UK Act of Parliament 2022 United Kingdom

PSTIA 2022

An Act to make provision about the security of internet-connectable products and products capable of connecting to such products; to make provision about electronic communications infrastructure; and for connected purposes.

Enforced by
Ofcom, OPSS
Status
Amended (in force with amendments)
Penalty ceiling
Prosecution 3 of 38 obligations carry an unlimited fine. 2 carry different penalties and 33 have no criminal penalty — flagged in the list below.

Does it bind you?

Business-side roles with duties under this instrument.

Manufacturer18 Trader9 Distributor5 Any Person3 Employer1 Director or Officer1

Plus 1 duty on the regulator, Crown ministers and public bodies — folded into the section list below.

Other Acts binding the same actors

If a role above is yours, these are the other instruments that most often bind it.

Manufacturer — also bound by 502 other Acts
Trader — also bound by 825 other Acts
Distributor — also bound by 182 other Acts
Any Person — also bound by 2340 other Acts
Employer — also bound by 682 other Acts
Director or Officer — also bound by 429 other Acts

What it requires

Sections creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.

Part 1

Product security

23 of 56 sections shown
s.008 Duty to comply with security requirements (opens in a new tab) Prosecution
  • Ensure connectable products meet UK security requirementsManufacturer
  • Ensure your UK consumer connectable products meet security requirementsManufacturer

Fine up to £17,500,000

s.009 Statements of compliance (opens in a new tab) Regulated
  • Provide a statement of compliance with connectable productsManufacturer
s.010 Duty to investigate potential compliance failures (opens in a new tab) Regulated
  • Investigate possible product security compliance failuresManufacturer
  • Investigate potential security compliance failures in smart productsManufacturer
s.011 Duties to take action in relation to compliance failure (opens in a new tab) Regulated
  • Stop sales and fix security failures in connected productsManufacturer
  • Take action on product security compliance failuresManufacturer
s.012 Duty to maintain records (opens in a new tab) Regulated
  • Keep records of product security investigations and failuresManufacturer
  • Maintain records of security investigations and compliance failuresManufacturer
s.013 Duties to take action in relation to manufacturer’s compliance failure (opens in a new tab) Regulated
  • Authorised representatives must report manufacturer security failuresManufacturer
  • Notify ICO of product security compliance failuresManufacturer
s.014 Duty to comply with security requirements (opens in a new tab) Regulated
  • Ensure imported connectable products meet security requirementsTrader
  • Ensure products meet UK security standardsManufacturer
s.015 Statements of compliance (opens in a new tab) Regulated
  • Ensure imported connectable products have a statement of complianceManufacturer
s.016 Duty not to supply products where compliance failure by manufacturer (opens in a new tab) Regulated
  • Do not supply products with known security compliance failuresTrader
  • Do not supply connectable products with known security failuresManufacturer
s.017 Duty to investigate potential compliance failures of importer or manufacturer (opens in a new tab) Regulated
  • Investigate any reported product compliance failuresTrader
  • Investigate potential security compliance failuresManufacturer
s.018 Duties to take action in relation to importer’s compliance failure (opens in a new tab) Regulated
  • Fix product security failures and notify ICO and customersEmployer
  • Remedy and report security failures in your imported productsManufacturer
s.019 Duties to take action in relation to manufacturer’s compliance failure (opens in a new tab) Regulated
  • Act for products with security failures if you are an importerManufacturer
  • Take action when an imported product has a security compliance failureTrader
s.020 Duty to maintain records of investigations (opens in a new tab) Regulated
  • Keep records of product security investigations for 10 yearsManufacturer
  • Keep records of security investigations for imported productsTrader
s.021 Duty to comply with security requirements (opens in a new tab) Regulated
  • Ensure smart products meet UK security requirementsDistributor
  • Ensure your connectable products meet UK security requirementsTrader
s.022 Statements of compliance (opens in a new tab) Regulated
  • Do not supply connectable products without a statement of complianceDistributor
s.023 Duty not to supply products where compliance failure by manufacturer (opens in a new tab) Regulated
  • Do not supply non‑compliant consumer connectable productsTrader
  • Do not sell products with known manufacturer security failuresDistributor
s.024 Duties to take action in relation to distributor’s compliance failures (opens in a new tab) Regulated
  • Fix product security failures and notify ICO and customersTrader
  • Remedy and report security failures in digital productsDistributor
s.025 Duties to take action in relation to manufacturer’s compliance failure (opens in a new tab) Regulated
  • Act on and report security compliance failures in products you distributeDistributor
  • Notify manufacturer, regulator and supply chain of product security failuresTrader
s.032 Failure to comply with enforcement notice (opens in a new tab) Prosecution
  • Fail to comply with enforcement noticeAny Person

Unlimited fine

s.037 Determining the amount of a penalty (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • Secretary of State must ensure penalties are appropriate and proportionateCrown / Minister / Government department
s.040 Enforcement of penalty notices (opens in a new tab) Prosecution
  • Non-payment of product security finesAny Person

Unlimited fine

s.049 Offence of purporting to act as authorised to exercise enforcement function (opens in a new tab) Prosecution
  • Pretend to be authorised to enforce product securityAny Person

Unlimited fine

s.052 Offences by directors, partners etc (opens in a new tab) Regulated
  • Liable for corporate offence when you consent, connive or neglectDirector or Officer
33 other sections in this Part — procedural and definitional
Part 2

Telecommunications infrastructure

0 of 19 sections shown
19 other sections in this Part — procedural and definitional
Part 3

Final provisions

0 of 5 sections shown
1 other provision
s.unresponsive occupiers: consequential amendments Unresponsive occupiers: consequential amendments

Help complying

Guvnor’s practical routes through this instrument.

Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.