Cyber Resilience and Video Surveillance: how the new European regulations redefine the security of connected devices
The advent of the Cyber Resilience Act (Cyber Resilience Act, CRA) introduce a European-wide perspective change. The Regulation (UE) 2024/2847 establishes horizontal cybersecurity requirements for products with digital elements marketed in the European Union, from design and development to maintenance and vulnerability management throughout their lifecycle.
for years, the security of a video surveillance system has mainly been measured in physical terms: camera resolution, optics quality, cobertura, image storage, resistance against sabotage or infrastructure availability. The progressive connection of these systems to IP networks, cloud services and management platforms has added a new dimension that can no longer be ignored: the cybersecurity.
For the video surveillance industry, The change is significant. An IP camera, un grabador de vídeo en red, a management device or certain software components are no longer considered solely as functional elements of a security installation but form part of a technological chain in which digital security must be incorporated from the start.
The CRA adopts a risk-based and lifecycle approach. Its scope extends to hardware and software products that incorporate digital elements and that, due to their intended purpose or reasonably foreseeable use, establish a direct or indirect data connection with another device or network.
This criterion has an obvious consequence for video surveillance. The IP camera connected to a corporate network, The NVR that stores the images, The VMS software that manages hundreds of devices or specific equipment used for video control and processing is part of an ecosystem that must also be analyzed from the perspective of digital exposure.
The regulation thus shifts a large part of the responsibility to the manufacturer. Before introducing a product to the market, they must carry out a cybersecurity risk assessment and adopt the necessary measures so that the product is designed, developed, and manufactured with an adequate level of protection. That assessment must be reflected in the technical documentation.
The principle is especially relevant in video surveillance: it's not enough to incorporate protection mechanisms after a vulnerability appears. Security must be part of the product architecture.
Much more than changing the password
One of the cultural changes introduced by the CRA directly affects the initial configuration of devices. The European Commission establishes that elements to be considered include issues such as security by default, access control, the use of cryptography and security updates. The goal is overcoming models in which certain essential measures are left in the hands of the user or installer.
In video surveillance, this affects issues that for years have been part of best practice recommendations: initial credentials, account management, administrative privileges, exposure of network services, comunicaciones cifradas, firmware update or segmentation of devices.
The difference is that many of these issues cease to belong exclusively to the realm of technical recommendation to be integrated into a European regulatory framework applicable to the product.
Another aspect with greater impact for the industry is vulnerability management. The CRA establishes specific requirements for manufacturers to manage vulnerabilities of their products during the support period. This implies having processes to identify, correct and communicate security issues, as well as provide the necessary updates.
For a video surveillance system, the issue is particularly sensitive. Una A vulnerability in the firmware of a camera can compromise the camera itself, but can also become a gateway into the network where it is installed. If the device has access to servers,, sistemas de control, storage, or cloud services, the potential impact multiplies.
That's why, the product's security can no longer be analyzed in isolation. Vulnerability management must consider both own and third-party components, software dependencies, and the technology supply chain.

Reporting exploited vulnerabilities
Although the general application of the CRA is planned for 11 de diciembre de 2027, one of its most relevant obligations has already come into effect. From the 11 de septiembre de 2026, los manufacturers subject to the regulation must report actively exploited vulnerabilities and certain serious incidents affecting the security of their products with digital elements. These communications are carried out through the single notification platform managed by ENISA.
The system establishes especially demanding deadlines. For an actively exploited vulnerability, the regulation provides for an initial alert within 24 hours from when the manufacturer becomes aware of it, a main notification within 72 hours and subsequent communications related to corrective measures.
In a market such as video surveillance, where the same platform can be installed in thousands of locations, this obligation also changes the relationship between manufacturer, distributor, integrator and owner of the infrastructure. The detection of a vulnerability is no longer exclusively an internal technical matter. It can trigger a formal chain of response and communication.
It is appropriate to introduce an important clarification here. The CRA distinguishes between products with digital elements subject to general requirements and categories considered important or critical, for which more stringent conformity assessment procedures are established. The European Commission specified the technical descriptions of these categories through the Implementing Regulation (UE) 2025/2392.
A video surveillance camera does not automatically become an important or critical product simply because it is connected to the Internet. La clasificación depende de la funcionalidad que desempeñe y de si encaja en alguna de las categorías definidas en los anexos correspondientes.
Esto resulta relevante para evitar una interpretación excesivamente amplia de la norma. El conjunto del ecosistema de videovigilancia puede quedar dentro del ámbito de la CRA, pero no todos sus componentes estarán necesariamente sometidos al mismo procedimiento de evaluación de conformidad.
Para los productos importantes de determinadas categorías, la regulación puede exigir una evaluación por terceros cuando no se cumplen determinadas condiciones. Los productos críticos están sujetos a requisitos todavía más estrictos.

El impacto llega también al integrador
Aunque buena parte de las obligaciones recaen sobre los fabricantes, la CRA no deja al margen al resto de la cadena de suministro. Importadores y distribuidores tienen responsabilidades específicas para verificar determinados aspectos de conformidad antes de comercializar los productos. Besides, las autoridades de vigilancia del mercado podrán intervenir cuando un producto presente riesgos significativos de ciberseguridad. Para los integradores de sistemas de seguridad, esto puede traducirse en una mayor necesidad de documentación y trazabilidad.
La selección de una cámara o de un VMS no debería atender únicamente a prestaciones como resolución, video analytics, artificial intelligence, almacenamiento o interoperabilidad. Será cada vez más importante conocer su política de actualizaciones, periodo de soporte, vulnerability management procedure, security documentation and compliance evidence.
In projects of a certain size, these criteria may end up being incorporated into the technical specifications and the manufacturer approval processes.
The end user also changes position
The CRA aims to make cybersecurity more visible for those who buy and use connected products. Manufacturers must provide information and instructions that allow installing, operating and using the products safely.
For a security officer, this may mean having much more structured information about the behavior of the equipment during its useful life.
La pregunta ya no será únicamente cuánto cuesta una cámara o qué calidad de imagen ofrece, sino durante cuánto tiempo tendrá soporte, cómo se notifican las vulnerabilidades, qué procedimiento existe para aplicar parches, qué mecanismos de autenticación incorpora o qué ocurre cuando finaliza su periodo de soporte.
En otras palabras, la ciberseguridad empieza a convertirse en una variable de adquisición, mantenimiento y renovación de los sistemas de seguridad física.
La evolución normativa europea refleja una realidad que el sector lleva años experimentando: la frontera entre seguridad física y ciberseguridad se ha difuminado. Una cámara IP puede ser un elemento de seguridad física, pero también un dispositivo informático conectado permanentemente a una infraestructura de comunicaciones. Un VMS puede gestionar imágenes de seguridad y, at the same time, interactuar con directorios corporativos, access control systems, servidores y servicios cloud.
That's why, proteger una instalación de videovigilancia ya no consiste solamente en impedir que alguien manipule físicamente una cámara o acceda a una sala técnica. También implica reducir la superficie de ataque digital de todos los dispositivos que forman parte de ella.
La CRA consolida esta evolución desde el ámbito regulatorio: la seguridad deja de ser una característica añadida al producto para convertirse en un requisito que debe acompañarlo desde su concepción hasta el final de su ciclo de vida.
Highlight, por último que el calendario obliga al sector a actuar con antelación. La CRA entró en vigor el 10 de diciembre de 2024, mientras que la aplicación general del Reglamento está prevista para el 11 de diciembre de 2027. Algunas disposiciones, however, ya son aplicables, entre ellas las relativas a la notificación de vulnerabilidades e incidentes desde el 11 de septiembre de 2026.
¿Te gustó este artículo?
Subscribe to our NEWSLETTER and you won't miss anything.