Smart Home Assistant

EU Cyber Resilience Act: What It Means for Your Smart Home

SepehrBy Sepehr· 10 September 2026· Updated 10 September 2026
✓ Independent — no paid placements✓ UK-tested in real homes✓ Cited sources
A smartphone showing a camera app sitting next to a white wireless smart security camera on a table.

Key takeaways

  • From 11 September 2026, the EU Cyber Resilience Act requires manufacturers to report actively exploited smart home device vulnerabilities within 24 hours.
  • The Act covers connected cameras, smart locks, alarms and hubs sold in the EU and Northern Ireland, not just software products.
  • Manufacturers face fines up to €15 million or 2.5% of global turnover for non-compliance with core Cyber Resilience Act obligations.
  • The UK's PSTI Act, in force since April 2024, bans default passwords but has no 24-hour vulnerability reporting requirement.
  • The Cyber Resilience Act's full design and support requirements don't apply until 11 December 2027.
On this page[tap to expand]

The EU Cyber Resilience Act now forces manufacturers to report actively exploited security flaws in smart home devices within 24 hours, a rule taking effect on 11 September 2026 and covering cameras, locks, alarms and hubs sold across the EU and Northern Ireland.

What has changed under the EU Cyber Resilience Act?

Regulation (EU) 2024/2847, known as the Cyber Resilience Act, entered into force on 10 December 2024. From 11 September 2026, its reporting obligations apply: manufacturers of "products with digital elements" — a category that explicitly includes connected home cameras, smart locks, alarms and other connected devices — must send an early warning to their national Computer Security Incident Response Team (CSIRT) within 24 hours of learning a vulnerability is being actively exploited, or that a severe security incident has occurred. A fuller notification follows within 72 hours, and a final report is due within 14 days of a fix becoming available (or within one month for severe incidents). Reports are filed once through the CRA Single Reporting Platform and shared onward to ENISA and other national CSIRTs. The Act's full set of design, support and vulnerability-handling requirements doesn't apply until 11 December 2027 — this September deadline is only the reporting clock. Non-compliance with the Act's core security obligations can bring fines of up to €15 million or 2.5% of a company's global annual turnover, whichever is higher. The scope is broad by design — the Commission's own guidance lists connected home cameras, smart locks, alarm panels, baby monitors, smart TVs and even connected fridges and toys as examples of in-scope "products with digital elements," alongside the apps and firmware that run them.

Why does this matter for Home Assistant users?

Mostly, it changes what happens behind the scenes rather than how your existing devices behave — the new reporting duty runs from manufacturer to regulator, not to individual owners. But it's still useful context for anyone running a mixed fleet of Zigbee, Wi-Fi and Matter gear through Home Assistant: many unbranded cameras, locks and sensors sold through marketplaces are made by companies with no EU presence, and are the devices least likely to have any disclosure process at all — a gap that has already pushed regulators to lean on retailers over CE/UKCA marking before listing connected products. If you run devices locally through Zigbee2MQTT, ESPHome or Home Assistant's own integrations, the Act changes nothing about firmware you already control — it targets how vendors disclose and patch flaws, not your local automations. It's still worth tightening the basics yourself, such as keeping IoT devices on a separate network segment and following general smart home security practices, since a manufacturer patch still has to reach your device before it helps — the Act obliges a vendor to disclose and fix a flaw, not to push that fix to every device automatically.

How does this compare with the UK's own PSTI Act?

The UK already has a baseline via the Product Security and Telecommunications Infrastructure (PSTI) Act 2022, in force since 29 April 2024 and enforced by the Office for Product Safety and Standards (OPSS). It bans universal or easily guessable default passwords, requires manufacturers to publish a way to report security vulnerabilities, and covers the same broad category of "relevant connectable products," including routers, smart cameras, locks and TVs. But it stops well short of the Cyber Resilience Act's mandatory 24-hour reporting clock, and it doesn't route disclosures through a body like ENISA or a shared reporting platform. In practice, most smart home brands sold on UK shelves also sell the same hardware and firmware into the EU and Northern Ireland, so their reporting obligations under the Cyber Resilience Act still apply regardless of Brexit — UK buyers benefit from the stricter EU-side rule even though it isn't written into UK law.

Should you do anything about the devices you already own?

No immediate action is required — the Act doesn't ask owners to replace or reconfigure anything, and the September 2026 deadline is a reporting obligation on manufacturers, not a compliance deadline for products already on shelves. It's more useful as a buying filter going forward: before adding a new camera, lock or alarm to your setup, check that the manufacturer maintains a visible security or support page, since that's now a stronger regulatory expectation than it was even a year ago. For devices you already own, the practical move is the same one that predates this rule — keep firmware and companion apps updated, and don't rely on cloud-only devices you can't patch yourself.

Buy the picks in this guide

Recommended for Smart Security

See all devices →

Frequently asked questions

What is the EU Cyber Resilience Act?
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is an EU law setting mandatory cybersecurity requirements for any "product with digital elements" sold in the EU, including smart home cameras, locks, alarms, hubs and other connected devices. It entered into force on 10 December 2024, with obligations phasing in over several years. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents to their national Computer Security Incident Response Team within 24 hours of becoming aware, followed by a fuller report within 72 hours and a final report within 14 days of a fix. The Act's complete set of design and support requirements, including mandatory security updates and vulnerability-handling processes, applies from 11 December 2027. Non-compliance can bring fines of up to €15 million or 2.5% of global annual turnover, whichever is higher.
Does the UK's PSTI Act already require this kind of reporting?
No. The UK's Product Security and Telecommunications Infrastructure (PSTI) Act 2022, in force since April 2024, bans easily guessable default passwords and requires manufacturers to publish a way to report security flaws, but it doesn't impose the EU Cyber Resilience Act's 24-hour vulnerability-disclosure clock or route reports through a body like ENISA. In practice, most smart home brands sold in the UK also sell the same hardware and firmware into the EU and Northern Ireland, so their reporting obligations under the Cyber Resilience Act still apply even though the UK has left the EU. Combined, the two regimes mean a device bought through a mainstream UK retailer is now more likely to have a manufacturer with a documented disclosure and patching process than it was a couple of years ago.

Sources

Sources verified 2026-09-10

  1. European Commission — Cyber Resilience Act — Digital Strategy overview
  2. EUR-Lex — Regulation (EU) 2024/2847 (Cyber Resilience Act)
  3. HLC (Hogan Lovells) — EU Cyber Resilience Act: Preparing for Vulnerability and Incident Reporting
  4. legislation.gov.uk — Product Security and Telecommunications Infrastructure Act 2022
How we researched this

Claims in this article are checked against primary sources — manufacturer specifications, official documentation, Which? research, Ofgem guidance, or gov.uk — rather than forum threads or video reviews. Where the author has direct hands-on experience with a product (most Home Assistant, Zigbee, and home-networking gear is running in his own homelab), that is stated explicitly in the text.

For categories outside that personal setup — such as boilers, heat pumps, and other areas that are traditionally a heating engineer's domain — verdicts are built from cross-referenced manufacturer data, published lab results, and vetted expert and owner reviews rather than a claim of personal hands-on testing. See the editorial policy for the full methodology.

Sepehr

Written by

Sepehr

10+ years hands-on with Home Assistant & networking · Research-backed elsewhere · No brand deals

Smart home specialist with 10+ years running a self-hosted Home Assistant setup — Zigbee2MQTT, Frigate NVR, and local-first automations. Independent coverage for UK homes, no brand deals.

LinkedIn →

Citing this page? Please use a dofollow link back to the original article — it helps us keep the data on this page accurate and up to date.

Related reading