PSIRT
Product Security Incident Response Team
Produkt-Sicherheitsreaktionsteam
A PSIRT is the vendor-side body that handles security vulnerabilities in its own products — from receiving a report through remediation to publishing an advisory. It is the counterpart to the internal CSIRT that protects one's own organisation: a PSIRT protects the vendor's customers. With product regulation, this function is gaining strongly in importance.
History & facts. For a long time product security was a side issue for many manufacturers; only coordinated disclosure and public pressure made structured processes necessary. A mature PSIRT runs a clear reporting channel, often a disclosure process (CVD), the assignment of Common Vulnerabilities and Exposures (CVE)-IDs as a CVE Numbering Authority (CNA) and the machine-readable publication of advisories. Forum of Incident Response and Security Teams (FIRST) provides a recognised maturity and framework model for this.
Outlook & recommendation. With the Cyber Resilience Act, a functioning PSIRT becomes effectively mandatory: manufacturers must handle vulnerabilities, provide updates and, from September 2026, report actively exploited flaws. Anyone placing products with digital elements on the market should plan the build-up of such a function now — including a reporting channel, disclosure process and structured advisory output.