Cyber Resilience Act
Cyber Resilience Act obligations
The Cyber Resilience Act (Regulation (EU) 2024/2847) sets security requirements for products with digital elements, which includes software such as Vicodis. Its reporting duties for actively exploited vulnerabilities apply from 11 September 2026; the main obligations follow from 11 December 2027.
For manufacturers, the core duties are security by design, handling vulnerabilities over a defined support period, providing security updates and documenting the product, including its software components. Several properties of Vicodis help here:
- Small attack surface: no cloud connection, no remote service, no own user database — access runs through the camera’s accounts.
- Signed licences: licence and deletion keys are cryptographically signed and checked offline.
- Known components: third-party software (such as SQLite and OpenSSL) is listed in the app.
Security updates for Vicodis are provided free of charge for every licence, independent of Vicodis Care: when something critical is fixed, every customer receives the new version. New versions with additional functions are part of Vicodis Care and supplied on request.
Support period: every Vicodis licence receives security updates for at least five years from purchase — the minimum the CRA sets for products expected to be used at least that long. The exact end date of the support period is stated at purchase.