The EU Cyber Resilience Act, Regulation (EU) 2024/2847, and the UK Product Security and Telecommunications Infrastructure (PSTI) regime both set cybersecurity expectations for connected products, but they are distinct laws in distinct jurisdictions. If you sell in both markets, you have to satisfy each on its own terms. This guide compares them at a high level and flags where UK-specific detail needs checking against the source.
The starting point is simple: the CRA governs products made available on the EU market, while the UK PSTI regime governs relevant connectable products made available in the UK. Placing a product in both markets means meeting both, and you cannot assume that conformity with one carries over to the other.
The CRA is broad. It covers products with digital elements, software and hardware alike, with obligations spanning security by design, vulnerability handling, the SBOM, support periods and conformity documentation, and its main obligations apply from 11 December 2027.
Since 29 April 2024, the UK PSTI product-security regime has required manufacturers of relevant consumer internet-connectable and network-connectable products to prevent easily guessable or universal default passwords, publish vulnerability-reporting information and disclose the minimum security-update period, or state that no updates will be provided.
Despite the different legal machinery, several themes recur across both regimes:
The CRA reaches further. It applies to a wide range of products with digital elements beyond consumer devices, imposes conformity assessment and CE marking, requires an SBOM within the technical documentation, and carries its own incident and vulnerability reporting timeline under Article 14. PSTI is principally limited to physical consumer internet-connectable and network-connectable products supplied in the UK, whereas the CRA covers a substantially wider range of connected hardware and software products, including B2B software, separately supplied components and qualifying remote data-processing solutions, made available on the EU market. PSTI does not create a CE-marking requirement: manufacturers must prepare a prescribed statement of compliance to accompany each in-scope product, although other product legislation may independently require CE or UKCA marking.
CRANIS2 is built for the EU Cyber Resilience Act, not the UK PSTI regime. It structures the SBOM, vulnerability handling, support-period and conformity evidence you need to sell software into the EU market. Some of that practice, default-credential hygiene, disclosure routes and update transparency, will look familiar if you also fall under PSTI, but that overlap is incidental: CRANIS2 does not produce a PSTI statement of compliance or manage a UK PSTI position. This page compares the two for orientation. Create an account to start on your CRA evidence.
No. They are separate laws in separate jurisdictions. Meeting the UK PSTI requirements does not establish CRA conformity, and if you place products on the EU market you must meet the CRA on its own terms.
The CRA covers products with digital elements broadly, including software and non-consumer hardware, whereas PSTI is principally limited to physical consumer internet-connectable and network-connectable products supplied in the UK, while the CRA covers a substantially wider range of connected hardware and software products, including B2B software, separately supplied components and qualifying remote data-processing solutions, made available on the EU market.
CE marking is a CRA conformity mechanism for the EU market. PSTI does not create a CE-marking requirement: manufacturers must prepare a prescribed statement of compliance to accompany each in-scope product, although other product legislation may independently require CE or UKCA marking.
Related guides: Does the CRA apply to my product? and CRA vs NIS2: how they differ and overlap.