What has changed under the EU Cyber Resilience Act?
Regulation (EU) 2024/2847, known as the Cyber Resilience Act, entered into force on 10 December 2024. From 11 September 2026, its reporting obligations apply: manufacturers of "products with digital elements" — a category that explicitly includes connected home cameras, smart locks, alarms and other connected devices — must send an early warning to their national Computer Security Incident Response Team (CSIRT) within 24 hours of learning a vulnerability is being actively exploited, or that a severe security incident has occurred. A fuller notification follows within 72 hours, and a final report is due within 14 days of a fix becoming available (or within one month for severe incidents). Reports are filed once through the CRA Single Reporting Platform and shared onward to ENISA and other national CSIRTs. The Act's full set of design, support and vulnerability-handling requirements doesn't apply until 11 December 2027 — this September deadline is only the reporting clock. Non-compliance with the Act's core security obligations can bring fines of up to €15 million or 2.5% of a company's global annual turnover, whichever is higher. The scope is broad by design — the Commission's own guidance lists connected home cameras, smart locks, alarm panels, baby monitors, smart TVs and even connected fridges and toys as examples of in-scope "products with digital elements," alongside the apps and firmware that run them.
Why does this matter for Home Assistant users?
Mostly, it changes what happens behind the scenes rather than how your existing devices behave — the new reporting duty runs from manufacturer to regulator, not to individual owners. But it's still useful context for anyone running a mixed fleet of Zigbee, Wi-Fi and Matter gear through Home Assistant: many unbranded cameras, locks and sensors sold through marketplaces are made by companies with no EU presence, and are the devices least likely to have any disclosure process at all — a gap that has already pushed regulators to lean on retailers over CE/UKCA marking before listing connected products. If you run devices locally through Zigbee2MQTT, ESPHome or Home Assistant's own integrations, the Act changes nothing about firmware you already control — it targets how vendors disclose and patch flaws, not your local automations. It's still worth tightening the basics yourself, such as keeping IoT devices on a separate network segment and following general smart home security practices, since a manufacturer patch still has to reach your device before it helps — the Act obliges a vendor to disclose and fix a flaw, not to push that fix to every device automatically.
How does this compare with the UK's own PSTI Act?
The UK already has a baseline via the Product Security and Telecommunications Infrastructure (PSTI) Act 2022, in force since 29 April 2024 and enforced by the Office for Product Safety and Standards (OPSS). It bans universal or easily guessable default passwords, requires manufacturers to publish a way to report security vulnerabilities, and covers the same broad category of "relevant connectable products," including routers, smart cameras, locks and TVs. But it stops well short of the Cyber Resilience Act's mandatory 24-hour reporting clock, and it doesn't route disclosures through a body like ENISA or a shared reporting platform. In practice, most smart home brands sold on UK shelves also sell the same hardware and firmware into the EU and Northern Ireland, so their reporting obligations under the Cyber Resilience Act still apply regardless of Brexit — UK buyers benefit from the stricter EU-side rule even though it isn't written into UK law.
Should you do anything about the devices you already own?
No immediate action is required — the Act doesn't ask owners to replace or reconfigure anything, and the September 2026 deadline is a reporting obligation on manufacturers, not a compliance deadline for products already on shelves. It's more useful as a buying filter going forward: before adding a new camera, lock or alarm to your setup, check that the manufacturer maintains a visible security or support page, since that's now a stronger regulatory expectation than it was even a year ago. For devices you already own, the practical move is the same one that predates this rule — keep firmware and companion apps updated, and don't rely on cloud-only devices you can't patch yourself.







