WP Basic
- Vulnerability Monitoring
- Vulnerability Reporting
- Mitigation Planning
- Threat Analysis and Risk Assessment
- HW/SW Maintenance
- Security Update Management

The Cyber Resilience Act (CRA), NIS2, and industry specific standards such as IEC 62443 require manufacturers of connected products to ensure product security throughout the entire product lifecycle, including monitoring, assessing, and reporting vulnerabilities, in some cases within tight legal deadlines.
Building an internal PSIRT means establishing your own processes, trained staff, round-the-clock availability, and solid documentation for authorities and customers, from a complete SBOM (Software Bill of Materials) of your products to evidence in the event of an incident. Not every company can or wants to maintain this structure on an ongoing basis. NewTec offers PSIRT functions as a managed service: you get a ready-to-deploy team, established processes, and standards-compliant documentation, without the effort of building it yourself.
With PSIRT as a managed service, you are immediately capable of action: established workflows, standards compliant response, and full scalability.
Classic vulnerability management often amounts to occasional scans or manual spot checks. Our service runs continuously: a daily automated comparison of your deployed components, both purchased assemblies and in-house developments based on your SBOM, against the relevant vulnerability databases NVD, EUVD, and GHSA, as well as manufacturer advisories. Every match is checked for actual relevance, since not every reported vulnerability affects your specific version or configuration. Assessment follows CVSS (Common Vulnerability Scoring System) and is documented as a machine-readable VEX statement (affected, not_affected, fixed, under_investigation), so you learn not just that a vulnerability exists, but whether and how it affects your specific product. This reduces false alarms and creates the documented basis required by CRA and NIS2. We also keep an eye on manufacturer discontinuations and end-of-support.
Incoming reports are triaged by our security team on call: first, we assess whether a reportable, actively exploited vulnerability or a severe incident affecting the security of the product is present (Article 14(3) and (5) CRA). Where a CRA reporting obligation applies, we issue a timely early warning within 24 hours and the notification with details within 72 hours to the relevant CSIRT and ENISA, and we prepare the final report within the legal deadline. Even where no reporting obligation applies, you receive a documented assessment. Every report is tracked through to the final report.
Once a vulnerability becomes known, a compliant mitigation plan is created within 14 days, in line with CRA requirements. This includes a technical analysis of the vulnerability in the context of the affected product, an assessment of the impact on security and operability, and the identification of practical measures such as configuration changes, workarounds, or organisational steps. We also support publication to authorities and affected users and maintain complete documentation to prove deadlines were met.
The systematic threat and risk analysis for OT systems begins with the Initial Risk Assessment (IRA): capturing the system environment, an initial risk profile, and identifying critical assets. The subsequent Detailed Risk Assessment (DRA) involves an in depth threat and vulnerability analysis assessed by likelihood and impact, from which technical and organisational protective measures are derived. An annual review of the risk situation and validation of existing measures ensures you continuously meet regulatory requirements such as NIS2 and IEC 62443.
Based on identified vulnerabilities and agreed mitigation plans, we provide tested, security relevant updates. We analyse the vulnerability and identify suitable updates for firmware, software, or configuration, before documenting the tested and approved security updates, including version and compatibility details. Technical guidance for safe implementation and a fallback option, along with support integrating updates into your rollout processes, round out the service.
Technical delivery of updates to implement planned mitigation measures takes place regardless of who ultimately deploys the update: we select suitable patches, firmware, or configuration changes, check compatibility and version status, and document everything, including integration notes and an optional fallback option. The clear separation between analysis, planning, and delivery ensures traceability regarding the availability and currency of your security updates, in line with CRA requirements.
You choose the depth, we deliver the matching package, or put together a custom one for your needs.

Building your own PSIRT ties up personnel, processes, and specialiced expertise that many companies cannot or do not want to maintain long term. NewTec already runs vulnerability management and incident response for customers in safety-critical industries, with established processes that are ready to use immediately rather than needing to be built from scratch. As a Product Security Incident Response Team, we handle monitoring, assessment, and reporting of your vulnerabilities in compliance with CRA, NIS2, and IEC 62443, with full transparency through complete, audit ready documentation. The overview below shows which company situations our PSIRT is especially well suited for as an outsourced service.
„If you already have your own SOC or CSIRT, our PSIRT service integrates seamlessly into your existing processes. It complements these structures by adding the product perspective: while a SOC/CSIRT responds to incidents in your own IT infrastructure, our PSIRT handles vulnerabilities and incidents in your products out in the field. Technical integration happens through your existing reporting channels (CVD portal, ticketing/vulnerability management system), with no parallel tool landscape required. Results can be consolidated into shared reporting for your management.“
You benefit from our experience with CRA, NIS2, and IEC 62443 requirements without having to build and maintain that expertise yourself, while retaining full transparency through complete, audit-ready documentation.
Our in house developed toolchain makes our team maximally efficient from day one.
Without tying up your own staff
From a single product to full service
Of all reports and assessments
Between analysis & reporting and technical implementation. Your development team stays focused.
Building in house or a managed service, the right answer depends on your individual situation. We help you make the right decision for your company and show transparently what each path means.
Regulations such as the Cyber Resilience Act (CRA), NIS2, or IEC 62443 explicitly require proof of qualified personnel. Sometimes the fastest lever isn't a service package but targeted training, so your team keeps the expertise in house.
At the NewTec Academy, we bundle our knowledge into open and in house formats: compact, practical, and led by trainers from live projects.
The Cyber Resilience Act (CRA) does not literally mandate a specific organisational form called a "PSIRT," but it does functionally require exactly that from manufacturers of products with digital elements: a process for receiving, assessing, and reporting vulnerabilities throughout the entire product lifecycle, including fixed reporting deadlines. These reporting obligations under Art. 14 CRA have already been in effect since September 11, 2026, regardless of when the respective product was placed on the market. In practice, a functioning PSIRT is therefore the natural way to fulfil this obligation.
Since September 11, 2026, the CRA reporting obligation under Article 14 has been binding. For actively exploited vulnerabilities, reporting follows three stages: an early warning within 24 hours and a vulnerability notification with details within 72 hours, each from becoming aware, followed by a final report no later than 14 days after a corrective or mitigating measure becomes available. For severe security incidents, the same deadlines apply to the early warning and the notification, and the final report is due within one month of the notification. Reports are submitted to the relevant CSIRT and ENISA via the single reporting platform.
This is also covered by the CRA: if a vulnerability is identified in a third-party component, there is an obligation to report it to the person or organization that maintains that component. Our monitoring covers both purchased components and in-house developments, including this reporting obligation toward suppliers.
The scope of service scales with the number of your product lines and components used. You can start with a single product or a manageable number of product lines and expand the service as needed.
Technical delivery of validated updates is part of the Full Service package. Deploying updates into your systems (rollout) typically remains your responsibility, as part of your change management process, and we support you with technical documentation and integration guidance.
As a development services provider, NewTec can also take on the actual implementation of patches or updates on request. This is not part of the PSIRT service scope but is commissioned separately as a development service.
The scope of service, and therefore the price, depends on the number of your product lines, the components used, and the package selected (Basic, Monitoring & Reporting, Full Service). We put together a custom quote after a brief assessment of your portfolio.
A CSIRT (Computer Security Incident Response Team) responds to IT security incidents within a company, such as attacks on its own IT infrastructure. A PSIRT (Product Security Incident Response Team) is specifically focused on vulnerabilities and security incidents in a manufacturer's products that occur in the field at customer sites. Many companies need both, for different areas of responsibility.
No. We support you with expert assessment and the operational handling of reports; legal responsibility for meeting the reporting obligations remains with the manufacturer itself.
Companies with very high, consistent incident volume and sufficient capacity for their own dedicated 24/7 team may benefit more from a fully in house PSIRT. In practice, however, a hybrid model with external support during peak periods is also common here.
Classic vulnerability management is often limited to scanning and assessing vulnerabilities. Our PSIRT service covers the entire process: from detection through legally required reporting to mitigation planning and the delivery of updates, including communication with authorities and external reporters.
We'll assess where you stand today, from the maturity of your processes to the right package size, and show you the fastest path to a ready to deploy PSIRT as a managed service.