The European Union’s Cyber Resilience Act (CRA) is the most significant cybersecurity legislation ever introduced for connected products. While many people associate cybersecurity with computers and IT networks, the CRA will have a major impact on smart homes, commercial buildings, lighting control systems, HVAC controls, access control systems, and virtually every connected device installed within modern buildings.
For Ireland’s construction, electrical, and building automation industries, the CRA represents a fundamental shift in how manufacturers design, support, and maintain products throughout their lifecycle.
For companies specifying smart building technology today, the message is clear: cybersecurity is no longer optional. It is becoming a legal requirement.
What is the Cyber Resilience Act?
The Cyber Resilience Act is an EU regulation that establishes mandatory cybersecurity requirements for products with digital elements. This includes hardware, software, IoT devices, smart home equipment, building automation products, gateways, cloud-connected devices, and mobile applications.
The legislation entered into force in December 2024 and will be fully applicable from 11 December 2027. Certain reporting obligations begin earlier, from September 2026.
The CRA applies across all EU member states, including Ireland, and is designed to ensure that products are:
- Secure by design
- Secure by default
- Maintained throughout their lifecycle
- Supported with security updates
- Protected against known vulnerabilities
- Capable of reporting serious cybersecurity incidents
Manufacturers that fail to comply risk significant penalties and may be prevented from selling products within the European Union.
Â
Why Was the CRA Introduced?
The modern building is becoming increasingly connected.
Lighting systems, heating controls, smart thermostats, access control, CCTV, energy management systems, EV chargers, shading systems, and even household appliances are now connected to networks and, often, the internet.
Unfortunately, many of these products have historically been developed with convenience and cost as priorities, while cybersecurity received less attention.
The CRA seeks to address this issue by shifting responsibility away from end users and installers and placing it firmly on manufacturers. Products entering the European market must now demonstrate appropriate cybersecurity protections throughout their operational life.
How Will the CRA Affect Smart Home and Building Products?
The impact on the smart building industry will be substantial.
Manufacturers will need to implement:
Secure Development Processes
Products must be designed with cybersecurity considerations from the outset rather than having security added later. The regulation promotes a “secure by design” philosophy.
Vulnerability Management
Manufacturers must monitor products for vulnerabilities and provide security fixes when issues are discovered.
Security Updates
Many connected products will require mechanisms for distributing updates throughout their supported lifetime. Manufacturers must continue to address cybersecurity risks after installation.
Incident Reporting
From September 2026, manufacturers must report actively exploited vulnerabilities and significant cybersecurity incidents to the appropriate authorities within strict timeframes.
Product Documentation
Manufacturers will need detailed technical documentation demonstrating compliance with CRA requirements and will need to maintain evidence supporting cybersecurity claims.
The Challenge for Building Automation Manufacturers
Many traditional building automation protocols were originally developed long before cybersecurity became a major concern.
Systems relying on unencrypted communications, weak authentication methods, or proprietary security approaches may face significant redevelopment work to meet CRA requirements.
Manufacturers that have relied on network isolation as their primary security strategy may discover that this is no longer sufficient.
As buildings become more connected and remote access becomes commonplace, cybersecurity must be built directly into the communication protocol and device architecture rather than relying solely on external IT measures.
Why KNX is Well Positioned for the CRA
Among building automation technologies, KNX stands out as one of the strongest candidates for long-term CRA compliance.
This is because KNX has been investing in cybersecurity for many years through the development of KNX Secure technologies.
Unlike many legacy automation protocols, KNX has already introduced security mechanisms specifically designed to protect building automation communications.
KNX Data Secure
KNX Data Secure protects communication between devices by encrypting telegrams travelling across the KNX network.
This helps prevent:
- Eavesdropping
- Data manipulation
- Device spoofing
- Unauthorised command injection
KNX Data Secure operates independently of the transmission medium and protects communications at protocol level.
KNX IP Secure
KNX IP Secure encrypts communication over IP networks, providing protection for building systems that operate across Ethernet or internet-connected infrastructure.
This becomes increasingly important as remote access and cloud connectivity become standard expectations in modern buildings.
Security Across All KNX Media
Today, security capabilities exist across KNX TP, KNX RF, KNX IP and KNX IoT technologies, providing authentication, integrity checking and confidentiality mechanisms directly within the KNX ecosystem.
Open Standard Advantages
The CRA does not favour proprietary systems.
In fact, open standards often benefit because their security architecture can be independently reviewed, validated, and improved over time.
KNX’s international standardisation and multi-vendor ecosystem create a framework where security enhancements can be adopted across hundreds of manufacturers rather than being dependent upon a single vendor’s roadmap. This reduces the risk of vendor lock-in while helping maintain long-term compliance.
What Does This Mean for Ireland?
For Irish consultants, electrical contractors, M&E consultants, developers, and building owners, the CRA will increasingly influence product selection decisions.
When specifying smart home or building technologies, questions will become more common:
- Does the manufacturer have a cybersecurity strategy?
- Are security updates available?
- Is encryption supported?
- How are vulnerabilities managed?
- Does the manufacturer have a path to CRA compliance?
Products lacking satisfactory answers may become difficult to justify in future projects.
This trend is likely to be particularly significant in:
- Hotels
- Healthcare facilities
- Pharmaceutical facilities
- Educational campuses
- Government buildings
- Commercial offices
- High-end residential developments




