KNX secure EU norm

Let’s have a look at the EU Cyber Security Developments:
1. Radio Equipment Directive Cyber Act:
The European Commission has postponed the enforcement of the Radio Equipment Directive (RED) to August 1, 2025, to finalize harmonized standards. This revised act includes three new articles and aims to enhance the cybersecurity of wireless devices in the EU.
Key Points:
- Postponed Enforcement: RED enforcement delayed to August 1, 2025, for finalizing standards.
- Scope: Applies to internet-connected devices, i.e. toys, childcare equipment, and wearables, etc.
- New Requirements:
- Network protection
- Data privacy
- Fraud prevention
- Compliance Options:
- Self-assessment
- Third-party evaluation
- Preparation: Manufacturers should prepare for certification against standards like ETSI EN 303 645 and IEC 62443-4-2.
- Framework: Development of standards for CE testing.
Manufacturers are advised to contact relevant authorities for more details.
2. Cyber Resilience Act:
Objective: Ensure safer hardware and software with digital components.
Coverage: The Cyber Resilience Act (CRA) aims to safeguard consumers and businesses buying or using products or software with a digital component. Products ranging from baby monitors to smartwatches. KNX products have digital components (such as integrated controllers, gateways, or software interfaces), those specific digital elements could potentially fall under the scope of the Act. In such cases, manufacturers would need to ensure compliance with the cybersecurity requirements outlined in the Act. KNXA is currently studying the extent of the coverage.
Issues Addressed:
- Inadequate cybersecurity in products and insufficient security updates.
- Difficulty for consumers and businesses to identify cybersecure products.
Key Provisions:
- Harmonised rules for market entry of digital products and software.
- Comprehensive cybersecurity requirements for the entire product lifecycle.
- Duty of care obligations for manufacturers and retailers.
Implementation:
- Products connected to the internet will bear a CE marking for compliance.
- Consumers and businesses will be able to make informed choices.
Regulatory Context:
- Announced in the 2020 EU Cybersecurity Strategy.
- Complements the NIS2 Framework.
Scope: Applies to all network-connected products, excluding some categories like open-source software and certain regulated industries (medical devices, aviation, cars).
Timeline:
- Expected to enter into force in early 2024.
- Manufacturers must comply within 36 months of enforcement.
- Periodic reviews by the Commission.
3. In the UK, there are additional regulations to consider:
1.- NIS1 vs NIS2 Directive:
- NIS1: Applies to key industries, imposing cybersecurity obligations.
- NIS2: Classifies important sectors via NACE code. KNX manufacturers must comply, ensuring protection against attacks.
2.- UK PSTI Act on Cyber Security:
- Effective from late April 2024.
- Applies to consumer products; some KNX manufacturers confirmed exemption.
- Compliance demonstrated via ETSI-EN303645.
Conclusion: Thanks to the great efforts done by KNX over the previous years, KNX is prepared to face these challenges much better than other protocols that did not place so much importance on secure transmission.
KNX secure complies with these new standards and we KNX guys don’t need to be worried. But surely this will change the dynamics of KNX secure devices in the market. Thus, if you have not prepared yourself to install secure devices yet, start doing it and don’t wait too long…