How the EU Cyber Resilience Act Is Changing Vendor Accountability in Physical Security
As the European Union’s Cyber Resilience Act (CRA) tightens cybersecurity expectations for connected products, physical security software leader Genetec has published guidance to help organizations assess whether their technology partners are ready to comply.
The CRA sets out cybersecurity obligations for any product with digital components sold within the EU. Its focus spans secure development practices, ongoing vulnerability management, transparency around risks, and continued support across a product’s lifespan. Although the rules are aimed primarily at manufacturers, their ripple effects will reach distributors, integrators, and the organizations that purchase and operate connected devices.
According to Mathieu Chevalier, Principal Security Architect at Genetec, the regulation formalizes practices the company has championed for years — namely, building security into products from the start and maintaining them responsibly over time. He notes that the CRA gives buyers a more structured way to judge whether a vendor’s products hold up to long-term cybersecurity scrutiny.
With vulnerability-reporting requirements under the CRA taking effect on September 11, companies will need greater assurance that their suppliers can meet these obligations. Genetec recommends organizations ask potential vendors the following:
- What is the vendor’s commitment to long-term security support?
The CRA requires manufacturers to provide security updates and handle vulnerabilities for a minimum of five years. Buyers should clarify how long updates will continue and what happens once a product reaches end-of-life. - Was security part of the design process from day one?
“Secure by Design” and “Secure by Default” are foundational CRA principles. Vendors should be able to explain how security considerations shaped their development and testing process. - How are vulnerabilities identified and handled?
A mature vendor will have a formal vulnerability management process — including routine testing, a clear disclosure policy, timely fixes based on risk level, and secure update delivery. - Does the vendor operate transparently?
Trustworthy providers communicate openly about how they build and test their products, and they give customers practical guidance for deploying systems securely. - Will the vendor support resilience long after purchase?
Security doesn’t stop at installation. Buyers should understand how a vendor plans to maintain support, respond to new threats, and eventually retire products — and what documentation it can provide to prove ongoing compliance.
Chevalier emphasizes that forward-thinking organizations treat cybersecurity as an ongoing relationship with their vendors rather than a single purchasing decision — a mindset the CRA is designed to reinforce industry-wide.
Genetec has spent over two decades building its physical security platform around secure development principles, incorporating encryption, access controls, monitoring, and structured vulnerability management into its product design.
