PSTI 認証

As an accredited testing laboratory, we’ve helped thousands of manufacturers complete cyber security testing for their products and achieve PSTI certification.

1. PSTI certification

In December 2022, the UK government formally passed the "Product Security and Telecommunications Infrastructure Act 2022" (PSTI) and it will be enforced from April 29, 2024. The new regulation marks a new era for cybersecurity in the UK, as it mandates the creation of new minimum security requirements that manufacturers, importers, and distributors of consumer connectable products (also called Internet of Things or IoT devices) must comply with.

2. More about PSTI certification

The bill received Royal Assent on 6 December 2022. It entered into force in April 2023 with a 12-month transition period, and became mandatory from 29th April 2024, and manufacturers are obliged to comply with the security requirements described therein or face potential penalties.

The bill consist of three main parts:

  • Part 1: product security;
  • Part 2: telecommunications infrastructure;
  • Part 3: final provisions.

Part 1 of the PSTI Regulation requires manufacturers, distributors, and importers to ensure that products placed on the UK market comply with minimum security requirements aimed at protecting the UK consumer.

It applies to England and Wales, Scotland, and Northern Ireland.

Products that can be connected to a network or internet are under the scope of this regulation. These are the Internet of Things devices, that include, but are not limited to:

  • Smartphones;
  • Smart cameras;
  • Smart TVs;
  • Smart speakers;
  • Connected home appliances like smart refrigerators, smart washing machines;
  • Smart home assistants;
  • Routers;
  • Cameras;
  • Smoke detectors;
  • Connected safety-relevant products such as smoke detectors, windows sensors, and door locks (smart locks);
  • Connected home automation and alarm systems (gateways and hubs);
  • Smart home hubs and assistants;
  • Wearable connected fitness trackers;
  • Outdoor leisure products, such as handheld connected GPS devices that are not wearables;
  • Connected children’s toys and baby monitors;
  • Internet of Things base stations and hubs to which multiple devices connect;

It is also important to know that the following devices are excluded from the UK PSTI Regulations:

  • vehicles;
  • Charge points for electric vehicles;
  • Medical devices (if they fall under the MDR);
  • Smart meter products;
  • Computer products like desktop, laptop and tablet computers (desktop and laptop computers designed for use by children aged 14 and under) which do not have the capability to connect to cellular networks;

Not sure if your product requires PSTI certification? Please 短いフォームに記入してください弊社の専門家が喜んでお手伝いいたします。

According to the UK GOV’s publication on PSTI, such as the documentThe Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023,as shown in Schedule 2, PSTI currently assesses products for compliance with three control requirements at this stage:

  1. Prohibition of common default passwords, reference standards: ETSI EN 303 645 provisions 5.1-1 and 5.1-2;
  2. Implementation of vulnerability disclosure management, reference standards: ETSI EN 303 645 provision 5.2-1;
  3. Requirement to maintain transparency for the shortest security update time period, reference standards: ETSI EN 303 645 provision 5.3-13.

ETSI EN 303 645 establishes new global standards for the security of consumer devices connected to the Internet of Things (IoT), enabling products to withstand serious cybersecurity threats and comply with GDPR requirements, protecting personal data and consumer privacy.

The ETSI EN 303 645 standard for IoT product security and privacy includes the following 13 categories of requirements:

  1. Common default password security;
  2. Vulnerability disclosure management;
  3. Software updates;
  4. Sensitive security parameter storage;
  5. Communication security;
  6. Minimization of attack surface;
  7. Protection of personal data;
  8. Software integrity;
  9. System resilience to interruptions;
  10. Inspection of system telemetry data;
  11. Ease of deletion of personal data by users;
  12. Simplified device installation and maintenance;
  13. Validation of input data.

PSTI Act and ETSI EN 303 645 standard testing processes:

  • Sample data preparation: three sets of samples including main units and accessories, unencrypted software, user manuals/specifications/relevant services, and login accounts;
  • Establishment of test environment: establish a test environment based on the user manual;
  • Execution of network security assessment: document review and technical testing, check vendor questionnaires, and provide feedback;
  • Weakness remediation: provide consulting services to address weakness issues;
  • Issuance of PSTI assessment report or ETSI EN 303 645 assessment report.

3. 価格と納期

You will never pay for services that you don’t need! GTG Group provides a customized quote which are tailored to each client's needs and budget. Furthermore, we can expedite the certification process by leveraging modern technologies that ensure you receive the PSTI certification in a reasonably short time frame, faster than the average industry time.

However, the cost and the lead time of testing and certification varies depending on the product complexity and the testing requirements. GTG Group provides free consultation to assess your needs and provide advice on how to get started with compliance. お問い合わせ today by 短いフォームに記入してください

4. FAQs

Does the Statement of Compliance (SoC) have to be a piece of paper that comes in the box with the product? What doesattachedmean? Does the Statement of Compliance (SoC) have to be a piece of paper that comes in the box with the product? What doesattachedmean?

No. It is up to each organization to decide how to comply with the Act based on the requirements of their own products. The Act require that the SoC must be a document, but they do not specify that this document must be paper-based; it can also be in digital form. However, manufacturers must ensure that this document is provided with the product, in whatever form, to ensure that users can access it when they receive the product.

Should Bluetooth be considered as meeting the second connectivity condition?

Section 5 defines the connectivity condition as follows:
‘(5) A product meets the second connectivity condition if

  • (a) it can connect directly to two or more products simultaneously through a communication protocol that is not part of the Internet Protocol Suite, and
  • (b) it can connect directly to an Internet-connectable product (whether or not it is also connected to any other product) through such a communication protocol.’

Accordingly, a Bluetooth product meets the second connectivity condition if it is capable of connecting to two or more products and is also capable of connecting directly to an Internet-connectable product.

If I only sell connected products for business/professional use, are they exempt from the Act?

If the manufacturer knew or should have known that the product would be used as a UK consumer connected product, then the product falls within the scope of the requirements. This means that whether or not the product is marketed to ‘professionals or merchants’, if the manufacturer knew or should have known that consumers would use the product, then the product needs to comply with the Act. For a manufacturer to be exempt from the Act, they must ensure that the product will not be used by consumers. They must ensure that the product will not be used by consumers, that there is no equivalent product on the market for consumers, and that the product has not been offered to consumers before.

Since retailers as part of the supply chain will be affected by the UK’s PSTI Act, do online consumer retail platforms like eBay, Amazon, Taobao, etc., need to comply with the UK PSIT Act in the following scenarios?

  • a. The relevant products come from distributors and importers who procure from suppliers,
  • b. The relevant products are directly procured by the online consumer retail platform from suppliers.

All relevant parties must comply with the Product Safety and Telecommunications Infrastructure Act of 2022.

5. なぜ私たちを選ぶのですか?

2012 年に設立された GTG グループは、中国における独立した ISO/IEC 17025 認定製品試験および認証サービス プロバイダーであり、幅広い製品に対して包括的な試験および規制認証取得サービスを提供しています。私たちの目標は、お客様が世界市場にアクセスできるよう、お客様の製品を認証し、規制基準への準拠を保証することです。

By working with GTG Group, you will enjoy the convenience of completing all of your tests (cyber security, safety, EMC, RF, wireless, energy efficiency, environmental, durability, performance, chemical and other tests) and receive certification for your product from a single accredited lab. You will also eliminate the headaches of using multiple labs, delays in logistics, and shipping costs. お問い合わせ 今日!

GTG グループと協力することの最も重要な利点の 1 つは、実際のテストを実行し、エンド ユーザーに対して責任を負うことです。これはリスクを回避し、製品を使用する企業や個人に安心感を与えるため、不可欠です。当社は世界有数の企業と協力しており、当社のサービスはクライアントから高く評価されています。テストと認証のために GTG グループを選択すると、信頼できるパートナーと協力していると確信できます。

当社のテストとテストレポートは世界的に認められており、規制当局によって受け入れられており、貴社の製品が必要な基準と規制を確実に満たしていることを保証します。 GTG グループの子会社は、IECEE、UL、A2LA、NVLAP、ITS (Intertek)、KTC、TÜV、Eurofins、CNAS、CMA、CQC を含む国内および国際的な認証機関によって認定されています。当社の認定は、業界基準を満たす高品質の試験サービスを提供するという当社の取り組みの証です。すべての認定書類を確認してください このページ

GTG Group accredited laboratory have more than 13 years of experience in IoT products testing for the global market and have helped thousands of businesses achieve PSTI certification. Experts we hired are all with deep industry expertise and extensive technical knowledge that can help you avoid common mistakes.

Furthermore, our facilities are with enough space to perform every type of test separately and have room for all your equipment as well as plenty of workspace around it. GTG Group covers a testing area of 30,000 square meters and have more cyber security testing labs, safety testing labs, EMC testing labs, RF testing labs, energy efficiency testing labs, performance testing labs, durability testing labs and environmental testing labs than our peers.

さらに、当社の標準化および正規化されたテストプロセスにより、正確で信頼性の高いテスト結果を短期間で提供できます。そのため、当社の納期は業界最速の部類に入り、お客様が遅延なく製品を市場に投入できるようになります。

GTG グループは最新の試験装置に多額の投資を行っており、試験方法が正確で信頼できるものであることを保証するために厳格な品質管理プロセスを導入しています。さらに、研究所は定期的に機器をアップグレードして、常に最先端の技術を維持しています。

私たちは、製品はそれぞれ異なり、製品開発に関してはコストが重要な要素であることを理解しています。 GTG グループは、品質に妥協することなく、手頃な価格のテスト ソリューションを提供するよう努めています。当社の専門家チームはお客様と緊密に連携して、お客様の製品固有のニーズを理解し、お客様の要件を満たし、規制基準への準拠を保証するテスト ソリューションを設計します。これは、必要のないサービスに料金を支払うことなく、必要な検査を受けることができ、クライアントが常にお金に見合った最高の価値を確実に得られることを意味します。

また、設計コストを削減し市場投入を加速するために、プロセスの早い段階で潜在的な設計上の欠陥を検出して解決するのに役立つ、無料の事前準拠テスト サービスも提供できます。私たちはリスクや義務を負わないことを約束します。

無料見積もりを入手する準備はできていますか?

当社では、テストおよび認証サービスを競争力のある価格で提供しています。また、当社のチームは、一般的な質問や、コンプライアンステスト/認証に関する技術的な議論にいつでも対応します。短いフォームにご記入の上、GTG グループの専門家にご相談ください。
助けが必要ですか、それとも質問がありますか?

規格の解釈、規格の適用性、または国固有の要件に関する製品のテストと認証について質問がありますか?

あなたの製品にどのような規格が適用されるかわからないですか?話しましょう!当社の専門家は 24 時間年中無休で待機しています。

認定

当社の包括的なテスト範囲、当社がカバーする基準、および完全な認定については、こちらをご覧ください。

無料見積もりを入手する準備はできていますか?

当社はテストおよび認証サービスを競争力のある価格で提供しています。また、当社のチームは、一般的な質問や、コンプライアンステスト/認証に関する技術的な議論にいつでも対応します。

お問い合わせ 0086-18188898539 で当社チームにご相談いただくか、 無料お見積り 以下の短いフォームにご記入ください。
入手する 無料お見積り 数分で!

GTG グループは、13 年間にわたり、国際的な承認を得て、何千もの組織が世界市場にアクセスできるよう支援してきました。

© 2012-2024 GTG グループ。無断転載を禁じます。

© 2012-2024 GTG グループ。無断転載を禁じます。