Euralarm has released a Position Paper in which definitions are proposed that can be endorsed by the European Commission in the Implementing an Act complementing the CRA. 

Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA) is expected to be published in the Official Journal of the European Union (OJEU) in  September or October 2024.

This new Regulation will provide essential requirements enforcing protection mechanisms on digital products (hardware and software) to improve their resilience against cyber-attacks. 

Conformity assessment procedures

Essential requirements will ensure that identified vulnerabilities are duly handled

In addition, essential requirements will ensure that identified vulnerabilities are duly handled and result in updates to the products during the whole support period of the product.

The Regulation also imposes conformity assessment procedures for the demonstration of compliance with these essential requirements. 

Smart home products

While most digital products are announced to benefit from the procedure of self-assessment, regardless of the existence of harmonised standards, and presumption of conformity when a harmonised standard (cited in the OJEU) is applied, categories of important products and critical products are listed in the CRA and associated with a stricter conformity assessment procedure. 

At least 1 category of important products in Class I is of importance for the Euralarm members. This one is listed in Annex III of the CRA as “Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems, and alarm systems”. 

OJEU or an EU-type examination

This category will require either the application of a harmonised standard cited in the OJEU or an EU-type examination by a CRA-notified body. It is therefore of utmost importance to have unambiguous definitions for it.

Euralarm, the European trade association representing the electronic fire safety and security industry, greatly appreciates the opportunity to propose definitions that can be endorsed by the European Commission in the Implementing Act complementing the CRA. After due consideration of the wording of the category in Annex III and the criteria in Article 7(2) of the CRA, the present position paper provides such proposals for the category mentioned above. 

Download PDF version Download PDF version

In case you missed it

Anviz Global expands palm vein tech for security
Anviz Global expands palm vein tech for security

The pattern of veins in the hand contains unique information that can be used for identity. Blood flowing through veins in the human body can absorb light waves of specific wavelen...

Bosch sells security unit to Triton for growth
Bosch sells security unit to Triton for growth

Bosch is selling its Building Technologies division’s product business for security and communications technology to the European investment firm Triton. The transaction enc...

In age of misinformation, SWEAR embeds proof of authenticity into video data
In age of misinformation, SWEAR embeds proof of authenticity into video data

The information age is changing. Today, we are at the center of addressing one of the most critical issues in the digital age: the misinformation age. While most awareness of thi...

Quick poll
What is the most significant challenge facing smart building security today?