information, plus statements and supply-chain duties.
ETSI published V3.1.3 in September 2024. Provision numbering and content changed, so a current-edition assessment needs an explicit mapping to V2.1.1 for UK statutory reliance.
An implementation conformance statement, applicability reasons, design records, test results, vulnerability and update records, and edition-specific assessment support the ETSI claim.
The legal conclusion maps product facts and evidence to the Act, Schedule 1, the exact Schedule 2 or 2A route, and actor-specific duties. OPSS retains enforcement authority.
ETSI TS 103 701 V1.1.1 can assess EN 303 645 V2.1.1 through implementation information, conceptual checks, functional testing, and provision-level verdicts. It is not itself a PSTI approval.
Keep the technical assessment and legal approval linked but distinct, with stable identifiers for the tested device, software, services, evidence, reviewer, and date.
Comparison row 1
Legal force
UK PSTI
The Act and Regulations are binding. OPSS can investigate and use statutory enforcement powers.
The standard is voluntary unless a law, contract, procurement rule, certification scheme, or other obligation gives it effect. The UK Regulations use selected V2.1.1 provisions in specified deemed-compliance conditions.
Consumer IoT products connected to network infrastructure and their interactions with associated services. The standard's technical scope does not decide UK market scope.
Specified requirements for passwords, vulnerability-reporting information, and security-update support-period information, plus statements and supply-chain duties.
ETSI published V3.1.3 in September 2024. Provision numbering and content changed, so a current-edition assessment needs an explicit mapping to V2.1.1 for UK statutory reliance.
An implementation conformance statement, applicability reasons, design records, test results, vulnerability and update records, and edition-specific assessment support the ETSI claim.
The legal conclusion maps product facts and evidence to the Act, Schedule 1, the exact Schedule 2 or 2A route, and actor-specific duties. OPSS retains enforcement authority.
ETSI TS 103 701 V1.1.1 can assess EN 303 645 V2.1.1 through implementation information, conceptual checks, functional testing, and provision-level verdicts. It is not itself a PSTI approval.
Keep the technical assessment and legal approval linked but distinct, with stable identifiers for the tested device, software, services, evidence, reviewer, and date.
Practical decision rule
What should the team do next?
Confirm PSTI product and actor scope before selecting a standards route.
Choose and record the ETSI edition used for engineering; map V3.1.3 back to V2.1.1 wherever the UK Regulations require it.
If relying on a recognised foreign label, verify the exact Schedule 2 or 2A condition and preserve evidence that the label covers the product and is current.
Test every applicable ETSI provision and preserve reasons for conditional or feature-dependent exclusions.
Complete the remaining UK statement or Schedule 2A, supply-chain, retention, post-market, and OPSS-response records.
The Product Security and Telecommunications Infrastructure Act 2022 and the 2023 Security Requirements Regulations are law. They apply to relevant connectable products made available to UK consumers, subject to the statutory scope tests and exceptions. The Regulations specify requirements for passwords, reporting security issues, and publication of the minimum period for security updates. They also govern statements of compliance and record retention.
is a European Standard for consumer Internet of Things products. It is not, by itself, a UK legal obligation for every product. The 2023 Regulations define 'ETSI EN 303 645' as V2.1.1 dated 19 June 2020 and use named provisions from that edition in Schedule 2 conditions for with specified security requirements. The current ETSI publication V3.1.3 dated September 2024 is useful engineering guidance, but an assessment against V3.1.3 should not be assumed to satisfy a statutory route that names V2.1.1 without checking the amended Regulations.
The original ETSI mappings are precise. Schedule 2 links the password requirement to provisions 5.1-1 and, where relevant, 5.1-2; vulnerability reporting to 5.2-1; and support-period information to 5.3-13, with additional statutory conditions. ISO/IEC 29147:2018 provides an alternative route for specified vulnerability-disclosure conditions. From 4 December 2025, amended Schedules 2 and 2A also recognise specified current labels under Japan JC-STAR STAR-1 and the Singapore Cybersecurity Labelling Scheme for listed security and statement-accompaniment conditions.
State the exact legal basis: identify the PSTI requirement, the Schedule 2 or 2A condition, the named standard edition, provision or label, the product and software assessed, the label's current status where relevant, and the supporting evidence. Do not write only 'ETSI compliant' or 'PSTI certified.' PSTI does not create a general product-certification scheme.
covers 13 consumer-IoT security areas plus data-protection provisions. Beyond passwords, vulnerability reporting, and updates, it addresses secure storage of sensitive security parameters, secure communications, minimising exposed attack surfaces, software integrity, personal-data security, resilience to outages, telemetry, deletion of user data, installation and maintenance, and input validation.
The standard uses mandatory, recommended, conditional, and feature-dependent provisions in its implementation conformance statement. A provision marked not applicable needs a product-specific reason. Passing the three areas reflected in PSTI does not show conformance with the full standard, and full-standard evidence does not remove the need to meet PSTI's scope, actor, statement or valid Schedule 2A alternative, retention, post-market, and enforcement rules.
ETSI TS 103 701 V1.1.1 supplies an assessment method for EN 303 645 V2.1.1. It uses implementation information, conceptual assessment, functional testing, and verdicts. A report is useful only when it identifies the device under test, firmware, companion applications, associated services, interfaces, claimed provisions, evidence, test method, deviations, and verdicts. The PSTI legal file must still map those results to the current Regulations.
Does an certificate prove PSTI compliance?
No general certificate automatically proves PSTI compliance. The Regulations provide specific deemed-compliance conditions and name V2.1.1. Check the exact Schedule 2 or 2A condition, provision or recognised label, product scope, assessment evidence, current status, and amended text. PSTI scope, economic-actor duties, any remaining statement requirement, retention, post-market duties, and enforcement obligations still require their own assessment.
Should a new product use V2.1.1 or V3.1.3?
Use V3.1.3 when it is the chosen current engineering baseline, but keep a separate trace to V2.1.1 wherever a UK statutory deemed-compliance condition names that edition. Record both editions and the mapping between changed provisions. Do not silently substitute V3.1.3 in a legal conclusion based on the definition in the UK Regulations.
Is broader than PSTI?
Yes. PSTI's specified security requirements focus on passwords, vulnerability reporting, and the security-update support period. also covers areas such as secure storage, communications, attack surfaces, software integrity, data protection, resilience, telemetry, user-data deletion, installation, maintenance, and input validation. The broader standard does not replace PSTI's legal scope and supply-chain duties.
Freeze the product boundary: device hardware, firmware, preinstalled software, companion application, cloud service, communication interfaces, and update service.
Record the exact ETSI edition and every applicable provision in an implementation conformance statement.
Link design evidence and test results to the product version, configuration, interface, and provision assessed.
Maintain a separate PSTI legal matrix for scope, each Schedule 1 requirement, any Schedule 2 reliance, statement content, accompaniment, and retention.
For a recognised label route, retain the scheme, specification version, covered product, label identifier, issue and expiry dates, public verification record, and evidence that the label remains current at the legal decision point.
Review both maps when credentials, interfaces, associated services, update delivery, support periods, vulnerability processes, label status, standard editions, or the product's consumer-market facts change.