You will be provided with a reference and some statements. Please determine whether each statement is 'supported', 'unsupported', or 'unknown' with respect to the reference. Please note:
First, assess whether the reference contains any valid content. If the reference contains no valid information, such as a 'page not found' message, then all statements should be considered 'unknown'.
If the reference is valid, for a given statement: if the facts or data it contains can be found entirely or partially within the reference, it is considered 'supported' (data accepts rounding); if all facts and data in the statement cannot be found in the reference, it is considered 'unsupported'.

You should return the result in a JSON list format, where each item in the list contains the statement's index and the judgment result, for example:
[
    {
        "idx": 1,
        "result": "supported"
    },
    {
        "idx": 2,
        "result": "unsupported"
    }
]

Below are the reference and statements:
<reference>
EU Cyber Resilience Act & Smart Home Security | Protexium

The EU Cyber Resilience Act (Sept 2026) sets new rules for alarm systems, Smart Home devices and IoT security – what it means for owners.

Skip to content

PROTEXIUM
Home
Services
Overview
Intrusion protection
Video surveillance
Fire protection
Automation
Child protection
Anti-squatter protection
Industries
Residential clients
Commerce & trade
Industrial facilities
High security
Tenerife
Case studies
Protection Knight
Webinar
Blog
Contact
Contact

Home
Services
Overview
Intrusion protection
Video surveillance
Fire protection
Automation
Child protection

Anti-squatter protection
Industries
Residential clients
Commerce & trade
Industrial facilities
High security
Tenerife
Tenerife overview
Puerto de la Cruz
Santa Cruz
Las Galletas
Los Cristianos
Case studies
Protection Knight
Webinar
Blog
Contact
Free security analysis

Home

/

Blog

/

Cyber Resilience Act

Actuality & Regulation

EU Cyber Resilience Act – What the new law means for your Smart Home security

From September 2026, manufacturers of connected devices must report security vulnerabilities within 24 hours. What does this mean for your alarm system, your cameras and your Smart Home?

16 April 2026

9 min read

Table of contents

What is the EU Cyber Resilience Act?

Timeline: when does what come into force?

Which devices are affected?

What this means for alarm systems and cameras

Cheap cameras vs. professional systems – the gap widens

How Protexium already meets the CRA

Checklist for consumers

Conclusion: more security for everyone

The European Union is getting serious about the cybersecurity of connected devices. The
EU Cyber Resilience Act (CRA)
is the most comprehensive law ever passed for the security of IoT devices – that is, connected everyday devices. And it directly affects what many of us use daily: alarm systems, surveillance cameras, smart door locks and Smart Home systems.
“Your alarm system protects you from burglars – but who protects your alarm system from hackers?”

What is the EU Cyber Resilience Act?

The Cyber Resilience Act is an EU regulation that establishes binding cybersecurity requirements for all products with digital elements – that is, for every device that has a network connection. The law was adopted in October 2024 and enters into force in stages.

The core requirements of the CRA:

Security by Design:
Cybersecurity must be integrated into product development from the outset – not retrofitted afterwards.

Mandatory security updates:
Manufacturers must provide security updates throughout the entire expected product lifetime.

Reporting obligation for vulnerabilities:
Actively exploited security vulnerabilities must be reported to the EU cybersecurity agency ENISA within 24 hours.

No default passwords:
Devices may not be delivered with default passwords such as “admin/admin”.

Transparency:
Manufacturers must maintain a software bill of materials (SBOM) and publish security information.

Timeline: when does what come into force?

Sep. 2026

Reporting obligation for vulnerabilities (24-hour deadline)

Dec. 2027

Full compliance of all products

€15 million

Max. fine for breaches

All IoT

Cameras, alarm systems, smart locks affected

From
11 September 2026
, all manufacturers must comply with the reporting obligation for vulnerabilities. From
11 December 2027
, all products sold in the EU must meet the full CRA requirements – including Security by Design, update obligations and documentation. ENISA (European Union Agency for Cybersecurity) is the designated recipient of the 24-hour vulnerability reports.

Which devices are affected?

The CRA applies to virtually all connected devices. Particularly relevant for the security technology sector:

Surveillance cameras
(IP cameras, doorbell cameras, NVR systems)

Alarm systems
with network connection (Wi-Fi, GSM, LAN)

Smart door locks
and electronic access control systems

Motion detectors and sensors
with wireless connection

Smart Home gateways
and hubs

Smoke detectors and water sensors
with network functionality

The CRA distinguishes between “normal” and “critical” products.
Alarm systems and access control systems fall into the higher category
and are subject to stricter testing requirements – including external audits.

What this means for alarm systems and cameras

For consumers, the CRA is good news: going forward, you can trust that connected security devices really are cyber-secure. Specifically, the following will change:

End of “plug and pray”

Previously, manufacturers could sell cheap IP cameras with default passwords and without encryption. Such devices are a gateway for hackers – in the worst case, strangers can use your own camera against you. The CRA puts an end to this: every device must be securely configured out of the box.

Mandatory security updates

Do you know the feeling: a camera installed three years ago has not had an update for two years? That will no longer be legal in future. Manufacturers must deliver updates over the entire product lifecycle. Those who cannot or will not do so may no longer sell in the EU. We have already looked at how important regular updates are for
data protection
.

Transparency about the security situation

In future, manufacturers must disclose which software components are in their devices. This makes it possible for security experts and consumers to assess the actual security situation.

Cheap cameras vs. professional systems – the gap widens

The CRA will change the market. Cheap no-name cameras and alarm systems from the Far East, previously sold via online marketplaces, will have a significantly harder time. That is because the CRA requirements incur costs – for development, testing, audits and long-term provision of updates.
“Cheap is not inexpensive – and certainly not secure.”

The consequence for consumers: anyone investing in an alarm system or camera system should
rely on manufacturers who demonstrably meet the CRA requirements
. Protexium works exclusively with
European-certified manufacturers
who already meet or exceed the upcoming standards today.

Caution with existing systems!

The CRA applies to new products placed on the market from December 2027. Already-installed devices are not affected – but may no longer receive updates if the manufacturer leaves the market. If your system is older than 5 years, a security check is worthwhile.

How Protexium already meets the CRA

For Protexium customers, little changes due to the CRA – because we already meet most of the requirements today:

Certified systems:
All Protexium installations are certified to
EN 50131
and meet the highest European security standards.

Encrypted communication:
Our
wireless systems
use encrypted radio protocols – no open Wi-Fi, no insecure Bluetooth.

Regular updates:
Firmware updates are pushed centrally via the monitoring centre – you do not have to worry about anything.

No default passwords:
Every system is configured individually during installation – with its own credentials and two-factor authentication.

European manufacturers:
We work exclusively with manufacturers who produce in the EU and proactively implement the CRA.

“Cybersecurity is not a feature – it is a basic prerequisite. At Protexium, this has always been the case.”

Checklist: is your security technology CRA-ready?

Check your existing system with these questions:

Were the default passwords changed during installation?

Is the firmware up to date?

Does the system use encrypted communication (no open Wi-Fi)?

Is there a named manufacturer with support in the EU?

Do you receive regular security updates?

Is the app connection secured with two-factor authentication?

Was the system installed and configured professionally?

If you answer more than two questions with “no” or “I do not know”, you should have your system checked. Protexium offers a free
security check
– also for existing systems from other providers.

Conclusion: more security for everyone – if you choose the right partners

The EU Cyber Resilience Act is an important step for the security of connected devices. It forces manufacturers to take cybersecurity seriously – and protects consumers from insecure cheap products that pose more risk than protection.
“A lock that can be hacked is not a lock – it is an invitation.”

For you as a consumer this means: rely on
security technology from certified providers
who already meet tomorrow’s standards today. And have existing systems checked regularly – physical security and cybersecurity belong together.

Start a free security analysis now

Sources & further links

European Commission – Cyber Resilience Act

Federal Office for Information Security (BSI)

ENISA – European Union Agency for Cybersecurity

Regulation (EU) 2024/2847 – full text of the Cyber Resilience Act

About the author

Protexium Security Editorial Team

Our team of experts, made up of security consultants and specialist technicians, shares well-founded knowledge on intrusion protection, Smart Home and modern security technology.

You may also be interested in

Smart Home and security – How automation protects your home

Data protection with alarm systems – What you need to know

Why a wireless system is more secure than Wi-Fi

Start free security analysis

“Security that protects before danger arises”
Individual security solutions for your home and business. European certification.
Services
Overview
Intrusion protection
Video surveillance
Fire protection
Automation
Child protection
Anti-squatter protection
Industries
Residential clients
Commerce & trade
Industrial facilities
High security
Case studies
Become a Protection Knight
Blog
Contact
+49 9129-2945775
info@protexium.de
Germany & Tenerife
Free webinar
Shop
© 2026 Protexium Security GmbH
Untere Rathausgasse 10, 90530 Wendelstein
Management: Oxana Nosenko · VAT ID: DE327683777
Legal notice
Privacy
</reference>

<statements>
1. Critically, the CRA imposes a legal obligation on manufacturers to report actively exploited vulnerabilities and severe security incidents to competent cybersecurity authorities within 24 hours of confirmation
2. EU Cyber Resilience Act (CRA): Statutory penalties for vulnerabilities; mandatory 24-hour breach reporting
</statements>

Begin the assessment now. Output only the JSON list, without any conversational text or explanations.