The Door & Hardware Federation (DHF) has released a new Best Practice Guide titled "A Beginner's Guide to PSTI," tailored for its members to navigate the Product Security and Telecommunications Infrastructure (PSTI) Act 2022.
Developed to address growing cyber security concerns, the guide aims to help entities within the door, gate, hardware, and access control sectors understand and comply with related regulations. This initiative was led by DHF's Cyber Security Committee Chair, Dave Herbert.
Remote Monitoring Systems
This publication serves as an introductory resource for the PSTI Regulations, detailing which products come under its scope, and clarifying obligations for manufacturers, importers, and distributors. It provides essential guidance for compliance and encourages businesses to strive for best practices beyond legal necessities, thereby avoiding severe enforcement actions and financial repercussions.
"As more products become connected to the internet, cyber security is no longer solely an IT issue," according to DHF's Deputy CEO, Patricia Sowsbery-Stevens. She emphasized the growing importance of cyber security in product compliance and business risk, especially for the door and hardware sector.
Internet-Connected Devices
Compliance responsibilities extend beyond manufacturers to include importers and distributors
The PSTI Regulations, effective from 29th April 2024, apply to consumer connectable products in the UK. These rules create a minimum baseline for cyber security to combat threats from cyber criminals targeting connected devices.
Compliance responsibilities extend beyond manufacturers to include importers and distributors, necessitating due diligence across the supply chain. The guide stresses that compliance is not merely a regulatory duty but a chance to boost customer trust and prepare for future regulatory shifts.
Mandatory PSTI Requirements
The guide emphasizes several key compliance actions, such as eliminating default passwords, establishing vulnerability reporting procedures, and defining the duration for security updates.
These are central to fulfilling PSTI obligations. Businesses are also advised to evaluate their supply chain roles, adhere to ETSI EN 303 645 standards, issue Statements of Compliance, and seek Secure Connected Device credentials where relevant. Compliance information must accompany the product rather than being solely online.
Vulnerability Reporting Mechanism
Non-compliance penalties can be steep, reaching up to £10 million or 4% of global turnover.
Past research indicates that only 27% of manufacturers had a basic vulnerability reporting mechanism, highlighting the need for industry-wide awareness and action. Patricia Sowsbery-Stevens concludes by urging all members to download and review the guide to ensure their products and processes meet PSTI standards.
The Door & Hardware Federation (DHF) has published a new Best Practice Guide, A Beginner's Guide to PSTI for members of DHF, to help them understand and comply with the requirements of the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 and associated regulations.
Developed in response to growing concerns around cyber security and the increasing use of connected technologies within the door, gate, hardware and access control sectors, the guide was produced at the request of DHF's Cyber Security Committee Chair, Dave Herbert.
Remote monitoring systems
The publication has been designed to provide members with a concise introduction to the PSTI Regulations. It explains which products may fall within scope, clarifies the responsibilities of manufacturers, importers and distributors, and offers straightforward guidance on achieving compliance. The guide also encourages businesses to adopt best practice beyond the minimum legal requirements while helping them avoid potentially significant enforcement action and financial penalties.
“As more products become connected to the internet, cyber security is no longer solely an IT issue,” explains DHF’s Deputy CEO, Patricia Sowsbery-Stevens. “It is increasingly a product compliance and business risk issue. Indeed, many businesses may be unaware that products incorporating connected technology are now subject to specific legal requirements under the PSTI Regulations. This is particularly relevant to the door and hardware sector, where technologies such as automated doors and gates, smart locks, access control systems, connected cameras, remote monitoring systems and connectivity hubs are becoming increasingly common. Many of these products may fall within the scope of the legislation.”
Internet-connected devices
The PSTI Regulations came into force on 29th April 2024 and apply to relevant consumer connectable products placed on the market in the UK. The regulations establish a minimum cyber security baseline for connected products, helping to address the growing threat posed by cyber criminals targeting internet-connected devices.
Importantly, responsibility for compliance does not rest solely with manufacturers. Importers and distributors also have legal obligations and must undertake appropriate due diligence to ensure products placed on the market meet the required standards. Businesses throughout the supply chain should therefore review their products, determine whether they fall within scope and ensure that appropriate compliance procedures are in place. The guide highlights that compliance should not be viewed simply as a regulatory burden. Demonstrating strong cyber security practices can improve customer confidence, strengthen business reputation and help organizations prepare for future regulatory developments.
Mandatory PSTI requirements
Among the most important actions identified within the guide are the removal of default or easily guessable passwords, the establishment of a clear vulnerability reporting process, and the communication of how long security updates will be provided for connected products. These measures form the foundation of the mandatory PSTI requirements.
The publication also encourages businesses to review their role within the supply chain, use ETSI EN 303 645 as a benchmark for compliance, prepare robust Statements of Compliance, establish effective vulnerability reporting processes, and consider Secure Connected Device accreditation where appropriate. Members are also reminded that PSTI compliance information must accompany the product and should not simply be published on a website.
Vulnerability reporting mechanism
The guide notes that financial penalties for non-compliance can reach £10 million or 4% of global turnover, whichever is greater. It also highlights previous research showing that only 27% of manufacturers had a basic vulnerability reporting mechanism in place, underlining the need for greater awareness and action across industry.
“We are encouraging all members to download and review the guide and assess whether their products and business processes meet the requirements of the PSTI Regulations,” concludes Patricia.