About us

Your Guide to new UK and EU Cyber Security Legislation

UPDATED: Get our exclusive walkthrough of connected device legislation, which affects all connected products on the UK and EU markets, has been updated ahead of the April 29th deadline.

Get your copy now which:

  • Adds more guidance about the products (and businesses) in scope
  • Includes new detailed information for retailers, distributors and installers about the requirements on them
  • Expands the section about the Statement of Compliance and the specific conditions that need to be met
  • Updates key compliance dates for both UK and EU
  • Provides new information about how to make sure you are covered (or certified that you don’t need to be) by the April 29th deadline.

Get your copy below - COMPLIANCE DEADLINE APRIL 29th

The security and safety of connected products is not only a customer-critical issue, it is now a legislative compliance issue for all manufacturers, importers and distributors.


UK Cybersecurity Standards

In the UK, the Product Security and Telecoms Infrastructure (PSTI) Bill became law in December 2022, with further secondary legislation outlining exact smart home cyber security requirements and enforcement to follow shortly.

It sets out cyber security requirements, to ensure consumer security, as a condition for market entry for all internet or network-connected devices, underpinned by the European ETSI EN 303 645 standard.

The new requirements will impact all stakeholders throughout the supply chain – not just the manufacturers. While fundamentally ensuring all internet-connected equipment is tested for cyber security performance before it can access the market, responsibility (and therefore liability) also lies with importers, and distributors to ensure that the requisite tests have been done by the manufacturer.

European Cyber Security Standards

In the EU, recently activated articles within the Radio Equipment Directive (RED), will mandate cyber security requirements for all internet-connected devices and a new standard is being developed by CEN-CENELEC for manufacturers to test their products against to demonstrate conformity.

This will be followed by the Cyber Resilience Act, first published in September 2022. As in the UK, new requirements will apply not just to manufacturers, but also importers and distributors.

This exclusive guide to cyber security standards and assurance outlines the precise tests that products and manufacturers need to pass, what they need to do, when they need to do it by and the implications for not acting swiftly enough or for non-compliance.

While (most) manufacturers clearly take security seriously, the nature of products in this market – which contain multiple software components from different sources – means it is much harder for manufacturers to have an overall comprehension of the cyber security performance of their products.

The common failure factor in each test case is that the manufacturer was not aware of the identified issues, much less their contravention of new standards and IoT requirements, despite their commitment to security and internal processes. It is therefore equally hard to determine PSTI device compliance without independent, verified device testing.

SafeShark’s independent testing service, backed by DTG’s London testing house and the British Standards Institute (BSI), gives manufacturers a true understanding of their product performance against UK and international standards. This cyber security certification, assurance and external verification provides clear proof of IoT device compliance. It provides a straightforward route to market and the confidence needed by those in the onward chain to the consumer.

5th Floor
89 Albert Embankment
Vauxhall, London
©2022 SafeShark Limited | All rights reserved | Terms and Conditions | Privacy Policy
Site by Fortico