Transparency about security update support periods
Manufacturers must clearly disclose the minimum period for which they will provide security updates for a connectable product. This information must be made available to consumers before they purchase the device and remain accessible throughout its lifecycle.
What it means
The intent of this requirement is to prevent "silent" end-of-life dates, where a consumer unknowingly purchases a device that is no longer receiving critical security patches. It ensures that the longevity of a product's security support is a transparent factor in the buyer's decision-making process.
In practice, this means you cannot simply state that you will provide updates "for as long as possible." You must commit to a specific, minimum timeframe (e.g., a number of years) during which security vulnerabilities will be addressed and patched.
This requirement applies specifically to the security aspect of software maintenance, rather than general feature enhancements or functional upgrades. The focus is on ensuring the device remains protected against known threats for a predictable duration.
How to meet it
- Define a concrete minimum support period (e.g., 3 years, 5 years) for each product model based on its hardware capabilities and intended lifecycle.
- Update product packaging or point-of-sale displays to explicitly state the security update window so it is visible before purchase.
- Include the specific security support duration in the digital product documentation or user manuals.
- Ensure the disclosure specifies the starting point of the period, such as the date of manufacture or the official release date.
- Establish an internal governance process to review and communicate any changes to these support periods if they are extended or modified.
Evidence an auditor asks for
- Screenshots of e-commerce product pages showing the security update period displayed clearly to potential buyers.
- Copies of physical packaging or retail signage that include the transparency statement.
- PDF versions of user manuals or "Quick Start Guides" containing the support duration disclosure.
- Internal policy documents detailing how the organization determines and validates the support window for different product lines.
Common pitfalls
- Using ambiguous language such as "supported for a reasonable period," which does not satisfy the requirement for concrete transparency.
- Burying the information inside lengthy Terms and Conditions or Privacy Policies rather than placing it prominently at the point of sale.
- Confusing general software support (feature updates) with security support, leading to misleading claims about how long the device is actually "secure."