Genetec Inc. has released a set of guidelines aimed at aiding physical security leaders in evaluating how technology providers design and maintain connected security products.
This initiative comes as the European Union’s Cyber Resilience Act (CRA) intensifies cybersecurity requirements across the product lifecycle. The CRA sets out cybersecurity standards for digital products sold within the EU, focusing on secure product development, vulnerability management, and continuous lifecycle product support. While primarily targeting manufacturers, the regulations will impact distributors, installers, and operators of connected devices as well.
Evaluating technology providers
Mathieu Chevalier, Principal Security Architect at Genetec Inc., commented that the CRA strengthens several core principles that Genetec has long upheld, such as secure design and lifecycle management.
"By raising expectations for product security and transparency, the CRA regulations give buyers a clear basis for evaluating technology providers and the long-term cyber resilience of their products," he stated. With the onset of CRA's vulnerability-reporting guidelines by 11 September, organisations will depend more heavily on technology providers to meet new cybersecurity standards. Genetec advises asking technology providers five essential questions to evaluate their preparedness.
Vulnerability-handling requirements
The CRA underscores the critical need for sustained product security through its lifecycle
The CRA underscores the critical need for sustained product security through its lifecycle. Organisations should inquire about the duration and extent of security updates, vulnerability handling, and support as products reach the end of their lifecycle. Manufacturers are mandated to provide updates and address vulnerabilities for at least five years, which is a critical factor when assessing products.
Integrating cybersecurity from the initial stages of product design is another principle of the CRA. Companies should question providers about their incorporation of cybersecurity during design, development, and testing, alongside how these practices extend throughout the product's lifecycle.
Vulnerability management program
Since no software is completely immune to vulnerabilities, the responsiveness of a provider can indicate its dedication to cybersecurity. Firms should look for well-defined vulnerability management programs, which include regular security assessments, a coordinated disclosure policy, prompt risk-based resolutions, secure update delivery, and transparent advisories about resolved vulnerabilities.
Transparency is essential, as cybersecurity is a shared obligation. Responsible providers will transparently communicate how they test and maintain product security and offer clear guidance for secure deployment to customers and integrators. Inquiries should cover the provider’s processes for regular security evaluations, communication of vulnerabilities, and security updates, along with system-hardening advice.
Long-term cyber resilience
Genetec, with over 25 years of experience, embeds cybersecurity at the core of its physical security solutions
Continuous partnership with trusted technology suppliers is vital for sustained product cybersecurity. Organisations are encouraged to scrutinise how providers communicate product support periods, manage vulnerabilities, deliver security updates, ensure secure operation, and oversee product termination. They should insist on evidence confirming that the product adheres to cybersecurity standards throughout its lifetime.
Chevalier concluded, "Organisations best positioned to manage future cyber threats treat cybersecurity as an ongoing partnership, not a one-time procurement decision. The CRA helps reinforce that approach by setting common expectations for transparency, disciplined vulnerability management, and long-term product support, benefiting manufacturers, integrators and the organisations that depend on connected physical security systems."
Genetec, with over 25 years of experience, embeds cybersecurity at the core of its physical security solutions, employing open architecture, encryption, identity and access management, and ongoing monitoring. The organisation also prioritises vulnerability management and provides guidance to ensure long-term system resilience.
Genetec Inc., the global pioneer in enterprise physical security software, releases guidance to help physical security leaders assess how technology providers design, maintain, and support connected products as the EU Cyber Resilience Act (CRA) raises cybersecurity expectations across the product lifecycle.
The CRA establishes cybersecurity requirements for products with digital elements sold in the European Union. It places greater emphasis on secure product development, vulnerability management, cybersecurity transparency, and ongoing product support throughout the product lifecycle. While the legislation primarily applies to manufacturers, the regulation will also affect the organisations that distribute, install, procure, and operate connected devices.
Evaluating technology providers
"The Cyber Resilience Act reinforces many of the secure-by-design and lifecycle management principles that Genetec has been advocating for years," said Mathieu Chevalier, Principal Security Architect at Genetec Inc. "By raising expectations for product security and transparency, the CRA regulations give buyers a clear basis for evaluating technology providers and the long-term cyber resilience of their products."
With the CRA's vulnerability-reporting obligations coming into force on 11 September, organisations will increasingly rely on technology providers to meet new cybersecurity and vulnerability-handling requirements. To help evaluate vendor readiness, Genetec encourages organisations to ask prospective technology providers five key questions:
Vulnerability-handling requirements
How long will the product receive security updates and support? - The CRA reinforces the importance of maintaining product security throughout its lifecycle. Security leaders should understand how long the provider will deliver updates, how it will address vulnerabilities, and what support it will offer when products reach end-of-life. The CRA regulations require manufacturers to provide security updates and vulnerability handling for at least five years, making long-term support an important consideration when evaluating products.
Was cybersecurity built into the product from the beginning? - The principles of Secured by Design and Secure by Default are central to the CRA. Ask the provider to explain how it incorporates cybersecurity into product design, development, testing, and the product’s ongoing lifecycle.
Vulnerability management program
How does the provider identify, disclose, and address vulnerabilities? – No software is immune to vulnerabilities. How a provider responds is a strong indicator of its commitment to cybersecurity. Look for an established vulnerability management program that includes regular security testing, a coordinated vulnerability disclosure policy, risk-based remediation without undue delay, secure delivery of security updates, and clear advisories about fixed vulnerabilities.
Is the provider transparent about its own cybersecurity practices? - Cybersecurity is a shared responsibility. Responsible providers explain how they develop, test, and maintain their products and give customers and integrators clear guidance for secure deployment. Ask how the provider regularly tests and reviews product security, communicates vulnerabilities and security updates, and provides system-hardening guidance.
Providing system-hardening guidance
How will the provider support your long-term cyber resilience? - Product cybersecurity does not end at installation. Working with trusted technology partners is critical.
Organisations should evaluate how the provider determines and communicates the product’s support period, handles vulnerabilities, delivers security updates, supports secure operation, and manages the product’s end of life. They should also ask what evidence the provider can supply to demonstrate that the product meets applicable cybersecurity requirements throughout its lifecycle.
Connected physical security systems
"Organisations best positioned to manage future cyber threats treat cybersecurity as an ongoing partnership, not a one-time procurement decision," concluded Chevalier. "The CRA helps reinforce that approach by setting common expectations for transparency, disciplined vulnerability management, and long-term product support, benefiting manufacturers, integrators and the organisations that depend on connected physical security systems."
For more than 25 years, Genetec has applied cyber secure development practices to its physical security technology. It builds solutions based on open architecture and designs them with cybersecurity at the core, incorporating encryption, identity and access management, continuous monitoring, vulnerability management, and guidance that helps customers maintain resilient systems over time.