On 27 August 2026 Help Net Security published an interview with Rob Janssens, EMEA Cyber Security Director at Hikvision Europe. One sentence in it is worth more attention than the rest. "The customer owns the system," he says, and they "should not be dependent on a particular installer to keep control of it."
He is describing a product design problem. A camera fleet is commissioned once by an integrator, then runs for a decade. Credentials, firmware and the whole administrative path often stay with a company that may move on, change hands, or close. Janssens calls the result a lifecycle problem, and the words he uses are exact. If an installer disappears and the customer can no longer administer its own cameras, the fleet is still running and nobody can secure it.
The interview does not mention the Cyber Resilience Act. It should, because the regulation converts every part of that argument into a duty with a date on it.
Why the installer gap becomes a manufacturer problem
The CRA places the vulnerability handling duty on the manufacturer. It does not follow the integrator, and it does not transfer to the customer.
Annex I Part II requires the manufacturer to identify and document vulnerabilities in the product, to remediate them without delay, and to distribute security updates. Article 13(8) requires a support period that reflects how long the product will be in use, with a floor of five years in most cases. A surveillance camera stays screwed to a wall far longer than five years, so the honest number for most of this sector is longer still.
Put those two together and the installer gap turns into an obligation nobody can discharge. The manufacturer must supply an update. The customer cannot apply it because the administrative path left with the integrator. Neither party is in breach of anything obvious, and the fleet stays unpatched.
Secure by default is now a legal standard
Janssens makes a second argument that the regulation also codifies. "Secure-by-default means the customer does not have to become a security specialist just to get a reasonably safe initial configuration."
Annex I Part I of the CRA says the same thing in regulatory language. Products must be made available with a secure by default configuration. They must be shipped without known exploitable vulnerabilities. They must protect against unauthorised access with appropriate control mechanisms, including authentication and identity management.
The practical test for a manufacturer is simple. If the safe configuration only exists in a hardening guide, the product does not ship secure by default. The guide is documentation about a state the product could reach. The regulation asks about the state the product arrives in.
That is why the specific measures Janssens lists matter more than they look. A forced password at activation, login failure monitoring, IP filtering, and remote access disabled until somebody turns it on are each the difference between a default and a recommendation.
What a manufacturer has to put in place
The interview describes the product half of the answer. The reporting half runs on a clock that starts on 11 September 2026.
| Duty | Source | What it requires |
|---|---|---|
| Reachable security contact | RFC 9116, Annex I Part II | A monitored address published at /.well-known/security.txt with a live Expires date |
| Public disclosure policy | Annex I Part II | A stated scope, a stated response commitment, and a position on good faith research |
| Internal handling process | ISO/IEC 30111 | A defined route from report to triage to fix, with named owners |
| Reporting to the finder | ISO/IEC 29147 | Acknowledgement and status updates through to disclosure |
| Early warning | CRA Article 14(1) and 14(2)(a) | 24 hours from awareness of an actively exploited vulnerability |
| Vulnerability notification | CRA Article 14(2)(b) | 72 hours, with affected versions and initial mitigations |
| Final report | CRA Article 14(2)(c) | 14 days after a corrective or mitigating measure is available |
| Support period | CRA Article 13(8) | At least five years in most cases, with the end date stated to users |
Hikvision states in the interview that its vulnerability reporting process is certified under ISO/IEC 29147 and ISO/IEC 30111. The published text prints the second number as 30011, which appears to be a typographical slip, because 30111 is the standard for vulnerability handling processes.
Those two standards are the operational content behind the CRA's disclosure requirements. 29147 governs how a report reaches you and how you answer the person who sent it. 30111 governs what happens inside the company after that. A manufacturer that runs both has most of Annex I Part II covered before reading the annex.
Ownership handover belongs in the product
The part of the interview that the regulation does not yet spell out is the recovery path. Nothing in the CRA text says a customer must be able to reclaim administrative control of a product from an absent integrator.
It follows anyway from the duties that are written down. A manufacturer that must deliver security updates for at least five years needs those updates to arrive. So the recovery path belongs in the product, and it belongs in the technical documentation as part of the reasoning behind the support period.
Three questions decide whether a product has one.
- Can a verified owner regain administrative access without the original installer, through a documented and auditable procedure?
- Does the manufacturer hold a record of who the owner is, separate from who commissioned the device?
- Can the owner see the firmware version and the support period end date without a service visit?
A product that answers no to all three has a support commitment that depends on a third party staying in business.
The number this sector should look at
Our CRA Exposure Study 2026 scanned 342 EU manufacturers on 29 July 2026, including 44 EU-headquartered video surveillance manufacturers. Across those 44, three publish a security.txt and none publish a discoverable coordinated disclosure policy. Six were not determinable, because bot protection or a transport failure blocked the probe, and our method never counts those as absences.
Hikvision is headquartered outside the EU and was therefore not in that frame. The sector it sells into was, and the sector has the weaker public disclosure route.
We wrote up what that gap means for the video surveillance market on the Porta Regulus intel feed, in Zero of forty-four.
What to do this month
Article 14 applies from 11 September 2026. Two weeks of work covers most of the exposure.
- Publish a conforming
security.txtwith a monitored address and anExpiresdate under a year out. Check yours with the free exposure scanner. - Publish a disclosure policy at the
PolicyURL that the file points to. - Write down who triages a report, who decides on a fix, and who files to the ENISA Single Reporting Platform. Article 14 gives you 24 hours, and that is not enough time to decide who is in charge.
- Document the ownership recovery path for every product still in its support period.
The first three are what CVD Portal does. The fourth is engineering work that only the manufacturer can do, and Janssens is right that the industry has been slow to it.