It shouldn't be time-based it should be support-based. As in, the moment you stop supporting your product is the moment you're legally required to publish the source code and any signing keys, tools, etc necessary to use it.
There is no excuse for not providing it from day one. And more than one reason to do it -- not only do you verify that you have what you need before they're gone, it allows people to find vulnerabilities sooner so they get patched before more people have the vulnerable device, and allows them to improve the software in general even when the hardware vendor is in a commodity market with margins to slim too do it themselves.