Contribution
My Lords, these draft regulations will be made under powers provided by the Product Security and Telecommunications Infrastructure Act 2022. The PSTI regulatory regime is comprised of Part 1 of the 2022 Act together with the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, which I will refer to as the 2023 regulations.
This world-leading regulatory regime came into force on 29 April 2024. It better protects consumers, businesses and the wider economy from the harms associated with cyberattacks on consumer connectable products. The law now requires these products that are made available to customers in the UK to meet baseline cybersecurity requirements. This is a world first, and a world-leading regulatory regime, with many other countries now mandating similar requirements based on the world-leading European Telecommunications Standards Institute standard which the UK helped create.
For instance, manufacturers cannot use universal default or easily guessable default passwords, such as “admin123”; this reduces one of the most commonly exploited vulnerabilities in connectable products. Manufacturers must also ensure that they are transparent about the minimum length of time for which they will provide much-needed security updates that patch these vulnerabilities. They must also publish information on how to report security vulnerabilities directly to them and provide status updates about the reported issues. Importers also have important duties they must comply with, as they play an important role in ensuring that more vulnerable products are not imported into the country. The same applies for distributors, as they are often the last line of defence against non-compliant products making their way to consumers.
Subject to the approval of this Committee, this draft instrument will add three new categories of products to the list of excepted products at Schedule 3 to the 2023 regulations, as well as making a correction to those regulations. In their 2020 call for views for this regime, the Government indicated that products would be excepted from the product security regime if it is deemed inappropriate to include them prior to further investigation, they are already covered by robust legislation or they will be covered by future legislation that is particularly relevant to that product category.
DSIT committed to except certain categories of automotive vehicles on 29 April 2023. The Department for Transport has been working at an international level to agree regulations setting cybersecurity requirements for vehicles. This would allow the cybersecurity of these products to be addressed by requirements that are specific to the sector and their functionality. The Department for Transport intends to mandate UN Regulation 155 on cybersecurity and cybersecurity management systems in Great Britain for all new cars, vans, buses, trucks and motorbikes. Its requirements are more appropriate, as it was created in response to the expanding capability and connectivity of vehicle systems.
A consultation is expected to be published with a proposal to lay, via a negative SI, Article 57 GB approval of assimilated EU Regulation 2018/858 in the first half of this year, with the requirements beginning to take effect from February 2026. Additionally, the automotive industry and its supply chain are already beginning to comply with UN Regulation 155, as it has been mandatory for new types of passenger and goods vehicles in the European Union from July 2022. To avoid dual regulation and unintentionally placing undue burden on the automotive industry and trade, the Government are seeking to except specific vehicle categories from the scope of this regime.
First, through the amendment made by Regulation 4, this draft instrument seeks to except consumer-connectable products that fall in scope of Regulation (EU) 2018/858, Regulation (EU) 168/2013 and Regulation (EU) 167/2013 from the scope of the PSTI product security regulatory regime in Great Britain. The consumer connectable products in scope of these regulations include cars, vans, buses, motorcycles, mopeds, quadbikes and tractors. These products are already excepted from the PSTI product security regulatory regime when they are made available for supply in Northern Ireland, as a result of the Windsor Framework.
Secondly, the amendment made by Regulation 3 will correct a minor error in the current language. Adding “period” ensures that the original intent of the paragraph is preserved.
The UK’s product security regulatory regime is world-leading. It cements our position as a world leader in consumer internet-of-things security. This measure will ensure that the regime works as intended and that the security of vehicles can be addressed through appropriate sector-specific regulations, and it will remove unnecessary burdens from the vehicles sector.
I hope the Committee will recognise the importance of excepting these additional products from the scope of the PSTI product security regulatory regime. I commend the regulations to the Committee.