Die Beispieldokumente und Projektpläne sind bewusst nur auf Englisch veröffentlicht: Sie sind Vorlagen zum Übernehmen, und eine Übersetzung wäre nicht die Fassung, mit der Sie am Ende arbeiten.
Fiktives Beispiel. Die ACME Embedded GmbH, ihre Produkte, Nachweise und Dokument-IDs sind zur Veranschaulichung erfunden. Nutzen Sie das als strukturelles Vorbild, nicht als unverändert zu übernehmende Vorlage — und nicht als Rechtsberatung.
PSM-LST-001 — Product & Support Register
| Document ID | PSM-LST-001, rev. 7 (living register) |
| Owner | Product Manager, with the Vulnerability Manager (VM) for branch data |
| Approved by | Managing Director — each change to a published end date |
| Reference | CRA Art. 13(8) (support period), Annex I Part II items 2, 7, 8; SDL-STD-022 §1.3, §1.5, §2.4; PSM-PROC-002, PSM-PROC-003 |
| Applies to | Every ACME product with digital elements placed on the market, from first placement until 10 years after the last unit shipped |
| Review | Monthly by the Product Manager; end dates reviewed in the management review |
1. What this register is for
Three questions have to be answerable in minutes, not days: which products are still in support, which firmware branches still receive security fixes, and which versions is a given advisory about. Every one of them is a lookup, and none of them can be reconstructed from the codebase.
This register is therefore the single source of truth for:
- the published support end date per product and hardware revision (SDL-STD-022 §1.3);
- the branches that receive security updates (SDL-STD-022 §2.4);
- the scope of "affected versions" in triage (PSM-PROC-003 P2.1) and in advisories (P4.2);
- the population that must be reached when a vulnerability is actively exploited (Art. 14(8)).
§2 is published as the public support matrix; §3 and §4 are internal.
2. Support matrix (published excerpt)
Support end dates are stated as month/year and are binding. Extensions never shorten a published date (SDL-STD-022 §1.4). Units placed on the market later inherit the end date of their hardware revision (§1.5).
| Product | HW revision | Line | First placed on market | Baseline at placement | Published support end |
|---|---|---|---|---|---|
| SensorNode S200-AP | rev B | Industrial | 2023-05 | 5 years → 2028-05 | 2030-05 (extended) |
| SensorNode S200-AP | rev C | Industrial | 2024-11 | 5 years → 2029-11 | 2030-05 (extended) |
| SensorNode S200-AP | rev D | Industrial | 2026-02 | 7 years | 2033-02 |
| Gateway G50 | rev A | Industrial | 2026-08 | 7 years | 2033-08 |
| ServiceTool commissioning app | — | Accessory | 2024-09 | 5 years | 2029-09 |
| SensorNode S300 | rev A | Industrial | planned 2027-04 | 7 years | planned 2034-04 |
Note on the S200-AP extension. Revisions B and C were placed on the market under SDL-STD-022 rev. 1.0, whose default was five years. When rev. 2.0 raised the industrial default to seven years, the Managing Director extended the existing revisions to a single aligned date (2030-05) rather than leaving three end dates in the field. The original baselines are kept in this table because the technical documentation of those units states them, and a support matrix that quietly overwrites history cannot be reconciled against the documents shipped with the product.
Placement responsibility. The S200-AP is placed on the EU market by ACME Embedded Asia Pte. Ltd. and carries an EU authorised representative (REG-REC-019). The obligations in this register apply unchanged; only the placing entity differs.
3. Supported branches (internal)
Minimum per SDL-STD-022 §2.4: the latest release branch, plus any branch declared long-term in a customer contract. A branch not listed here receives no security fixes, and users on it are directed to the free upgrade path.
| Product | Branch | Role | Security fixes until | Note |
|---|---|---|---|---|
| SensorNode S200-AP | 3.5.x | Current release | 2030-05 | Feature development |
| SensorNode S200-AP | 3.4.x | Long-term, security-only | 2028-12 | Contractual LTS for two customers; PATCH releases only |
| SensorNode S200-AP | 3.3.x | Retired | — | End-of-life 2026-03; upgrade path to 3.5.x published |
| Gateway G50 | 1.0.x | Current release | 2033-08 | Single branch until 1.1 |
| ServiceTool | 2.3.x | Current release | 2029-09 | Companion tool; certificate pinning per SDL-STD-022 §3(2) |
| SensorNode S300 | — | Not yet released | — | Branch created at release gate |
A fix for a vulnerability affecting both 3.5.x and 3.4.x is developed on both (PSM-PROC-003 P3.2). Two branches is a deliberate ceiling: each additional long-term branch is a multiplier on every future security release, and is only opened where a contract requires it.
4. Per-product references (internal)
| Product | Risk assessment | Threat model | Release dossier | Latest advisory |
|---|---|---|---|---|
| SensorNode S200-AP | SEC-RA-S200 v2.1 | SEC-TM-S200 | REL-DOS-2025-014 (3.4.0), REL-DOS-2026-003 (3.4.2) | ACME-SA-2026-004 |
| Gateway G50 | SEC-RA-G50 v1.0 | SEC-TM-G50 | REL-DOS-2026-007 (1.0.0) | — |
| ServiceTool | SEC-RA-ST v1.2 | — (no device attack surface) | REL-DOS-2024-011 | — |
| SensorNode S300 | SEC-RA-S300 v0.1 | SEC-TM-S300 | — (in development) | — |
5. Maintenance rules
- A product enters this register at the release gate (SDL-PROC-001 #3.7), not at first shipment. A product in the field but not in the register is a product nobody is monitoring.
- A new hardware revision is a new row. Revisions differ in components, and therefore in which advisories apply to them.
- End dates change only by MD decision, and only upward. Every change is recorded in §7.
- Branch changes are the VM's, because triage scope depends on them; retiring a branch requires a published upgrade path first.
- End of support is executed from this register: the 12-month advance announcement, the final security advisory, and the product-page statement that updates have ceased (SDL-STD-022 §1.4, SDL-PROC-001 #4.7).
- The register is reconciled against the published support pages monthly. A mismatch between what this table says and what a customer can read is a finding, and the published page wins until corrected.
6. Records
This register is itself a quality record. Superseded revisions are retained — an advisory published in 2027 must be verifiable against the branch and support data that were in force when it was written.
7. Revision history
| Rev | Date | Change | Approved |
|---|---|---|---|
| 5 | 2026-02-20 | S200-AP rev D added (7-year baseline) | MD |
| 6 | 2026-07-29 | S200-AP rev B and C extended to 2030-05 following SDL-STD-022 rev. 2.0; 3.3.x recorded as retired | MD |
| 7 | 2026-08-07 | Gateway G50 rev A added at placement; S300 planned row added; per-product reference table introduced | MD |
