Psirt-services
Secure Operation - Vulnerability Management

PSIRT
as a Managed Service.

Building your own Product Security Incident Response Team (PSIRT) is demanding, but the real risk only becomes visible in an actual incident: without established processes, response to reported vulnerabilities is delayed, deadlines are missed, and responsibilities remain unclear. NewTec takes over your PSIRT as a managed service, with proven workflows, clear escalation paths, and standards-compliant response when it matters most.

Secure Operation

Vulnerability Management. From Basic to Full Service.

The Cyber Resilience Act (CRA), NIS2, and industry specific standards such as IEC 62443 require manufacturers of connected products to ensure product security throughout the entire product lifecycle, including monitoring, assessing, and reporting vulnerabilities, in some cases within tight legal deadlines.

Building an internal PSIRT means establishing your own processes, trained staff, round-the-clock availability, and solid documentation for authorities and customers, from a complete SBOM (Software Bill of Materials) of your products to evidence in the event of an incident. Not every company can or wants to maintain this structure on an ongoing basis. NewTec offers PSIRT functions as a managed service: you get a ready-to-deploy team, established processes, and standards-compliant documentation, without the effort of building it yourself.

In detail

What our
PSIRT services cover.

With PSIRT as a managed service, you are immediately capable of action: established workflows, standards compliant response, and full scalability.

Vulnerability Monitoring (Third-party Components & In House Development)

Classic vulnerability management often amounts to occasional scans or manual spot checks. Our service runs continuously: a daily automated comparison of your deployed components, both purchased assemblies and in-house developments based on your SBOM, against the relevant vulnerability databases NVD, EUVD, and GHSA, as well as manufacturer advisories. Every match is checked for actual relevance, since not every reported vulnerability affects your specific version or configuration. Assessment follows CVSS (Common Vulnerability Scoring System) and is documented as a machine-readable VEX statement (affected, not_affected, fixed, under_investigation), so you learn not just that a vulnerability exists, but whether and how it affects your specific product. This reduces false alarms and creates the documented basis required by CRA and NIS2. We also keep an eye on manufacturer discontinuations and end-of-support.

Vulnerability Reporting

Incoming reports are triaged by our security team on call: first, we assess whether a reportable, actively exploited vulnerability or a severe incident affecting the security of the product is present (Article 14(3) and (5) CRA). Where a CRA reporting obligation applies, we issue a timely early warning within 24 hours and the notification with details within 72 hours to the relevant CSIRT and ENISA, and we prepare the final report within the legal deadline. Even where no reporting obligation applies, you receive a documented assessment. Every report is tracked through to the final report.

Mitigation Planning

Once a vulnerability becomes known, a compliant mitigation plan is created within 14 days, in line with CRA requirements. This includes a technical analysis of the vulnerability in the context of the affected product, an assessment of the impact on security and operability, and the identification of practical measures such as configuration changes, workarounds, or organisational steps. We also support publication to authorities and affected users and maintain complete documentation to prove deadlines were met.

Threat Analysis and Risk Assessment

The systematic threat and risk analysis for OT systems begins with the Initial Risk Assessment (IRA): capturing the system environment, an initial risk profile, and identifying critical assets. The subsequent Detailed Risk Assessment (DRA) involves an in depth threat and vulnerability analysis assessed by likelihood and impact, from which technical and organisational protective measures are derived. An annual review of the risk situation and validation of existing measures ensures you continuously meet regulatory requirements such as NIS2 and IEC 62443.

HW/SW Maintenance

Based on identified vulnerabilities and agreed mitigation plans, we provide tested, security relevant updates. We analyse the vulnerability and identify suitable updates for firmware, software, or configuration, before documenting the tested and approved security updates, including version and compatibility details. Technical guidance for safe implementation and a fallback option, along with support integrating updates into your rollout processes, round out the service.

Security Update Management

Technical delivery of updates to implement planned mitigation measures takes place regardless of who ultimately deploys the update: we select suitable patches, firmware, or configuration changes, check compatibility and version status, and document everything, including integration notes and an optional fallback option. The clear separation between analysis, planning, and delivery ensures traceability regarding the availability and currency of your security updates, in line with CRA requirements.

Tailored to fit

PSIRT Service Packages for Your Needs

You choose the depth, we deliver the matching package, or put together a custom one for your needs.

Work-PackageWP Basic
Work-PackageWP Monitoring & ReportingRecommended
Work-PackageWP Full Service
Vulnerability Monitoring
Vulnerability Reporting
Mitigation Planning
Threat Analysis and Risk Assessment
HW/SW Maintenance
Security Update Management
Work-Package

WP Basic

  • Vulnerability Monitoring
  • Vulnerability Reporting
  • Mitigation Planning
  • Threat Analysis and Risk Assessment
  • HW/SW Maintenance
  • Security Update Management
Work-Package

WP Monitoring & Reporting

Recommended
  • Vulnerability Monitoring
  • Vulnerability Reporting
  • Mitigation Planning
  • Threat Analysis and Risk Assessment
  • HW/SW Maintenance
  • Security Update Management
Work-Package

WP Full Service

  • Vulnerability Monitoring
  • Vulnerability Reporting
  • Mitigation Planning
  • Threat Analysis and Risk Assessment
  • HW/SW Maintenance
  • Security Update Management
PSIRT_Team

Who should consider our PSIRT Service.

Building your own PSIRT ties up personnel, processes, and specialiced expertise that many companies cannot or do not want to maintain long term. NewTec already runs vulnerability management and incident response for customers in safety-critical industries, with established processes that are ready to use immediately rather than needing to be built from scratch. As a Product Security Incident Response Team, we handle monitoring, assessment, and reporting of your vulnerabilities in compliance with CRA, NIS2, and IEC 62443, with full transparency through complete, audit ready documentation. The overview below shows which company situations our PSIRT is especially well suited for as an outsourced service.

  • ✓Manufacturers of connected products in regulated industries (industrial, automotive, medical, railway, avionics, off highway) without their own PSIRT
  • ✓Companies that need to implement CRA and NIS2 reporting obligations for the first time in a structured way
  • ✓Companies with a growing product portfolio that exceeds the capacity of internal monitoring
  • ✓Companies in a transition phase, building their own PSIRT while wanting to secure operations in the meantime
  • ✓OT and embedded manufacturers without their own round the clock security resources
„If you already have your own SOC or CSIRT, our PSIRT service integrates seamlessly into your existing processes. It complements these structures by adding the product perspective: while a SOC/CSIRT responds to incidents in your own IT infrastructure, our PSIRT handles vulnerabilities and incidents in your products out in the field. Technical integration happens through your existing reporting channels (CVD portal, ticketing/vulnerability management system), with no parallel tool landscape required. Results can be consolidated into shared reporting for your management.“
At a Glance

Your benefits with our PSIRT Services

You benefit from our experience with CRA, NIS2, and IEC 62443 requirements without having to build and maintain that expertise yourself, while retaining full transparency through complete, audit-ready documentation.

Ready to go immediately

Our in house developed toolchain makes our team maximally efficient from day one.

Specialized security expertise

Without tying up your own staff

Scales with your product portfolio

From a single product to full service

Audit ready, complete documentation

Of all reports and assessments

Clear separation

Between analysis & reporting and technical implementation. Your development team stays focused.

PSIRT as a Managed Service

How our collaboration works.

1.
Onboarding
We capture your product portfolio and the components you use (including your SBOM, where available), and align the technical integration, for example by routing your existing reporting portal/CVD channel to our on call team.
2.
Analysis
We assess your current maturity level, define the relevant product lines, and select the right scope of service, from basic monitoring to full service.
3.
Operations
Ongoing operations: daily monitoring, triage of incoming reports, timely reporting to CSIRT/ENISA where required, mitigation planning, and regular reporting.
4.
Handover
Clear interfaces to your internal teams: we deliver the assessment, report, and recommended action. Implementing patches and updates in your systems remains your responsibility, as part of your change management process.
Build or Outsource Your PSIRT?

Your decision guide

Building in house or a managed service, the right answer depends on your individual situation. We help you make the right decision for your company and show transparently what each path means.

In House Build
PSIRT as a Managed ServiceRecommended
Time to launch
Months (staff, processes, tools)
Ready to go immediately
Resource commitment
Dedicated in house team, round the clock readiness
No dedicated staff needed
Cost
Fixed, regardless of incident volume
Scales with product lines / scope
Specialiced expertise
Must be built up and kept current
Available immediately
Best suited for
Companies with high, sustained incident volume and capacity for dedicated teams
Companies without a dedicated security department (or in a transition phase)

In House Build

  • Months (staff, processes, tools)Time to launch
  • Dedicated in house team, round the clock readinessResource commitment
  • Fixed, regardless of incident volumeCost
  • Must be built up and kept currentSpecialiced expertise
  • Companies with high, sustained incident volume and capacity for dedicated teamsBest suited for

PSIRT as a Managed Service

Recommended
  • Ready to go immediatelyTime to launch
  • No dedicated staff neededResource commitment
  • Scales with product lines / scopeCost
  • Available immediatelySpecialiced expertise
  • Companies without a dedicated security department (or in a transition phase)Best suited for
ACADEMY / TRAININGS · WORKSHOPS
Engineer leading a workshop in a meeting room
— NewTec Academy

Enable your teams!

Regulations such as the Cyber Resilience Act (CRA), NIS2, or IEC 62443 explicitly require proof of qualified personnel. Sometimes the fastest lever isn't a service package but targeted training, so your team keeps the expertise in house.

At the NewTec Academy, we bundle our knowledge into open and in house formats: compact, practical, and led by trainers from live projects.

  • ✓Workshops & trainings on CRA, NIS2, IEC 62443, Secure Development Lifecycle
  • ✓Tailored to development, product management, or procurement teams
  • ✓Training materials & checklists as a working basis
  • ✓Documentation of all training measures, audit ready for authorities
Visit the NewTec Academy →
FAQ

Frequently Asked Questions About the PSIRT Services

The Cyber Resilience Act (CRA) does not literally mandate a specific organisational form called a "PSIRT," but it does functionally require exactly that from manufacturers of products with digital elements: a process for receiving, assessing, and reporting vulnerabilities throughout the entire product lifecycle, including fixed reporting deadlines. These reporting obligations under Art. 14 CRA have already been in effect since September 11, 2026, regardless of when the respective product was placed on the market. In practice, a functioning PSIRT is therefore the natural way to fulfil this obligation.

Since September 11, 2026, the CRA reporting obligation under Article 14 has been binding. For actively exploited vulnerabilities, reporting follows three stages: an early warning within 24 hours and a vulnerability notification with details within 72 hours, each from becoming aware, followed by a final report no later than 14 days after a corrective or mitigating measure becomes available. For severe security incidents, the same deadlines apply to the early warning and the notification, and the final report is due within one month of the notification. Reports are submitted to the relevant CSIRT and ENISA via the single reporting platform.

This is also covered by the CRA: if a vulnerability is identified in a third-party component, there is an obligation to report it to the person or organization that maintains that component. Our monitoring covers both purchased components and in-house developments, including this reporting obligation toward suppliers.

The scope of service scales with the number of your product lines and components used. You can start with a single product or a manageable number of product lines and expand the service as needed.

Technical delivery of validated updates is part of the Full Service package. Deploying updates into your systems (rollout) typically remains your responsibility, as part of your change management process, and we support you with technical documentation and integration guidance.

As a development services provider, NewTec can also take on the actual implementation of patches or updates on request. This is not part of the PSIRT service scope but is commissioned separately as a development service.

The scope of service, and therefore the price, depends on the number of your product lines, the components used, and the package selected (Basic, Monitoring & Reporting, Full Service). We put together a custom quote after a brief assessment of your portfolio.

A CSIRT (Computer Security Incident Response Team) responds to IT security incidents within a company, such as attacks on its own IT infrastructure. A PSIRT (Product Security Incident Response Team) is specifically focused on vulnerabilities and security incidents in a manufacturer's products that occur in the field at customer sites. Many companies need both, for different areas of responsibility.

No. We support you with expert assessment and the operational handling of reports; legal responsibility for meeting the reporting obligations remains with the manufacturer itself.

Companies with very high, consistent incident volume and sufficient capacity for their own dedicated 24/7 team may benefit more from a fully in house PSIRT. In practice, however, a hybrid model with external support during peak periods is also common here.

Classic vulnerability management is often limited to scanning and assessing vulnerabilities. Our PSIRT service covers the entire process: from detection through legally required reporting to mitigation planning and the delivery of updates, including communication with authorities and external reporters.

Let's talk

Let's talk about your PSIRT.

We'll assess where you stand today, from the maturity of your processes to the right package size, and show you the fastest path to a ready to deploy PSIRT as a managed service.