Artifact GuideUK and EUPSTI vs EU CRA

UK PSTI vs EU Cyber Resilience Act

Run both scope tests for dual-market products. UK PSTI targets consumer connectable products and three specified security areas; the EU Cyber Resilience Act covers a wider set of connected hardware and software and adds lifecycle, conformity, CE-marking, and reporting duties.

One security program can support both regimes, but each market needs its own legal conclusion, product documents, dates, and regulator-facing record.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Start with the sales territory and complete product boundary. For the UK, apply the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 to test whether each item is a relevant connectable product made available to consumers and whether an exception applies. For the EU, test each hardware or software item, including qualifying , against Regulation (EU) 2024/2847 and its exclusions. If both apply, share engineering evidence but keep the legal approvals separate.

Side-by-side decision guide

UK PSTI vs EU Cyber Resilience Act

Use the rows to route the product, evidence, and approvals. Do not collapse the two legal tests into one result.

Review all sources
First framework
UK PSTI

A focused UK regime for consumer connectable products and their supply chain.

Second framework
EU Cyber Resilience Act

A broader EU regime for connected hardware and software across the product lifecycle.

Comparison row 1

Product boundary

UK PSTI

Assess the relevant connectable product, including the hardware and software that make it internet-connectable or network-connectable, against the UK definitions and exceptions.

EU Cyber Resilience Act

Assess the product with digital elements, including software or hardware and qualifying necessary for a function, against Article 2 and 3.

Operational implication

Draw one architecture boundary, then annotate how each regime treats every component and service.

Comparison row 2

Exclusions and special cases

UK PSTI

The Act and Regulations except specified products, including certain regulated products and, after the 2025 amendment, specified vehicle categories. The exact exception conditions must be checked.

EU Cyber Resilience Act

Article 2 excludes or limits specified medical, in vitro diagnostic, automotive, aviation, marine, defence, national-security, and other products. Free and open-source software supplied outside a commercial activity is outside the main scope, with separate steward rules.

Operational implication

Cite the exact exclusion and facts. Regulation in another sector does not create a general exemption.

Comparison row 3

Who must act

UK PSTI

Manufacturers, importers, and distributors have distinct duties; authorised representatives can perform specified functions.

EU Cyber Resilience Act

Manufacturers, importers, distributors, authorised representatives, open-source software stewards, and other specified actors have role-specific duties.

Operational implication

Assign duties to the legal entity performing each market role, not only to the engineering team.

Comparison row 4

Approval outputs

UK PSTI

A compliant product is accompanied by a UK statement of compliance, subject to any valid deemed-compliance route; the file also needs actor and retention records.

EU Cyber Resilience Act

The manufacturer prepares technical documentation and an EU declaration of conformity, completes the applicable assessment, and affixes CE marking.

Operational implication

Control both outputs against the same product identifier, but do not merge their approvals or legal wording.

Comparison row 5

Security and support

UK PSTI

Schedule 1 specifies password conditions, a published security-reporting route and response-time information, and publication of the minimum security-update period with an end date.

EU Cyber Resilience Act

Annex I sets risk-based product cybersecurity and vulnerability-handling requirements. Article 13 requires a reasoned support period, normally at least five years unless expected use is shorter.

Operational implication

Use one engineering plan, but map each control and support decision to the exact UK and EU text and keep the different publication and lifecycle evidence.

Comparison row 6

Reports and corrective action

UK PSTI

PSTI requires publication of a route for reporting security issues. A compliance failure also triggers actor-specific investigation, reasonable steps, notification, and record duties; it does not use the CRA Article 14 reporting sequence.

EU Cyber Resilience Act

From 11 September 2026, Article 14 requires staged reporting of actively exploited vulnerabilities and severe incidents affecting product security, with related user information and final-report duties where applicable.

Operational implication

Use shared detection and triage, then route the event through separate UK compliance-failure and CRA Article 14 decisions with their own clocks and submission evidence.

Comparison row 7

Enforcement and penalties

UK PSTI

OPSS can investigate, serve compliance, stop, and recall notices, impose monetary penalties, seek forfeiture, publish failures, and pursue specified offences.

EU Cyber Resilience Act

EU market-surveillance authorities can require corrective action, restrict or prohibit products, order withdrawal or recall, and impose national penalties within the CRA framework.

Operational implication

Keep market-specific supply, technical, reporting, corrective-action, notice, and regulator-communication records; one authority's outcome does not bind the other.

Comparison row 8

Dates

UK PSTI

PSTI Part 1 and the 2023 Regulations have applied since 29 April 2024.

EU Cyber Resilience Act

CRA conformity-body provisions apply from 11 June 2026, Article 14 reporting from 11 September 2026, and most provisions from 11 December 2027.

Operational implication

Close current UK gaps now and implement the CRA reporting workflow before finishing the wider 2027 conformity program.

Practical decision rule

What should be approved before release?

  • A separate cited scope and exclusion finding for the UK and EU.
  • A CRA class and conformity-route decision, where the CRA applies.
  • A shared technical evidence map tied to the exact product and software release.
  • Separate UK statement and EU technical-documentation, declaration, CE-marking, reporting, and retention records.
Section 1

Choose the applicable workstream

Use the PSTI workstream when a manufacturer, importer, or distributor makes a relevant connectable product available to UK consumers. The regime has applied since 29 April 2024. Confirm the password requirement, published security-issue reporting route, published minimum security-update period, statement of compliance, and actor-specific supply checks.

Use the EU Cyber Resilience Act workstream for a product with digital elements made available on the EU market when its intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. The CRA can cover standalone software, embedded software, hardware, and a remote data-processing solution on which a product depends for a function. Check Article 2 exclusions before classifying the product.

Run both workstreams when the same product is supplied in both markets. A connected home camera is a representative dual-market example. Standalone commercial software may be a CRA product even when it is not a UK consumer connectable product. The product may have a shared bill of materials, threat model, vulnerability process, update mechanism, test suite, and support plan, but it still needs jurisdiction-specific scope findings and outputs.

Record exclusions narrowly. PSTI Schedule 3 and the CRA Article 2 exclusions use different sector, product, and legal conditions. Free and open-source software supplied outside a commercial activity is outside the CRA's main product obligations, while open-source software stewards have separate duties. Neither framework creates a general exemption merely because another cybersecurity standard or sectoral rule applies.

Section 2

What changes when the CRA also applies?

The CRA requires the manufacturer to perform and document a cybersecurity risk assessment, design and produce the product in accordance with Annex I, handle vulnerabilities throughout the support period, prepare technical documentation, complete the applicable conformity assessment, issue an EU declaration of conformity, and affix CE marking. Importers and distributors have verification, identification, cooperation, and corrective-action duties.

Product classification affects the conformity route. The CRA distinguishes default products, important products in classes I and II, and critical products. Classification depends on Annexes III and IV and any delegated acts, not on a general impression that a product is high risk. Most products can use the internal-control route, while important and critical categories may need a harmonised-standard route, EU-type examination, full quality assurance, or another route specified by Article 32.

The CRA support period normally must be at least five years unless the product is expected to be used for less than five years. The manufacturer must base it on expected use, product and market characteristics, user expectations, component support, and other Article 13 factors. PSTI instead requires the manufacturer to publish the minimum period for which security updates will be provided, expressed with an end date. One operational period can serve both only when its reasoning and publication satisfy both rules.

Article 14 reporting starts before the general product obligations. From 11 September 2026, manufacturers must use the CRA process for actively exploited vulnerabilities and severe incidents affecting product security. Most other CRA provisions apply from 11 December 2027; Chapter IV on notification of conformity-assessment bodies has applied since 11 June 2026.

Does the CRA replace PSTI for products sold in the UK?

No. The CRA is an EU regulation and PSTI is UK law. A product sold in both markets may need both. EU conformity, an EU declaration, or CE marking does not remove UK PSTI scope, security, statement, and supply-chain duties.

Are products already on the EU market exempt from the CRA?

Not as a blanket rule. Article 69 contains transitional provisions for products placed on the market before 11 December 2027, but the CRA can apply when a product is substantially modified after that date. Article 14 reporting also applies from 11 September 2026 to products within its terms. Record market-placement and modification facts rather than relying only on a model launch date.

Does the CRA always require a notified body?

No. The conformity route depends on product classification, applicable harmonised standards or certification, and Article 32. Many products can use internal control. Important class II products and critical products face stricter routes, and some class I cases require a third-party route when the conditions for internal control are not met.

  • Assign one product owner to maintain the boundary across device, software, cloud dependency, interfaces, versions, and markets.
  • Record the Annex III or IV classification decision and the chosen Article 32 conformity-assessment route.
  • Build a CRA technical file around the Annex I risk assessment, design evidence, tests, vulnerability handling, update delivery, user information, and support-period reasoning.
  • Prepare CRA incident triage and reporting before 11 September 2026, including clocks, submission ownership, and user-notification decisions.
  • Keep the UK statement of compliance separate from the EU declaration of conformity and CE-marking file.
  • Reassess after a new intended use, connectivity path, remote-service dependency, software component, product class, legal entity, support-period decision, market route, or .
Primary sources

References and citations

Related guides

Explore more topics

UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a UK PSTI statement is required, the Schedule 4 fields, supply-chain checks, retention, digital accompaniment, and the December 2025 label route.
UK PSTI Act: vulnerability disclosure policy requirements and template
Publish a free, clear, accessible English reporting route plus expected acknowledgement and status-update times, and retain evidence that the information remained available.
UK PSTI applicability test: product, market, and actor scope
Apply the UK PSTI tests in order: connectivity, current exceptions, UK consumer availability, supply facts, and the manufacturer, importer, or distributor trigger.
UK PSTI compliance checklist for product release
Use a release checklist with scope, role, security-control, statement, records, and compliance-failure evidence for UK consumer connectable products.
UK PSTI compliance: duties, evidence, and response
Build a UK PSTI compliance process covering product scope, supply-chain roles, the three security requirements, statements, records, and post-market failures.
UK PSTI default password requirements
Apply the UK PSTI password rule to each relevant password, test unique-per-product generation, and keep reset and release evidence for the shipped model.
UK PSTI Default Password Rules
PSTI requires each covered password to be user-defined or unique per product. Unique credentials must not use prohibited predictable generation methods.
UK PSTI ETSI Evidence and Deemed Compliance
ETSI EN 303 645 and TS 103 701 can structure technical evidence, but the standards-based PSTI route depends on the exact mapped provisions and additional Schedule 2 conditions.
UK PSTI Excepted Products and Boundaries
An internet- or network-connectable product is outside the relevant-product definition only when a current Schedule 3 exception applies; record the exact category and facts rather than relying on a broad sector label.
UK PSTI Importer and Distributor Duties
Importers and distributors have their own statement, stop-supply, remediation, and notification duties; importers also have statutory investigation and 10-year investigation-record duties.
UK PSTI Manufacturer, Importer and Distributor Roles
Distinguish manufacturer, importer, distributor, and authorised-representative duties per product and supply route, including rebranding, imports, statement checks, stop-supply decisions, and compliance failures.
UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties
OPSS can use compliance, stop, and recall notices alongside monetary and other measures; notice recipients should preserve the notice, product scope, supply records, corrective actions, representations, and appeal dates.
UK PSTI password and security update policy requirements
Implement the UK PSTI password rule and publish a defined security support period with the required end date, access conditions, and change controls.
UK PSTI Product Security Deadlines and Compliance Calendar Guide
Track the UK PSTI regime's commencement and amendment dates, product-specific support periods, record retention, and OPSS response and appeal windows.
UK PSTI Product Security FAQ
Get direct, sourced answers on product scope, exceptions, roles, passwords, vulnerability reporting, update-period information, statements, records, and OPSS enforcement.
UK PSTI Product Security Importer and Distributor Duties Guide
Identify the pre-supply checks, statement or deemed-compliance evidence, stop-supply decisions, notification and remediation duties required of UK importers and distributors, plus importer-specific investigation and record duties.
UK PSTI Product Security Minimum Support Period and Update Transparency Guide
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in clear language, without implying that PSTI sets one duration for every product.
UK PSTI Product Security OPSS Enforcement and Penalties Guide
Understand OPSS investigations, compliance, stop and recall notices, monetary penalties, forfeiture, court orders, representations, appeals, and evidence needed to respond.
UK PSTI Product Security OPSS Notices Guide
Prepare for compliance, stop, and recall notices by understanding their effects, representation and appeal routes, product records, and corrective-action evidence.
UK PSTI Product Security Penalties and Fines Guide
Understand the maximum fixed and daily PSTI penalties, how OPSS sets an amount, representation and appeal rights, and separate court-ordered sanctions.
UK PSTI product security requirements
Read the three Schedule 1 security requirements and the surrounding manufacturer, importer, distributor, statement, record, and failure-response duties.
UK PSTI Relevant Connectable Product Scope
A product is relevant when it is internet-connectable or network-connectable and not excepted, then the UK consumer-use and supply facts determine whether the Part 1 duties engage.
UK PSTI relevant connectable product scope test
Decide whether one product meets the UK PSTI connectivity definition, falls within a current exception, and reaches the separate UK-consumer duty tests.
UK PSTI relevant connectable products: categories and exceptions
Understand which connected product categories can enter UK PSTI scope, how the statutory tests work, and why examples never replace the current exception schedule.
UK PSTI Scope Classifier Workflow
Decide whether a product falls within the UK PSTI product-security regime by checking connectivity, consumer supply, exceptions, actor roles, and product-specific evidence.
UK PSTI security requirements in practice
Implement the three UK PSTI security requirements through product specifications, release tests, public information, approvals, and post-release evidence.
UK PSTI Security Update Support Periods
PSTI does not prescribe a universal minimum number of support years. The manufacturer sets and publishes a product-specific minimum period and end date; preserve the published commitment and assess any later change against the current Regulations.
UK PSTI Security Update Transparency
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in language understandable without technical knowledge.
UK PSTI Statement of Compliance Evidence Pack
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
UK PSTI Statement of Compliance Template
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
UK PSTI Statement of Compliance Workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
UK PSTI Statement of Compliance: Contents, Delivery, and Records
A statement must contain the prescribed information and accompany the product unless a current deemed-compliance route applies; a digital method is possible, but each business must ensure that it meets the Act.
UK PSTI Support Period Evidence Workflow
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
UK PSTI to ETSI Evidence Mapping
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
UK PSTI vs Australia Smart Device Rules
Compare UK PSTI with Australia's Cyber Security Act smart-device rules by scope, duties, statements, security controls, retention, dates, and enforcement.
UK PSTI vs ETSI EN 303 645
See how binding UK PSTI duties relate to ETSI EN 303 645, which edition the UK Regulations name, what the standard adds, and what evidence to retain.
UK PSTI vs EU Cyber Resilience Act (CRA)
Compare UK PSTI and the EU Cyber Resilience Act by scope, security duties, support periods, conformity assessment, reporting, evidence, and application dates.
UK PSTI Vulnerability Disclosure Requirements
Publish a clear reporting route plus expected acknowledgement and status-update times. PSTI requires the information and timescales to be available; it does not prescribe one universal response deadline for every report.
UK PSTI Vulnerability Disclosure Workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.