EU Implements Elevator Cybersecurity Compliance Certification, Products Without Certificate Banned from Market from 2026
On January 2, 2026, the European Commission issued an official announcement, officially including smart elevators (including IoT and remote control functions) in the high-risk product list of the Cyber Resilience Act (CRA), implementing strict cybersecurity compliance supervision. Core requirements: First, mandatory certification, smart elevators must pass cybersecurity tests by third-party institutions recognized by the EU, covering data encryption, access control, vulnerability management, anti-hijacking and other dimensions, and can affix the CE mark only after obtaining certification; Second, access ban, from January 1, 2026, smart elevators without cybersecurity certification are prohibited from being sold, installed and used in EU member states; Third, transition arrangement, existing smart elevators put into use before January 1, 2025 must complete compliance transformation and pass certification by December 31, 2027; Fourth, violation penalties, enterprises that sell or install products without certificates will be fined 20%-40% of the goods value, and those with serious circumstances will be included in the EU blacklist, prohibited from entering the EU market; Fifth, standard basis, certification tests are based on the special chapter on cybersecurity of EN ISO 8100 and relevant clauses of CRA to ensure that elevator cybersecurity meets international standards. This policy will comprehensively raise the cybersecurity threshold for smart elevators in the EU market and accelerate the global compliance upgrading of the industry.