EU Cyber Resilience Act Fully Implemented in January 2027, All Connected Elevators Must Meet Digital Security Requirements
The EU Cyber Resilience Act was officially signed in April 2024, aiming to ensure that all digital products have sufficient cybersecurity protection capabilities throughout their entire lifecycle. For the elevator industry, the main requirements include:
1) Manufacturers must integrate security concepts into the product design stage, adopting the "security by design" principle;
2) Provide at least 5 years of security update support, and release repair patches for high-risk vulnerabilities within 24 hours;
3) Establish vulnerability management and incident response mechanisms;
4) Provide users with clear security information and usage instructions; 5) Retain product safety documentation for at least 10 years.
The act stipulates that non-compliant products will face fines of up to 4% of global annual turnover. Elevator manufacturers need to complete compliance transformation of existing products by December 31, 2026.