Preparing Connected Video Security Products for the Next Cybersecurity Framework
Connected products are becoming an increasingly important part of the European cybersecurity regulatory landscape.
For manufacturers of network-connected hardware and software, cybersecurity is moving from a market expectation toward a formal product lifecycle requirement.
The European Union Cyber Resilience Act, or CRA, introduces cybersecurity requirements for many products with digital elements made available on the EU market.
For the video security industry, the CRA reinforces several themes that are already becoming central to product engineering:
security by design, vulnerability management, secure maintenance and lifecycle responsibility.
What Is the Cyber Resilience Act?
The Cyber Resilience Act is Regulation (EU) 2024/2847.
It establishes cybersecurity requirements for products with digital elements placed on the European Union market.
The framework covers both hardware and software within its scope, subject to defined exclusions and sector-specific rules.
Manufacturers need to determine whether a particular product falls within the scope of the regulation and what requirements apply to it.
For connected video security products, this assessment should be carried out at the product level rather than assumed from a broad product category.
When Does the CRA Apply?
The CRA entered into force on 10 December 2024.
Its main requirements will apply from 11 December 2027.
However, some provisions apply earlier.
Of particular importance to manufacturers, reporting obligations relating to actively exploited vulnerabilities and severe security incidents apply from 11 September 2026.
This means CRA readiness should not be treated solely as a 2027 project.
Vulnerability reporting and incident-response processes already require attention before the wider product requirements become fully applicable.
Security by Design
One of the central principles of the CRA is that cybersecurity should be considered during the design, development and production of products with digital elements.
The regulation includes essential cybersecurity requirements addressing areas such as risk-appropriate security and secure product configuration.
For manufacturers, this encourages a shift away from treating cybersecurity as an optional add-on.
Instead, security considerations increasingly need to become part of normal product engineering.
For connected security equipment, relevant considerations may include:
authentication and access control;
protection of communications;
software and firmware integrity;
reduction of unnecessary attack surfaces;
secure configuration;
protection of security-relevant information;
vulnerability handling;
security updates.
The exact measures should reflect the identified risks and the characteristics of the product.
Cybersecurity Risk Assessment
CRA preparation begins with understanding the cybersecurity risks associated with a product.
The assessment should consider the product's intended purpose and foreseeable use.
Rather than applying exactly the same controls to every device, manufacturers need a risk-based approach.
For example, relevant considerations may include:
network connectivity;
available interfaces and services;
authentication mechanisms;
software dependencies;
update mechanisms;
data handled by the product;
possible consequences of compromise;
expected operating environment.
The objective is not to assume that every connected product has identical cybersecurity risk.
It is to identify the risks relevant to a specific product and apply proportionate security measures.
Vulnerability Handling Becomes a Lifecycle Responsibility
The CRA places significant emphasis on vulnerability management.
Cybersecurity responsibility does not end when the product leaves the factory.
Manufacturers need processes that allow vulnerabilities to be identified, received, evaluated and addressed throughout the applicable support period.
A mature vulnerability-handling process can include:
receiving vulnerability reports;
validating and assessing the issue;
determining affected products and software versions;
developing corrective or mitigating measures;
testing security updates;
communicating relevant information;
maintaining appropriate records.
A coordinated vulnerability disclosure process can help provide researchers and other external parties with a defined channel for reporting potential security issues.
Security Updates and Product Support
Security updates are another important part of the CRA framework.
Manufacturers need to consider how products will be maintained over their expected lifecycle.
This includes determining and communicating an appropriate support period.
Under the CRA framework, support periods are generally expected to reflect the length of time the product is reasonably expected to remain in use, subject to the specific provisions of the regulation.
For long-lived security infrastructure, lifecycle planning therefore becomes particularly important.
Manufacturers should think about product maintenance during development rather than only after vulnerabilities are discovered.
Software Components and Dependency Awareness
Modern connected products commonly include multiple software components and dependencies.
Understanding those components is important for vulnerability management.
If a vulnerability is discovered in a software dependency, manufacturers need to be able to determine whether their products are affected.
This makes software component management and appropriate software inventory practices an increasingly important part of cybersecurity engineering.
The objective is not simply to produce documentation.
It is to improve the manufacturer's ability to understand and respond to cybersecurity risk throughout the product lifecycle.
CRA Vulnerability and Incident Reporting
From 11 September 2026, CRA reporting obligations apply to certain actively exploited vulnerabilities and severe security incidents affecting products with digital elements.
The regulation establishes staged reporting timelines.
For relevant reportable events, manufacturers may need to provide:
an early warning within 24 hours after becoming aware;
additional notification information within 72 hours;
subsequent reporting in accordance with the applicable CRA requirements.
Manufacturers should therefore have internal escalation processes that allow potential reportable events to be identified quickly.
This does not mean every software defect must automatically be reported.
The CRA defines the types of vulnerabilities and incidents covered by the reporting requirements.
Technical and regulatory assessment remains necessary.
Technical Documentation and Conformity Assessment
The CRA also brings cybersecurity more directly into product conformity activities.
Manufacturers within scope will need appropriate technical documentation demonstrating how applicable cybersecurity requirements have been addressed.
Depending on the product classification and applicable conformity procedure, different assessment routes may apply.
This means cybersecurity evidence increasingly needs to be structured and maintainable.
Documentation may need to support areas such as:
cybersecurity risk assessment;
relevant security controls;
vulnerability-handling processes;
product support information;
secure-use instructions;
applicable conformity assessment.
The specific evidence required should be determined according to the product and applicable regulatory requirements.
Avoiding Overly Broad CRA Claims
Because the CRA involves product scope, classification, lifecycle processes and conformity assessment, manufacturers should be careful with broad marketing statements.
Claims such as:
“All products are fully CRA compliant”
may be difficult to support without product-specific evaluation and applicable conformity evidence.
A safer and more accurate approach is to communicate CRA preparation at the organizational and engineering level while confirming applicability and supporting documentation for individual products.
Regulatory readiness should be supported by evidence rather than by marketing terminology alone.
Sunell's Approach
Sunell continues to monitor evolving cybersecurity requirements affecting connected video security products.
Our approach emphasizes risk-based product security, vulnerability handling, lifecycle management and product-specific documentation.
Because cybersecurity requirements and product configurations vary, applicable security capabilities and compliance documentation should be confirmed for the exact model, software version, configuration and intended market.
This product-specific approach helps customers and project stakeholders evaluate the information relevant to their own procurement and deployment requirements.
Cybersecurity Is Becoming a Product Lifecycle Discipline
The CRA represents a broader shift in cybersecurity regulation.
Manufacturers are increasingly expected not only to add security technologies to products, but also to demonstrate how cybersecurity risks are managed throughout the product lifecycle.
For connected video security, that means secure engineering, vulnerability management, updates, documentation and ongoing product support will become increasingly interconnected.
Preparing early can help manufacturers build these requirements into existing engineering processes rather than treating compliance as a final-stage documentation exercise.
Looking for cybersecurity documentation for a specific Sunell product?
Contact Sunell or request applicable supporting documentation for the selected product and configuration.
This article provides general information about the EU Cyber Resilience Act and does not constitute legal, regulatory or conformity-assessment advice. Scope and requirements should be evaluated for each specific product and market situation.
