B

Baroness Lloyd of Effra (Lab)

Speaking in the House of Lords on 19 November 2025

Debate

Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) (Amendment) (No. 2) Regulations 2025

Contribution

I thank both noble Lords for the fact that we find ourselves in agreement on the fundamental principle underlying this SI: common cybersecurity standards that facilitate trade are a good step forward for the UK and for global cybersecurity. I come to some of the questions raised. Regarding how this regime will be enforced, the Office for Product Safety and Standards is the regulator of the PSTI regime. It has a comprehensive set of enforcement powers and can act against any business found to be non-compliant. Only products with a valid, unexpired label, under either the Japanese or the Singaporean scheme, can be made available, and if a product is subsequently found to have a security risk, the enforcement body—the OPSS—can act in line with its published enforcement policy to ensure that consumers are protected from harm. Equally, Japan and Singapore have regulators overseeing their regimes. The Japanese Ministry of Economy, Trade and Industry and the Cyber Security Agency of Singapore are responsible for enforcing their respective labelling schemes. Although the mutual recognition pathway streamlines compliance, it does not remove accountability, and the OPSS will continue to monitor market activity and enforce if it sees any security failures. In addition, the Government will continue to engage with our international partners to ensure that the recognised schemes remain aligned with UK standards. That is part of this proposal. In respect of the EU, ETSI EN 303 645 is the international standard for consumer devices, and EU members follow it. As noble Lords will know, the EU has the CRA, which covers more than the PSTI, some of which has not yet come into effect. We are considering how best to align with that regime, which is quite different in nature. If the standards change fundamentally, both MoUs allow us to disengage, and the SI applies to these specific Japanese and Singaporean standards only. If they change too much, it would be invalid. That should provide some reassurance that these standards are equivalent, there are processes to ensure that they remain equivalent, and we can disengage if we need to. On the question of business impact and how to make the most of it, it is true that the trade corridors for manufactured goods between us and Japan and Singapore are perhaps not the most active. However, the latest figures show that in 2024 approximately £183 million of exports to Japan and £442 million of imports were goods potentially within the scope of PSTI. For Singapore, those figures were £84 million of exports and £88 million of imports. We are keen to publicise and make it clear that these regimes will enable those businesses that can take advantage of them to do so, along with all our normal trade promotion activities. I hope that that addresses the questions raised by noble Lords. To conclude: as we know, we have more connected products than ever. It is very rare to find a UK household that does not own a connected product, and this connectivity brings convenience but also risks. The cyber- security regulatory landscape is evolving and countries around the world, such as Japan and Singapore, are introducing similar regimes. We are keen to keep our leadership in this space by co-operating with like-minded regimes. The draft instrument we have considered today will ensure that the UK remains a global leader in product cybersecurity, while strengthening our position as an attractive destination for digital innovation and trade. We are reducing regulatory burdens and supporting UK businesses to bring compliant products to our market. This is a practical step forward in our mission to drive economic growth and build a more resilient digital economy. It complements efforts to harmonise security standards across other major economies in partnerships with, for example, Brunei, the UAE, Australia, Germany, Finland, South Korea, Canada, Japan, Singapore and Hungary via the global cybersecurity labelling initiative. With forecasts suggesting that the global IoT market will grow to 24.1 billion devices by 2030, generating over £1 trillion of annual revenue, it is more essential than ever that we enhance the security of connected products on a global scale. This is a good step towards achieving this goal. I look forward to working further on this and commend the instrument to the Committee.

More from Baroness Lloyd of Effra (Lab)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.