# UK PSTI Act: The Cybersecurity Law That Hits Every IoT Product

The UK Product Security and Telecommunications Infrastructure Act came into force in April 2024. It mandates three baseline security requirements for every connectable product sold in the UK — consumer IoT devices, smart home products, and anything that connects to a network or another device. Non-compliant products cannot legally be sold in the UK market, and retailers are liable too.


## Transcript

### Three requirements, no exceptions, enforced now

The UK's PSTI Act has been in force since April 2024, applying to every connectable consumer product sold in the UK. Three requirements are mandatory: unique passwords, a published vulnerability disclosure policy, and a minimum security support period. Miss one, and you can't legally sell.

### The three requirements in detail

PSTI implements the first three provisions of ETSI EN 303 645: no shared default passwords, a published vulnerability disclosure contact, and a disclosed security update period at point of sale. OPSS enforces this, with fines up to £10 million or 4% of global turnover.

### What to do if you sell connected products in the UK

Audit your product against all three requirements. Ship unique credentials, or force a password change on first use. Publish a vulnerability disclosure page with a monitored mailbox. Add your security support period to product listings and packaging.

Tags: UK PSTI Act, IoT security, UKCA, connected products, UK compliance