On Demand Webinar

Product Cybersecurity Requirements for UK PSTI and EU RED Webinar

Smartphone held against a test mannequin head in an anechoic chamber for wireless device compliance testing

Selling a connected product in the UK or EU? Two sets of cybersecurity rules already apply, and failing to meet them can stop your product reaching the market. 

This on-demand webinar, presented by Element Technical Solution Manager Alex Toohie, explains the mandatory product cybersecurity requirements under the UK PSTI regime and the EU Radio Equipment Directive, or RED. You will learn which products are in scope, what each regime requires, and the steps your compliance team should take now. 

Why watch this webinar on Product Cybersecurity Requirements for UK PSTI and EU RED? 

  • Work out which rules apply to your product. The webinar shows how to tell whether UK PSTI, the EU RED cybersecurity requirements, or both apply, so you can stop guessing at scope. 
  • Understand what "in scope" means for RED. Alex explains the internet-connected question that determines RED applicability, including the grey areas the standard leaves to your own judgment. 
  • See exactly what each regime requires. Get a plain breakdown of the UK PSTI security requirements and the RED requirements under Article 3.3, so you know what evidence you need. 
  • Choose the right route to compliance. Learn when meeting the harmonized EN 18031 standards lets you self-declare, and when a Notified Body is required. 
  • Avoid costly mistakes. Understand the commercial risk of getting scope or evidence wrong, from blocked market access to product withdrawal. 

Key topics covered 

  • What is the UK PSTI regime, and which products does it cover? 
  • What are the UK PSTI security requirements? 
  • What are the EU RED cybersecurity requirements under Article 3.3? 
  • Is my product "internet-connected" under RED? 
  • What is the difference between an internet-connectable and a network-connectable product? 
  • How do EN 18031 and ETSI EN 303 645 support compliance? 
  • When do the UK PSTI and EU RED requirements apply?
  • How does product cybersecurity law differ between the UK and EU?


Watch the webinar below

0:00 – Introduction 

Alex Toohie opens the session, the first of two on product cybersecurity, and explains his background in radio, EMC and cybersecurity testing. He sets out what this first part covers: the rules that already apply today under UK PSTI and EU RED. 

1:20 – Why product cybersecurity matters 

A short grounding in the threat. Alex explains how connected devices get pulled into botnets and denial-of-service attacks, and walks through the weaknesses attackers exploit most, from universal default passwords to exposed interfaces, insecure communications and built-in backdoors. 

5:10 – The rules and how they fit together 

Alex maps the three regimes by geography: UK PSTI, the EU RED cybersecurity requirements, and the EU Cyber Resilience Act, and which products each one covers. For a full side-by-side comparison of all three, read the whitepaper. 

8:00 – The compliance timeline 

A walk through the key dates, from the first baseline standard in 2020 to the RED cybersecurity requirements becoming mandatory in August 2025 and the CRA taking effect from 2027. This is the quickest way to see what applies to you now against what is still coming. 

11:30 – UK PSTI: which products are in scope 

Alex breaks down the two PSTI categories, internet-connectable and network-connectable products, and uses a typical home network to show where the line falls. If you sell consumer connectable products, this segment tells you whether PSTI applies to yours. 

15:50 – UK PSTI: the four requirements 

The four things PSTI asks of manufacturers: no universal default passwords, a published security update period, a way to report vulnerabilities, and a statement of compliance. Alex also shows how the statement can sit alongside an existing UKCA declaration. The Act itself is on legislation.gov.uk. 

18:40 – EU RED Article 3.3: what is covered 

The three RED cybersecurity categories under Article 3.3: internet-connected radio equipment, equipment that processes personal data, and equipment that handles money or virtual currency. For a clause-by-clause look, read Element's article on cybersecurity and the RED Article 3.3 essential requirements. 

20:30 – Is my product "internet-connected" under RED? 

The question that decides RED scope. Alex works through the internet-ready against non-internet-ready protocol test, gives examples of products that fall in and out of scope, and explains the grey areas where you have to make and document your own judgment. 

25:10 – RED requirements and your conformity route 

The three RED essential requirements, protect the network, protect data and privacy, and protect against fraud, and how you demonstrate them. Meet the harmonized EN 18031 standards in full and you can self-declare; deviate and you need a Notified Body. Alex introduces EN 18031-1, -2 and -3. 

27:40 – EN 18031: assets, decision trees and evidence 

A closer look at what EN 18031 demands in practice: the asset lists, decision trees and documentation behind a compliant assessment, which is where much of the work sits. For the step-by-step asset-identification method, read Element's whitepaper on testing to EN 18031. 

30:20 – What comes next: the Cyber Resilience Act 

Alex closes with a preview of the Cyber Resilience Act and its September 2026 reporting date, and points to the free tools and guidance Element provides. For the CRA in full, watch Element's EU Cyber Resilience Act webinar. 

Related Services

IoT Testing Services and IoT Certification

Internet of Things (IoT) Testing and Certification

Element's IoT testing services and certification ensure compliance, accelerate market readiness, and provide global IoT network access. Learn More.

Consumer Electronics Testing and Certification

Consumer Electronics Testing and Certification

Get expert consumer electronics testing to accelerate your market entry. Element's accredited EMC, safety & wireless compliance services facilitate smoother market entry.

Wireless Network

Wireless Device Testing & Certification

Get your wireless devices to market faster with Element's accredited testing services. Expert guidance through compliance, certification and global approvals for all wireless technologies.

Radio

RED Directive Testing for CE Marking

Element's Radio Equipment Directive (RED) services provide testing, certification, and expert guidance to help manufacturers meet EU compliance requirements and secure CE marking for wireless products.

Mobile and Cellular Devices

Product Cybersecurity Testing & Certification Services

Element offers end-to-end product Cybersecurity testing and certification services to ensure your IoT product is safe, secure and compliant with PSTI, RED, and CRA.

Speak to our team of experts

AMERICAS

Toll free from US lines

+1 888 786 7555

EUROPE

Contact our Central Team
UK

Freephone from UK

+44 808 234 1667

Germany

Freephone from Germany 

+49 800 000 5137

MIDDLE EAST

Toll free from UAE

+971 800 353 6368