Enterprise IT security protects a company's own infrastructure and is typically governed by an ISMS based on ISO/IEC 27001. Product security, by contrast, protects the product in the field – in the customer's environment, often with attackers having physical access, and over lifetimes that far exceed typical IT support cycles. A vulnerability then affects not a single system but the entire installed base, and can lead to safety consequences, recalls or the loss of type approval. Organizationally, responsibility thus shifts from IT operations to product development – with its own management systems (CSMS), development processes (secure development lifecycle) and response structures (PSIRT).
Product Security Across the Entire Lifecycle
Why the security of connected products requires dedicated standards, processes and organizational structures – from ISO/SAE 21434 through IEC 62443 and EN 18031 to the PSIRT.
8practices in the secure development lifecycle under IEC 62443-4-1
4security levels (SL 1 to SL 4) under IEC 62443-4-2
6service areas in the FIRST PSIRT Services Framework v1.1
5years of support period — as a rule, at least (CRA, Art. 13(8))
Product security refers to the security of the products a company develops and sells – not the security of its own IT. Connected vehicles, industrial components and radio equipment face growing regulatory pressure: UN R155/R156 tie type approval to a cybersecurity management system, the RED Delegated Act has made cybersecurity a market-access requirement for internet-connected radio equipment since August 2025, and the Cyber Resilience Act extends this logic to virtually all products with digital elements from 2026/2027. Anyone developing products containing software therefore needs dedicated structures alongside the ISMS: a secure development lifecycle, a PSIRT for handling vulnerabilities, and a robust plan for support periods through to end-of-life.
Regulatory Milestones
From type approval to the CRA reporting obligations — tap a milestone for details.
Jul 2022
UN R155/R156 for New Vehicle Types
Via the General Safety Regulation (EU) 2019/2144, UN R155 and UN R156 have applied in the EU to new vehicle types since July 2022.
Jul 2024
Mandatory for All New Vehicles
Since July 2024 the UNECE regulations apply to all new vehicles — a certified CSMS is a prerequisite for type approval.
Jan 2025
EN 18031 Listed in the Official Journal
The European Commission lists EN 18031-1, -2 and -3 (2024 edition) as harmonized standards — albeit with restrictions, for example where a password can be dispensed with or assured parental controls are missing.
1 Aug 2025
RED Delegated Act Binding
Since 1 August 2025, the cybersecurity requirements of Art. 3(3)(d)–(f) RED have been a binding prerequisite for placing internet-connected radio equipment on the market.
11 Sep 2026
CRA Reporting Obligations under Art. 14
From 11 September 2026, manufacturers must report actively exploited vulnerabilities in stages within 24 hours, 72 hours and 14 days to the CSIRT designated as coordinator and to ENISA.
The Essentials at a Glance
Six topic blocks — tap to expand.
Sector Regulation Compared
Automotive, industrial components and radio equipment — tap a tab for standards and obligations.
- ISO/SAE 21434:2021 defines cybersecurity engineering for road vehicles across the entire lifecycle — its centerpiece is the TARA under Clause 15.
- UN R155 requires a certified cybersecurity management system (CSMS) as a prerequisite for type approval, UN R156 a software update management system (SUMS).
- In the EU, both apply via the General Safety Regulation (EU) 2019/2144 — since July 2022 for new vehicle types and since July 2024 for all new vehicles.
TARACSMSSUMSUN R155UN R156(EU) 2019/2144
- IEC 62443-4-1:2018 describes a secure product development lifecycle in eight practices — explicitly extending to product end-of-life and assessed across four maturity levels.
- IEC 62443-4-2:2019 specifies component requirements for four component types, derived from seven foundational requirements and tiered into security levels SL 1 to SL 4.
- Both parts are increasingly becoming procurement criteria, because operators are specifically asking for evidence and security levels.
Embedded devicesHost devicesNetwork componentsSoftware applicationsFoundational requirementsSL 1 to SL 4Maturity levels
- Delegated Regulation (EU) 2022/30 activates Art. 3(3)(d)–(f) RED — since 1 August 2025 a binding prerequisite for placing internet-connected radio equipment on the market.
- EN 18031-1, -2 and -3 (2024 edition) serve as harmonized standards for network protection, protection of personal data and fraud protection — listed in the Official Journal, albeit with restrictions.
- Where the presumption of conformity does not apply — for example if a password can be dispensed with or assured parental controls are missing — a notified body must be involved.
(EU) 2022/30EN 18031-1EN 18031-2EN 18031-3Presumption of conformityNotified body
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
ISO/SAE 21434:2021 – Road vehicles – Cybersecurity engineering
Engineering standard for cybersecurity across the vehicle lifecycle; defines the TARA methodology (Clause 15) and is regarded as the state of the art for the CSMS under UN R155.
UN Regulation No. 155 – Cyber security and cyber security management system
Binding type-approval regulation for the CSMS; applicable in the EU via Regulation (EU) 2019/2144 since July 2022 for new types and since July 2024 for all new vehicles.
IEC 62443-4-1:2018 / IEC 62443-4-2:2019
Process requirements (eight practices of the secure development lifecycle) and technical component requirements (SL 1–4) for industrial automation components.
Delegierte Verordnung (EU) 2022/30 (RED Delegated Act)
Activates Art. 3(3)(d)–(f) RED, binding since 1 August 2025; presumption of conformity via the EN 18031 series (2024), listed in the Official Journal with restrictions since January 2025.
PSIRT Services Framework Version 1.1
Reference framework for establishing and operating a PSIRT, with six service areas and three organizational models (distributed, centralized, hybrid).
Verordnung (EU) 2024/2847 (Cyber Resilience Act)
Reporting obligations for actively exploited vulnerabilities from 11 September 2026 (Art. 14), main obligations from 11 December 2027, support period as a rule at least five years (Art. 13(8)).
Want to Clarify the Product Security Obligations for Your Portfolio?
In a no-obligation initial consultation, we map out which standards and deadlines apply to your products – from the TARA through IEC 62443 and EN 18031 to building a PSIRT.