The Door & Hardware Federation (DHF) has released a new guide titled "A Beginner's Guide to PSTI" to aid its members in understanding and adhering to the mandates of the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 and the related regulations.
This initiative addresses growing cyber security concerns and reflects the increasing adoption of connected technologies within the door, gate, hardware, and access control industries. The guide was developed following a request from Dave Herbert, Chair of DHF’s Cyber Security Committee.
Understanding PSTI regulations
This publication offers a straightforward introduction to the PSTI Regulations for members. It specifies which products are covered, details the duties of manufacturers, importers, and distributors, and provides clear compliance guidance. Moreover, it urges businesses to go beyond the bare minimum legal requirements to avoid significant enforcement actions and potential financial punishments.
This publication offers a straightforward introduction to the PSTI Regulations for members
“As more products become connected to the internet, cyber security is no longer solely an IT issue,” explains DHF’s Deputy CEO, Patricia Sowsbery-Stevens. “It is increasingly a product compliance and business risk issue. Indeed, many businesses may be unaware that products incorporating connected technology are now subject to specific legal requirements under the PSTI Regulations. This is particularly relevant to the door and hardware sector, where technologies such as automated doors and gates, smart locks, access control systems, connected cameras, remote monitoring systems and connectivity hubs are becoming increasingly common. Many of these products may fall within the scope of the legislation.”
Scope of the PSTI act
The PSTI Regulations, effective from 29th April 2024, apply to consumer connectable products marketed in the UK and establish a basic cyber security standard for connected devices. Compliance is not solely the responsibility of manufacturers; importers and distributors are equally liable and must perform due diligence to ensure compliance.
Companies within the supply chain should evaluate their products to determine applicability and establish necessary compliance protocols. The guide notes that viewing compliance purely as a regulatory obligation underestimates its potential benefits in enhancing customer confidence, business reputation, and readiness for future regulations.
Key compliance actions
The guide identifies critical compliance measures, including eliminating default or weak passwords
The guide identifies critical compliance measures, including eliminating default or weak passwords, setting up a clear process for vulnerability reporting, and detailing the duration of security updates for connected devices.
These lay the foundation for the mandatory PSTI requirements. Additionally, businesses are urged to reassess their supply chain roles, use ETSI EN 303 645 as a compliance benchmark, draft strong Statements of Compliance, establish effective vulnerability reporting, and consider Secure Connected Device accreditation.
Awareness and action
With financial penalties for non-compliance reaching as high as £10 million or 4% of global turnover, the guide emphasizes the importance of industry-wide awareness and action.
Previous studies cited in the guide reveal only 27% of manufacturers having a basic vulnerability reporting mechanism, highlighting the critical need for improvement. “We are encouraging all members to download and review the guide and assess whether their products and business processes meet the requirements of the PSTI Regulations,” concludes Patricia.
The Door & Hardware Federation (DHF) has published a new Best Practice Guide, A Beginner's Guide to PSTI for members of DHF, to help them understand and comply with the requirements of the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 and associated regulations.
Developed in response to growing concerns around cyber security and the increasing use of connected technologies within the door, gate, hardware and access control sectors, the guide was produced at the request of DHF's Cyber Security Committee Chair, Dave Herbert.
Remote monitoring systems
The publication has been designed to provide members with a concise introduction to the PSTI Regulations. It explains which products may fall within scope, clarifies the responsibilities of manufacturers, importers and distributors, and offers straightforward guidance on achieving compliance. The guide also encourages businesses to adopt best practice beyond the minimum legal requirements while helping them avoid potentially significant enforcement action and financial penalties.
“As more products become connected to the internet, cyber security is no longer solely an IT issue,” explains DHF’s Deputy CEO, Patricia Sowsbery-Stevens. “It is increasingly a product compliance and business risk issue. Indeed, many businesses may be unaware that products incorporating connected technology are now subject to specific legal requirements under the PSTI Regulations. This is particularly relevant to the door and hardware sector, where technologies such as automated doors and gates, smart locks, access control systems, connected cameras, remote monitoring systems and connectivity hubs are becoming increasingly common. Many of these products may fall within the scope of the legislation.”
Internet-connected devices
The PSTI Regulations came into force on 29th April 2024 and apply to relevant consumer connectable products placed on the market in the UK. The regulations establish a minimum cyber security baseline for connected products, helping to address the growing threat posed by cyber criminals targeting internet-connected devices.
Importantly, responsibility for compliance does not rest solely with manufacturers. Importers and distributors also have legal obligations and must undertake appropriate due diligence to ensure products placed on the market meet the required standards. Businesses throughout the supply chain should therefore review their products, determine whether they fall within scope and ensure that appropriate compliance procedures are in place. The guide highlights that compliance should not be viewed simply as a regulatory burden. Demonstrating strong cyber security practices can improve customer confidence, strengthen business reputation and help organisations prepare for future regulatory developments.
Mandatory PSTI requirements
Among the most important actions identified within the guide are the removal of default or easily guessable passwords, the establishment of a clear vulnerability reporting process, and the communication of how long security updates will be provided for connected products. These measures form the foundation of the mandatory PSTI requirements.
The publication also encourages businesses to review their role within the supply chain, use ETSI EN 303 645 as a benchmark for compliance, prepare robust Statements of Compliance, establish effective vulnerability reporting processes, and consider Secure Connected Device accreditation where appropriate. Members are also reminded that PSTI compliance information must accompany the product and should not simply be published on a website.
Vulnerability reporting mechanism
The guide notes that financial penalties for non-compliance can reach £10 million or 4% of global turnover, whichever is greater. It also highlights previous research showing that only 27% of manufacturers had a basic vulnerability reporting mechanism in place, underlining the need for greater awareness and action across industry.
“We are encouraging all members to download and review the guide and assess whether their products and business processes meet the requirements of the PSTI Regulations,” concludes Patricia.