Book an Appointment

Product Security Across the Entire Lifecycle

Why the security of connected products requires dedicated standards, processes and organizational structures – from ISO/SAE 21434 through IEC 62443 and EN 18031 to the PSIRT.

Product security refers to the security of the products a company develops and sells – not the security of its own IT. Connected vehicles, industrial components and radio equipment face growing regulatory pressure: UN R155/R156 tie type approval to a cybersecurity management system, the RED Delegated Act has made cybersecurity a market-access requirement for internet-connected radio equipment since August 2025, and the Cyber Resilience Act extends this logic to virtually all products with digital elements from 2026/2027. Anyone developing products containing software therefore needs dedicated structures alongside the ISMS: a secure development lifecycle, a PSIRT for handling vulnerabilities, and a robust plan for support periods through to end-of-life.

The Essentials at a Glance

01

What Sets Product Security Apart from Enterprise IT Security

Enterprise IT security protects a company's own infrastructure and is typically governed by an ISMS based on ISO/IEC 27001. Product security, by contrast, protects the product in the field – in the customer's environment, often with attackers having physical access, and over lifetimes that far exceed typical IT support cycles. A vulnerability then affects not a single system but the entire installed base, and can lead to safety consequences, recalls or the loss of type approval. Organizationally, responsibility thus shifts from IT operations to product development – with its own management systems (CSMS), development processes (secure development lifecycle) and response structures (PSIRT).

02

Automotive: ISO/SAE 21434, UN R155 and UN R156

ISO/SAE 21434:2021 defines cybersecurity engineering for road vehicles across the entire lifecycle – from the concept phase through to decommissioning. Its centerpiece is the Threat Analysis and Risk Assessment (TARA) under Clause 15: from asset identification through threat scenarios and damage and attack path analysis to the risk treatment decision. The UNECE regulations make the topic binding: UN R155 requires a certified cybersecurity management system (CSMS) as a prerequisite for type approval, UN R156 a software update management system (SUMS). In the EU, both apply via the General Safety Regulation (EU) 2019/2144 – since July 2022 for new vehicle types and since July 2024 for all new vehicles; ISO/SAE 21434 is regarded as the recognized state of the art for implementing the CSMS requirements.

03

Industrial Components: IEC 62443-4-1 and 62443-4-2

For components of industrial automation systems, the IEC 62443 series separates process and product requirements. IEC 62443-4-1:2018 describes a secure product development lifecycle in eight practices – from security management and requirements specification through secure design and implementation to verification, defect and patch management, and security guidelines for users – which explicitly extends to product end-of-life and is assessed across four maturity levels. IEC 62443-4-2:2019 specifies the technical requirements for the components themselves: component requirements for four component types (embedded devices, host devices, network components, software applications), derived from seven foundational requirements and tiered into security levels SL 1 to SL 4. For manufacturers, both parts are increasingly becoming procurement criteria, because operators are specifically asking for evidence and security levels.

04

Radio Equipment: RED Delegated Act and the EN 18031 Series

Delegated Regulation (EU) 2022/30 activates the cybersecurity requirements of Art. 3(3)(d)–(f) of the Radio Equipment Directive (RED); since 1 August 2025 they have been a binding prerequisite for placing internet-connected radio equipment on the market. EN 18031-1, -2 and -3 (2024 edition) serve as harmonized standards for network protection, protection of personal data and fraud protection; the European Commission listed them in the Official Journal in January 2025 – albeit with restrictions. If, for example, a product allows a password to be dispensed with (clauses 6.2.5.1/6.2.5.2), or if assured parental controls are missing under EN 18031-2 (clauses 6.1.3–6.1.6), the presumption of conformity does not apply and a notified body must be involved. Manufacturers should therefore review these restrictions early in the conformity assessment procedure.

05

PSIRT: An Organized Response to Product Vulnerabilities

A Product Security Incident Response Team (PSIRT) handles vulnerabilities in a company's own products – unlike a CSIRT, which deals with incidents in the company's own infrastructure. The PSIRT Services Framework v1.1 from FIRST (2020) structures the tasks into six service areas – Stakeholder Ecosystem Management, Vulnerability Discovery, Triage, Remediation, Disclosure, and Training and Education – and describes distributed, centralized and hybrid organizational models. At the latest with the Cyber Resilience Act (Regulation (EU) 2024/2847), this capability becomes mandatory: from 11 September 2026, manufacturers must report actively exploited vulnerabilities under Art. 14 in stages within 24 hours, 72 hours and 14 days to the CSIRT designated as coordinator and to ENISA; for severe incidents the same staging applies, with one month for the final report. Without well-rehearsed PSIRT processes, these deadlines are barely achievable.

06

Security Across the Product Lifecycle – Through to End-of-Life

Product security does not end at market launch: vulnerability management, security updates and monitoring must be planned and funded across the entire period of use. The Cyber Resilience Act requires a support period that reflects the expected product lifetime and is, as a rule, at least five years (Art. 13(8)); security updates must be provided free of charge, and the support period must be made transparent before purchase. Industry standards also factor in end-of-life: IEC 62443-4-1 explicitly includes it in the development lifecycle, and UN R156 requires managed software updates over the vehicle's lifetime. An orderly end-of-life comprises early announcement of the end of support, final security advisories, and migration paths for existing customers.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO / SAE International · 2021

ISO/SAE 21434:2021 – Road vehicles – Cybersecurity engineering

Engineering standard for cybersecurity across the vehicle lifecycle; defines the TARA methodology (Clause 15) and is regarded as the state of the art for the CSMS under UN R155.

UNECE · 2021

UN Regulation No. 155 – Cyber security and cyber security management system

Binding type-approval regulation for the CSMS; applicable in the EU via Regulation (EU) 2019/2144 since July 2022 for new types and since July 2024 for all new vehicles.

IEC · 2018/2019

IEC 62443-4-1:2018 / IEC 62443-4-2:2019

Process requirements (eight practices of the secure development lifecycle) and technical component requirements (SL 1–4) for industrial automation components.

Amtsblatt der EU / EUR-Lex · 2022

Delegierte Verordnung (EU) 2022/30 (RED Delegated Act)

Activates Art. 3(3)(d)–(f) RED, binding since 1 August 2025; presumption of conformity via the EN 18031 series (2024), listed in the Official Journal with restrictions since January 2025.

FIRST.org · 2020

PSIRT Services Framework Version 1.1

Reference framework for establishing and operating a PSIRT, with six service areas and three organizational models (distributed, centralized, hybrid).

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/2847 (Cyber Resilience Act)

Reporting obligations for actively exploited vulnerabilities from 11 September 2026 (Art. 14), main obligations from 11 December 2027, support period as a rule at least five years (Art. 13(8)).

Want to Clarify the Product Security Obligations for Your Portfolio?

In a no-obligation initial consultation, we map out which standards and deadlines apply to your products – from the TARA through IEC 62443 and EN 18031 to building a PSIRT.