Intermediate2h 21m

# UK Cyber Security and Resilience Bill (CSRB) for Connected Device Manufacturers

The complete UK cyber security compliance course for connected device manufacturers — the Product Security and Telecommunications Infrastructure Act's three security requirements, the Cyber Security and Resilience Bill's expanded supply chain and critical-supplier regime, and a full practical compliance program built for both.

A smart plug ships with an admin password of "admin1234" set at the factory, identical across every unit sold — and it's illegal, not just careless. A camera manufacturer publishes no way to report a security flaw, and discovers the flaw from a journalist instead of a researcher. A component supplier feeding sensors into an NHS diagnostics pipeline gets a letter informing them they've just been designated a critical supplier under a law they'd never heard of, with new obligations attached. None of this is exotic. It's the ordinary result of treating UK connected-device law as one rule instead of the two real, separately-enforced systems it actually is. This course teaches UK cyber security compliance for connected device manufacturers from first principles to complete practical compliance. It starts with the Product Security and Telecommunications Infrastructure Act 2022 and its Regulations — the direct product law every manufacturer, importer, and distributor of a consumer connectable product must meet: the ban on easily-guessable default passwords, the vulnerability disclosure policy every product needs, and the minimum security update period every product must publicly disclose. You'll learn exactly how to classify a product into scope, build the statement of compliance and technical documentation OPSS expects, and what OPSS's compliance notices, recall powers, and penalties actually mean in practice. The course then turns to the Cyber Security and Resilience Bill — the legislation modernising the UK's Network and Information Systems Regulations 2018, currently moving through Parliament toward Royal Assent. You'll understand exactly how it expands regulatory scope to data centres, large load controllers, and managed service providers, and — critically for hardware manufacturers — how its new "designated critical supplier" power can pull a device or component maker into a second, separate regulatory regime the moment their product feeds into a regulated essential or important entity. Incident reporting timelines, the two-tier turnover-based penalty structure, and the NCSC's Cyber Assessment Framework round out the regulatory core. A concise comparison to the EU's parallel regime — the NIS2 Directive, the Radio Equipment Directive's cybersecurity requirements, and the Cyber Resilience Act — helps any manufacturer selling into both markets keep the two systems straight. The closing modules deliver a complete, realistic walkthrough of a connected device manufacturer building its compliance program from scratch, the common mistakes and edge cases that trip up even careful teams, and your own thirty, sixty, ninety-day compliance action plan. Built on Krono's regulatory database and current 2026 guidance, covering the Product Security and Telecommunications Infrastructure Act 2022 and the Product Security and Telecommunications Infrastructure (Security Requirements) Regulations 2023, and the Cyber Security and Resilience Bill as it stood in Parliament at the time of this course's production. This course contains the use of artificial intelligence for asthetic purposes.

*   Includes the ebook edition, free
*   8 downloadable resources included

## What you'll learn

*   Build the statement of compliance and technical documentation file OPSS actually expects to see
*   Understand the Cyber Security and Resilience Bill's expanded scope and the designated critical supplier power
*   Meet CSRB incident reporting timelines and understand the two-tier turnover-based penalty structure
*   Compare the UK regime to the EU's NIS2, RED cybersecurity requirements, and Cyber Resilience Act
*   Build a real, ongoing compliance program instead of treating registration as a one-time checkbox

## Requirements

*   ·No prior cyber security, legal, or engineering background required — the course builds every concept from first principles
*   ·A working knowledge of your own product's connectivity and update mechanism is helpful but not required
*   ·Manufacturers, importers, distributors, compliance teams, and hardware startups selling into the UK will all benefit

$199.00

One-time purchase · Lifetime access · No subscription

Less than one hour with a compliance consultant.

[First lesson free to preview: UK Cyber Security and Resilience Bill](#lesson-86dfab97-869e-4d03-a3a0-c42090fb0727)

*   Map the UK's cyber security regulatory landscape and know exactly which law — PSTI, CSRB, or both — applies to your product
*   Classify any connected product into or out of PSTI Act scope, and correctly apply its exemptions
*   Implement all three PSTI security requirements — password, vulnerability disclosure, and update-period rules — correctly

Includes the ebook edition, free — read it in your [library](/profile/books) after purchase.

Enroll — $199.00

Secure checkout via Paddle

Not what you expected? Contact us within 14 days.

Built from a regulatory graph already at work

1,506

users this week

661

guides

323

product types

9

markets

## Course content

218 lessons·1707 min total

UK Connected Device Cyber Law: The Big Picture

12 lessons · 101 min

*   UK Cyber Security and Resilience Bill
    
    Preview8:24
    
*   Two Laws, Not One
    
    8:24
    
*   Three Ordinary Failures
    
    8:24
    
*   Who This Course Is Built For
    
    8:24
    
*   The Agency Map
    
    8:24
    
*   Five Real Products, Five Real Trip-Ups
    
    8:24
    
*   How This Course Is Structured
    
    8:24
    
*   Where Does Your Product Stand Today?
    
    8:24
    
*   The Cost of Getting It Wrong
    
    8:24
    
*   What Good Looks Like
    
    8:24
    
*   A Note on Real Diligence
    
    8:24
    
*   Knowledge Check — The Big Picture
    
    8:24
    

The UK Regulatory Framework

12 lessons · 109 min

PSTI Act 2022: Scope & Product Classification

13 lessons · 122 min

Security Requirement 1: No Default Passwords

11 lessons · 82 min

Security Requirement 2: Vulnerability Disclosure

12 lessons · 97 min

Security Requirement 3: Minimum Security Update Period

12 lessons · 94 min

Statement of Compliance & Technical Documentation

12 lessons · 89 min

PSTI Enforcement: OPSS Powers & Penalties

11 lessons · 78 min

The Cyber Security and Resilience Bill: Scope & Structure

13 lessons · 114 min

CSRB's Newly Regulated Entities

12 lessons · 93 min

Designated Critical Suppliers: When a Device Manufacturer Gets Pulled In

12 lessons · 102 min

Incident Reporting Under CSRB

12 lessons · 91 min

CSRB Enforcement & Penalties

11 lessons · 75 min

The NCSC Cyber Assessment Framework

11 lessons · 76 min

UK vs. EU: NIS2, RED & the Cyber Resilience Act

13 lessons · 108 min

Full Walkthrough: A Connected Device Manufacturer's Compliance Program

12 lessons · 82 min

Common Mistakes & Edge Cases

11 lessons · 70 min

Your Compliance Action Plan

15 lessons · 125 min

What's Next

1 lessons · 0 min

Enroll — $199.00