TRA Studio
Alle Beispieldokumente

Die Beispieldokumente und Projektpläne sind bewusst nur auf Englisch veröffentlicht: Sie sind Vorlagen zum Übernehmen, und eine Übersetzung wäre nicht die Fassung, mit der Sie am Ende arbeiten.

Fiktives Beispiel. Die ACME Embedded GmbH, ihre Produkte, Nachweise und Dokument-IDs sind zur Veranschaulichung erfunden. Nutzen Sie das als strukturelles Vorbild, nicht als unverändert zu übernehmende Vorlage — und nicht als Rechtsberatung.

PSM-LST-001 — Product & Support Register

Document IDPSM-LST-001, rev. 7 (living register)
OwnerProduct Manager, with the Vulnerability Manager (VM) for branch data
Approved byManaging Director — each change to a published end date
ReferenceCRA Art. 13(8) (support period), Annex I Part II items 2, 7, 8; SDL-STD-022 §1.3, §1.5, §2.4; PSM-PROC-002, PSM-PROC-003
Applies toEvery ACME product with digital elements placed on the market, from first placement until 10 years after the last unit shipped
ReviewMonthly by the Product Manager; end dates reviewed in the management review

1. What this register is for

Three questions have to be answerable in minutes, not days: which products are still in support, which firmware branches still receive security fixes, and which versions is a given advisory about. Every one of them is a lookup, and none of them can be reconstructed from the codebase.

This register is therefore the single source of truth for:

  • the published support end date per product and hardware revision (SDL-STD-022 §1.3);
  • the branches that receive security updates (SDL-STD-022 §2.4);
  • the scope of "affected versions" in triage (PSM-PROC-003 P2.1) and in advisories (P4.2);
  • the population that must be reached when a vulnerability is actively exploited (Art. 14(8)).

§2 is published as the public support matrix; §3 and §4 are internal.


2. Support matrix (published excerpt)

Support end dates are stated as month/year and are binding. Extensions never shorten a published date (SDL-STD-022 §1.4). Units placed on the market later inherit the end date of their hardware revision (§1.5).

ProductHW revisionLineFirst placed on marketBaseline at placementPublished support end
SensorNode S200-APrev BIndustrial2023-055 years → 2028-052030-05 (extended)
SensorNode S200-APrev CIndustrial2024-115 years → 2029-112030-05 (extended)
SensorNode S200-APrev DIndustrial2026-027 years2033-02
Gateway G50rev AIndustrial2026-087 years2033-08
ServiceTool commissioning appAccessory2024-095 years2029-09
SensorNode S300rev AIndustrialplanned 2027-047 yearsplanned 2034-04

Note on the S200-AP extension. Revisions B and C were placed on the market under SDL-STD-022 rev. 1.0, whose default was five years. When rev. 2.0 raised the industrial default to seven years, the Managing Director extended the existing revisions to a single aligned date (2030-05) rather than leaving three end dates in the field. The original baselines are kept in this table because the technical documentation of those units states them, and a support matrix that quietly overwrites history cannot be reconciled against the documents shipped with the product.

Placement responsibility. The S200-AP is placed on the EU market by ACME Embedded Asia Pte. Ltd. and carries an EU authorised representative (REG-REC-019). The obligations in this register apply unchanged; only the placing entity differs.


3. Supported branches (internal)

Minimum per SDL-STD-022 §2.4: the latest release branch, plus any branch declared long-term in a customer contract. A branch not listed here receives no security fixes, and users on it are directed to the free upgrade path.

ProductBranchRoleSecurity fixes untilNote
SensorNode S200-AP3.5.xCurrent release2030-05Feature development
SensorNode S200-AP3.4.xLong-term, security-only2028-12Contractual LTS for two customers; PATCH releases only
SensorNode S200-AP3.3.xRetiredEnd-of-life 2026-03; upgrade path to 3.5.x published
Gateway G501.0.xCurrent release2033-08Single branch until 1.1
ServiceTool2.3.xCurrent release2029-09Companion tool; certificate pinning per SDL-STD-022 §3(2)
SensorNode S300Not yet releasedBranch created at release gate

A fix for a vulnerability affecting both 3.5.x and 3.4.x is developed on both (PSM-PROC-003 P3.2). Two branches is a deliberate ceiling: each additional long-term branch is a multiplier on every future security release, and is only opened where a contract requires it.


4. Per-product references (internal)

ProductRisk assessmentThreat modelRelease dossierLatest advisory
SensorNode S200-APSEC-RA-S200 v2.1SEC-TM-S200REL-DOS-2025-014 (3.4.0), REL-DOS-2026-003 (3.4.2)ACME-SA-2026-004
Gateway G50SEC-RA-G50 v1.0SEC-TM-G50REL-DOS-2026-007 (1.0.0)
ServiceToolSEC-RA-ST v1.2— (no device attack surface)REL-DOS-2024-011
SensorNode S300SEC-RA-S300 v0.1SEC-TM-S300— (in development)

5. Maintenance rules

  1. A product enters this register at the release gate (SDL-PROC-001 #3.7), not at first shipment. A product in the field but not in the register is a product nobody is monitoring.
  2. A new hardware revision is a new row. Revisions differ in components, and therefore in which advisories apply to them.
  3. End dates change only by MD decision, and only upward. Every change is recorded in §7.
  4. Branch changes are the VM's, because triage scope depends on them; retiring a branch requires a published upgrade path first.
  5. End of support is executed from this register: the 12-month advance announcement, the final security advisory, and the product-page statement that updates have ceased (SDL-STD-022 §1.4, SDL-PROC-001 #4.7).
  6. The register is reconciled against the published support pages monthly. A mismatch between what this table says and what a customer can read is a finding, and the published page wins until corrected.

6. Records

This register is itself a quality record. Superseded revisions are retained — an advisory published in 2027 must be verifiable against the branch and support data that were in force when it was written.

7. Revision history

RevDateChangeApproved
52026-02-20S200-AP rev D added (7-year baseline)MD
62026-07-29S200-AP rev B and C extended to 2030-05 following SDL-STD-022 rev. 2.0; 3.3.x recorded as retiredMD
72026-08-07Gateway G50 rev A added at placement; S300 planned row added; per-product reference table introducedMD