Book an Appointment

Product Security Across the Entire Lifecycle

Why the security of connected products requires dedicated standards, processes and organizational structures – from ISO/SAE 21434 through IEC 62443 and EN 18031 to the PSIRT.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

8practices in the secure development lifecycle under IEC 62443-4-1
4security levels (SL 1 to SL 4) under IEC 62443-4-2
6service areas in the FIRST PSIRT Services Framework v1.1
5years of support period — as a rule, at least (CRA, Art. 13(8))

Product security refers to the security of the products a company develops and sells – not the security of its own IT. Connected vehicles, industrial components and radio equipment face growing regulatory pressure: UN R155/R156 tie type approval to a cybersecurity management system, the RED Delegated Act has made cybersecurity a market-access requirement for internet-connected radio equipment since August 2025, and the Cyber Resilience Act extends this logic to virtually all products with digital elements from 2026/2027. Anyone developing products containing software therefore needs dedicated structures alongside the ISMS: a secure development lifecycle, a PSIRT for handling vulnerabilities, and a robust plan for support periods through to end-of-life.

Regulatory Milestones

From type approval to the CRA reporting obligations — tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Sector Regulation Compared

Automotive, industrial components and radio equipment — tap a tab for standards and obligations.

ISO/SAE 21434 · UN R155/R156
  • ISO/SAE 21434:2021 defines cybersecurity engineering for road vehicles across the entire lifecycle — its centerpiece is the TARA under Clause 15.
  • UN R155 requires a certified cybersecurity management system (CSMS) as a prerequisite for type approval, UN R156 a software update management system (SUMS).
  • In the EU, both apply via the General Safety Regulation (EU) 2019/2144 — since July 2022 for new vehicle types and since July 2024 for all new vehicles.
TARACSMSSUMSUN R155UN R156(EU) 2019/2144

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO / SAE International · 2021

ISO/SAE 21434:2021 – Road vehicles – Cybersecurity engineering

Engineering standard for cybersecurity across the vehicle lifecycle; defines the TARA methodology (Clause 15) and is regarded as the state of the art for the CSMS under UN R155.

UNECE · 2021

UN Regulation No. 155 – Cyber security and cyber security management system

Binding type-approval regulation for the CSMS; applicable in the EU via Regulation (EU) 2019/2144 since July 2022 for new types and since July 2024 for all new vehicles.

IEC · 2018/2019

IEC 62443-4-1:2018 / IEC 62443-4-2:2019

Process requirements (eight practices of the secure development lifecycle) and technical component requirements (SL 1–4) for industrial automation components.

Amtsblatt der EU / EUR-Lex · 2022

Delegierte Verordnung (EU) 2022/30 (RED Delegated Act)

Activates Art. 3(3)(d)–(f) RED, binding since 1 August 2025; presumption of conformity via the EN 18031 series (2024), listed in the Official Journal with restrictions since January 2025.

FIRST.org · 2020

PSIRT Services Framework Version 1.1

Reference framework for establishing and operating a PSIRT, with six service areas and three organizational models (distributed, centralized, hybrid).

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/2847 (Cyber Resilience Act)

Reporting obligations for actively exploited vulnerabilities from 11 September 2026 (Art. 14), main obligations from 11 December 2027, support period as a rule at least five years (Art. 13(8)).

Want to Clarify the Product Security Obligations for Your Portfolio?

In a no-obligation initial consultation, we map out which standards and deadlines apply to your products – from the TARA through IEC 62443 and EN 18031 to building a PSIRT.