How PSTI compares to the EU Cyber Resilience Act
Comparing PSTI and the EU CRA requires identifying overlapping security baselines while distinguishing between their different scopes and enforcement mechanisms. While UK PSTI focuses on baseline requirements for consumer connectable products, the EU CRA is a broader framework introducing risk-based tiers and mandatory CE marking for most products with digital elements.
What it means
In practice, this comparison is about mapping two different regulatory philosophies. The UK PSTI Act acts as a "security floor," targeting common vulnerabilities like default passwords and lack of update transparency specifically for the consumer market. It is designed to be straightforward and focused on preventing large-scale botnets and basic attacks.
The EU CRA is significantly more comprehensive, covering almost all products with digital elements regardless of whether they are for consumers or industrial use. It introduces a tiered risk system (Uncritical, Critical, Highly Critical) where higher-risk products face stricter conformity assessments and third-party audits before they can be placed on the market.
For an implementer, this means that while many technical controls overlap—such as vulnerability management and secure defaults—the administrative burden of the CRA is higher due to its integration with EU market access laws (CE marking) and more rigorous documentation requirements throughout the product lifecycle.
How to meet it
- Perform a gap analysis between PSTI's specific mandates and the CRA’s "Essential Requirements" to identify shared controls.
- Implement a unified Vulnerability Disclosure Policy (VDP) that meets both UK transparency rules and EU reporting timelines.
- Remove all universal default passwords across all product lines, ensuring unique per-device passwords or forced changes upon setup.
- Define and document the minimum security update support period for every product model sold in both jurisdictions.
- Map products to CRA risk categories (e.g., Critical vs. Non-Critical) to determine if additional third-party conformity assessments are required beyond standard self-assessment.
- Establish a centralized technical documentation repository that can serve as the basis for both UK compliance evidence and EU Technical Documentation dossiers.
Evidence an auditor asks for
- A product inventory identifying which devices fall under PSTI, CRA, or both, including their assigned risk tier under the CRA.
- The public-facing Vulnerability Disclosure Policy and a log of vulnerabilities received, tracked, and patched.
- Firmware configuration files or setup guides proving that default passwords are not used.
- Customer-facing documentation (e.g., on the website or packaging) explicitly stating the security update support window for each product.
- The EU Declaration of Conformity and associated technical files required for CE marking under the CRA.
Common pitfalls
- Assuming that meeting EU CRA requirements automatically satisfies UK PSTI, ignoring specific UK reporting obligations to the OPSS.
- Applying a generic security standard across all products instead of adopting the risk-based approach mandated by the CRA's different product classes.
- Failing to maintain an accurate "End of Life" (EOL) schedule