Contact company icon Add as a preferred source Download PDF version
Summary is AI-generated, newsdesk-reviewed
  • DHF releases Best Practice Guide for PSTI Act compliance in door and hardware sector.
  • PSTI regulations demand cyber security standards; key focus on connected product compliance.
  • Non-compliance penalties up to £10 million emphasize importance of PSTI adherence.

The Door & Hardware Federation (DHF) has released a new Best Practice Guide titled "A Beginner's Guide to PSTI," tailored for its members to navigate the Product Security and Telecommunications Infrastructure (PSTI) Act 2022.

Developed to address growing cyber security concerns, the guide aims to help entities within the door, gate, hardware, and access control sectors understand and comply with related regulations. This initiative was led by DHF's Cyber Security Committee Chair, Dave Herbert.

Remote Monitoring Systems

This publication serves as an introductory resource for the PSTI Regulations, detailing which products come under its scope, and clarifying obligations for manufacturers, importers, and distributors. It provides essential guidance for compliance and encourages businesses to strive for best practices beyond legal necessities, thereby avoiding severe enforcement actions and financial repercussions.

"As more products become connected to the internet, cyber security is no longer solely an IT issue," according to DHF's Deputy CEO, Patricia Sowsbery-Stevens. She emphasized the growing importance of cyber security in product compliance and business risk, especially for the door and hardware sector.

Internet-Connected Devices

Compliance responsibilities extend beyond manufacturers to include importers and distributors

The PSTI Regulations, effective from 29th April 2024, apply to consumer connectable products in the UK. These rules create a minimum baseline for cyber security to combat threats from cyber criminals targeting connected devices. 

Compliance responsibilities extend beyond manufacturers to include importers and distributors, necessitating due diligence across the supply chain. The guide stresses that compliance is not merely a regulatory duty but a chance to boost customer trust and prepare for future regulatory shifts.

Mandatory PSTI Requirements

The guide emphasizes several key compliance actions, such as eliminating default passwords, establishing vulnerability reporting procedures, and defining the duration for security updates.

These are central to fulfilling PSTI obligations. Businesses are also advised to evaluate their supply chain roles, adhere to ETSI EN 303 645 standards, issue Statements of Compliance, and seek Secure Connected Device credentials where relevant. Compliance information must accompany the product rather than being solely online.

Vulnerability Reporting Mechanism

Non-compliance penalties can be steep, reaching up to £10 million or 4% of global turnover.

Past research indicates that only 27% of manufacturers had a basic vulnerability reporting mechanism, highlighting the need for industry-wide awareness and action. Patricia Sowsbery-Stevens concludes by urging all members to download and review the guide to ensure their products and processes meet PSTI standards.

In case you missed it

Enhancing Security At Lincoln's Inn With KeyWatcher
Enhancing Security At Lincoln's Inn With KeyWatcher

The Honourable Society of Lincoln’s Inn is one of the four Inns of Court and operates as an active and thriving society of lawyers, sprawling across 11 acres in central Londo...

How Are New Technologies Reshaping Casino Surveillance And Security?
How Are New Technologies Reshaping Casino Surveillance And Security?

Casinos are tasked with monitoring vast gaming floors, cashier cages, and access points. The market for casino security and surveillance demands software and hardware that provide...

ASSA ABLOY Showcases At GSX 2026 In Atlanta
ASSA ABLOY Showcases At GSX 2026 In Atlanta

ASSA ABLOY will be exhibiting at Global Security Exchange (GSX) 2026 from September 14 - 16 at the Georgia World Congress Center in Atlanta, Georgia. The company invites attendees...