Selling Connected Devices in the UK: The PSTI Penetration Testing Assurance Buyers Expect

Selling Connected Devices in the UK: The PSTI Penetration Testing Assurance Buyers Expect

By EJN Labs · 30 Jul 2026 · 8 min read

The PSTI product security regime does not mandate penetration testing, but UK retailers, distributors and enterprise buyers increasingly demand independent security assurance before stocking or deploying a connected device. A device penetration test from a CREST-accredited firm evidences your statement of compliance and ETSI EN 303 645 alignment. Typical assessments run 4 to 9 days, £4,800 to £12,600, depending on scope.

Why PSTI product security assurance now decides who stocks your device

PSTI assurance decides who stocks your device because retail buyers, distributors and enterprise procurement teams all ask the same question: can you prove this product meets the PSTI baseline, and what independent testing sits behind that claim? That answer is the difference between a purchase order and a delisting.

The Product Security and Telecommunications Infrastructure (PSTI) product security regime has applied to consumer connectable products sold in the UK since 29 April 2024, and it reaches anyone who manufactures, imports or distributes smart devices.

The regime is enforced by the Office for Product Safety and Standards (OPSS) on behalf of the Department for Science, Innovation and Technology (DSIT), with enforcement notices, recall powers and penalties of up to £10 million or 4 percent of worldwide revenue. Distributors and importers carry their own duties under the Act, which is why they push assurance requirements back up the supply chain to you, the vendor.

What PSTI actually requires, and where testing fits

PSTI is mandatory for in-scope consumer connectable products, which covers most internet-connected and network-connectable consumer devices: smart cameras, wearables, connected appliances, smart locks, routers and hubs, and many IoT products sold into homes. The current security requirements are deliberately narrow.

Within that scope, manufacturers must:

  • Ban universal default passwords. Every unit must ship with a unique password or force the user to set one.
  • Publish a vulnerability disclosure policy with a contact point and expected response timelines.
  • State the minimum period during which the product will receive security updates, and honour it.
  • Produce a statement of compliance that accompanies the product through the supply chain.

Here is the honest position: nothing in the PSTI regime says “you must commission a penetration test”. Product security verification and testing supports compliance rather than being a named legal obligation. What the regime does is create liability for false or unverified claims. If a researcher pulls a hardcoded credential out of your firmware six months after launch, your statement of compliance and update commitments are what OPSS and your trade customers will hold you to. Independent testing is how you know your claims are true before you sign them, and it is the evidence buyers ask for because the underlying standard, ETSI EN 303 645, expects far more than the three baseline requirements.

What buyers expect you to have tested

A connected product is never just the device. Buyers asking for security assurance mean the whole ecosystem a customer touches, across four layers.

The device and its firmware

Hardware and firmware review is where PSTI claims live or die. We extract and analyse firmware for hardcoded credentials, weak update signing, exposed debug interfaces such as UART and JTAG, and insecure storage of keys and personal data. Default-password compliance is verified on the physical unit, not on a datasheet, because factory provisioning is where unique-credential schemes most often break.

Local interfaces and radio

Bluetooth Low Energy pairing, Wi-Fi provisioning flows, Zigbee or proprietary RF, and any local web or API interface the device exposes on the network. Insecure onboarding is one of the most common findings in consumer IoT and one of the easiest for a reviewer at a large retailer to spot in a teardown video.

The companion mobile app

Most connected products are controlled through iOS and Android apps that hold session tokens, device keys and customer data. Mobile application penetration testing covers authentication, local data storage, certificate pinning and the trust relationship between app and device.

The cloud backend and APIs

Device fleets talk to cloud services, and those services are where a single flaw becomes a fleet-wide incident. API penetration testing looks for broken object-level authorisation, where one customer can address another customer’s device, weak device identity, and update-delivery weaknesses. Where your platform runs on AWS, Azure or GCP, cloud penetration testing reviews the configuration behind it.

How a PSTI-aligned device engagement runs

A PSTI-aligned engagement starts with scoping: we ask for the device variants in scope, the firmware version, the radio interfaces present, the companion apps, and the cloud endpoints the fleet uses. From there a well-run product assessment follows a predictable path.

From experience testing connected-product estates, the single biggest scoping decision is whether the cloud API is in or out, because that is usually where the highest-impact findings sit, and vendors who exclude it to save two days often end up commissioning a second engagement.

Testing itself typically runs one to two weeks. You ship us production-representative hardware, provide test accounts for the app and API, and nominate a technical contact. Critical findings are flagged the day we confirm them, not held for the report. The report maps findings to the PSTI security requirements and to ETSI EN 303 645 provisions, so it works both as an engineering fix list and as the assurance artefact trade customers ask for, and a retest window lets fixed issues be verified in an updated report. Our penetration testing checklist walks through how to prepare on your side.

What it costs and how scope drives the price

Device security testing in the UK is priced on effort. Day rates at accredited firms typically run £1,200 to £1,400, and the scope decisions above set the day count. Typical ranges look like this:

ScopeTypical effortTypical cost
Single device plus companion app4 to 6 days£4,800 to £8,400
Device, app and cloud API6 to 9 days£7,200 to £12,600
Full ecosystem or multi-product portfolio10 to 15 days£12,000 to £21,000

Hardware complexity moves the number: multiple radios, custom bootloaders or secure elements take longer than a Wi-Fi-only product on a common chipset. Retesting fixed findings is usually a day or less. For how these figures compare across engagement types, see our guide to penetration testing costs in the UK. For an exact figure against your product, request a scoped quote.

How EJN Labs approaches PSTI product security assurance

EJN Labs is a UK-based, CREST-accredited penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, and all testing is delivered by UK-based testers. For connected-product vendors we scope against the product as shipped: we test the retail unit, its provisioning flow, the companion apps and the cloud APIs together, because that is how an attacker and a retail security reviewer will see it. Findings are mapped to the PSTI security requirements and ETSI EN 303 645 so your compliance, engineering and sales teams each get what they need from one report. We hold prototype hardware and pre-release firmware under strict handling controls, and we retest fixes so the assurance pack you hand a buyer reflects the product you actually ship. If you are comparing suppliers, our guide to choosing the best UK penetration testing provider sets out the questions worth asking.

Frequently Asked Questions

Does the PSTI Act require penetration testing?

No. The PSTI product security regime does not name penetration testing as a legal requirement. It mandates unique passwords, a vulnerability disclosure policy, transparency about security update periods and a statement of compliance, and testing is how manufacturers verify those claims before signing the statement.

Testing is also the independent assurance that retailers, distributors and enterprise buyers increasingly ask for before stocking a connected product.

Which products are in scope of the PSTI product security regime?

Consumer connectable products sold in the UK are in scope: devices that can connect to the internet or to a network, including smart cameras, speakers, wearables, connected appliances, smart locks, routers and most consumer IoT. Manufacturers, importers and distributors each carry duties under the Act.

Some categories are excluded, such as certain vehicles, smart meters and medical devices covered by other regimes.

What does a PSTI-aligned device penetration test cost?

Expect £4,800 to £8,400 for a single device plus companion app, which is usually 4 to 6 days at UK day rates of £1,200 to £1,400. Adding the cloud API takes it to 6 to 9 days, £7,200 to £12,600.

A full ecosystem or multi-product portfolio runs 10 to 15 days, £12,000 to £21,000. Exact pricing depends on hardware complexity and interfaces, so request a scoped quote.

What is the difference between PSTI and ETSI EN 303 645?

PSTI is UK law, enforced by OPSS, and currently mandates three security requirements plus a statement of compliance. ETSI EN 303 645 is the European consumer IoT security standard the UK regime draws on, covering thirteen provision areas including secure storage, secure communication and software integrity.

Buyers often ask for EN 303 645 alignment because it demonstrates security depth beyond the legal minimum.

What evidence should we give retailers and distributors?

Give retailers your statement of compliance, your published vulnerability disclosure policy and your defined security update period at minimum. To win and keep shelf space, most vendors add an independent penetration test report from a CREST-accredited firm covering the device, app and cloud API.

That report should show findings remediated and retested. The full pack answers a buyer’s security questionnaire in one attachment and de-risks their own duties under the Act.

Turn PSTI compliance into a sales asset

Buyers are already asking for security assurance; the vendors who can hand over an independent test report win the listing. Tell us about your device, apps and cloud platform and we will return a fixed scope and price. Get a CREST penetration testing quote from our UK-based team.

Leave a Reply

Your email address will not be published. Required fields are marked *