- Status
- Amended (in force with amendments)
- Penalty ceiling
- Prosecution 3 of 38 obligations carry an unlimited fine. 2 carry different penalties and 33 have no criminal penalty — flagged in the list below.
Does it bind you?
Business-side roles with duties under this instrument.
Plus 1 duty on the regulator, Crown ministers and public bodies — folded into the section list below.
Other Acts binding the same actors
If a role above is yours, these are the other instruments that most often bind it.
Manufacturer — also bound by 502 other Acts
Trader — also bound by 825 other Acts
Distributor — also bound by 182 other Acts
Any Person — also bound by 2340 other Acts
Employer — also bound by 682 other Acts
Director or Officer — also bound by 429 other Acts
What it requires
Sections creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.
Product security
23 of 56 sections shown- Ensure connectable products meet UK security requirementsManufacturer
- Ensure your UK consumer connectable products meet security requirementsManufacturer
Fine up to £17,500,000
- Provide a statement of compliance with connectable productsManufacturer
- Investigate possible product security compliance failuresManufacturer
- Investigate potential security compliance failures in smart productsManufacturer
- Stop sales and fix security failures in connected productsManufacturer
- Take action on product security compliance failuresManufacturer
- Keep records of product security investigations and failuresManufacturer
- Maintain records of security investigations and compliance failuresManufacturer
- Authorised representatives must report manufacturer security failuresManufacturer
- Notify ICO of product security compliance failuresManufacturer
- Ensure imported connectable products meet security requirementsTrader
- Ensure products meet UK security standardsManufacturer
- Ensure imported connectable products have a statement of complianceManufacturer
- Do not supply products with known security compliance failuresTrader
- Do not supply connectable products with known security failuresManufacturer
- Investigate any reported product compliance failuresTrader
- Investigate potential security compliance failuresManufacturer
- Fix product security failures and notify ICO and customersEmployer
- Remedy and report security failures in your imported productsManufacturer
- Act for products with security failures if you are an importerManufacturer
- Take action when an imported product has a security compliance failureTrader
- Keep records of product security investigations for 10 yearsManufacturer
- Keep records of security investigations for imported productsTrader
- Ensure smart products meet UK security requirementsDistributor
- Ensure your connectable products meet UK security requirementsTrader
- Do not supply connectable products without a statement of complianceDistributor
- Do not supply non‑compliant consumer connectable productsTrader
- Do not sell products with known manufacturer security failuresDistributor
- Fix product security failures and notify ICO and customersTrader
- Remedy and report security failures in digital productsDistributor
- Act on and report security compliance failures in products you distributeDistributor
- Notify manufacturer, regulator and supply chain of product security failuresTrader
- Fail to comply with enforcement noticeAny Person
Unlimited fine
Other duties (1) — Crown / regulator
- Secretary of State must ensure penalties are appropriate and proportionateCrown / Minister / Government department
- Non-payment of product security finesAny Person
Unlimited fine
- Pretend to be authorised to enforce product securityAny Person
Unlimited fine
- Liable for corporate offence when you consent, connive or neglectDirector or Officer
33 other sections in this Part — procedural and definitional
Telecommunications infrastructure
0 of 19 sections shown19 other sections in this Part — procedural and definitional
Final provisions
0 of 5 sections shown5 other sections in this Part — procedural and definitional
1 other provision
Help complying
Guvnor’s practical routes through this instrument.
PSTI IoT compliance check
Quick compliance check for IoT manufacturers, importers, and distributors. Confirm product scope, verify three mandatory security requirements, identify your supply chain role, …
IoT product security compliance (PSTI Act)
How to comply with the Product Security and Telecommunications Infrastructure Act 2022 if you manufacture, import, or distribute consumer connectable products in …
Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.