Contact company icon Add as a preferred source Download PDF version
Summary is AI-generated, newsdesk-reviewed
  • DHF publishes PSTI Guide to aid compliance in door, gate, and hardware sectors.
  • PSTI Act mandates cyber security for connected products, impacting manufacturers, importers, distributors.
  • Non-compliance penalties reach £10m or 4% turnover; guide provides steps for adherence.

The Door & Hardware Federation (DHF) has released a new guide titled "A Beginner's Guide to PSTI" to aid its members in understanding and adhering to the mandates of the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 and the related regulations.

This initiative addresses growing cyber security concerns and reflects the increasing adoption of connected technologies within the door, gate, hardware, and access control industries. The guide was developed following a request from Dave Herbert, Chair of DHF’s Cyber Security Committee.

Understanding PSTI regulations

This publication offers a straightforward introduction to the PSTI Regulations for members. It specifies which products are covered, details the duties of manufacturers, importers, and distributors, and provides clear compliance guidance. Moreover, it urges businesses to go beyond the bare minimum legal requirements to avoid significant enforcement actions and potential financial punishments. 

This publication offers a straightforward introduction to the PSTI Regulations for members

As more products become connected to the internet, cyber security is no longer solely an IT issue,” explains DHF’s Deputy CEO, Patricia Sowsbery-Stevens. “It is increasingly a product compliance and business risk issue. Indeed, many businesses may be unaware that products incorporating connected technology are now subject to specific legal requirements under the PSTI Regulations. This is particularly relevant to the door and hardware sector, where technologies such as automated doors and gates, smart locks, access control systems, connected cameras, remote monitoring systems and connectivity hubs are becoming increasingly common. Many of these products may fall within the scope of the legislation.”

Scope of the PSTI act

The PSTI Regulations, effective from 29th April 2024, apply to consumer connectable products marketed in the UK and establish a basic cyber security standard for connected devices. Compliance is not solely the responsibility of manufacturers; importers and distributors are equally liable and must perform due diligence to ensure compliance.

Companies within the supply chain should evaluate their products to determine applicability and establish necessary compliance protocols. The guide notes that viewing compliance purely as a regulatory obligation underestimates its potential benefits in enhancing customer confidence, business reputation, and readiness for future regulations.

Key compliance actions

The guide identifies critical compliance measures, including eliminating default or weak passwords

The guide identifies critical compliance measures, including eliminating default or weak passwords, setting up a clear process for vulnerability reporting, and detailing the duration of security updates for connected devices.

These lay the foundation for the mandatory PSTI requirements. Additionally, businesses are urged to reassess their supply chain roles, use ETSI EN 303 645 as a compliance benchmark, draft strong Statements of Compliance, establish effective vulnerability reporting, and consider Secure Connected Device accreditation.

Awareness and action

With financial penalties for non-compliance reaching as high as £10 million or 4% of global turnover, the guide emphasizes the importance of industry-wide awareness and action.

Previous studies cited in the guide reveal only 27% of manufacturers having a basic vulnerability reporting mechanism, highlighting the critical need for improvement. “We are encouraging all members to download and review the guide and assess whether their products and business processes meet the requirements of the PSTI Regulations,” concludes Patricia.

In case you missed it

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence
How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organisations are increasingly discovering that the same cameras installed to pro...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...