Building automation sat outside the cybersecurity conversation for a long time, on the argument that a BMS is not a plant. That argument is closing from two directions at once: the EU Cyber Resilience Act arrives as law, and specifiers have started writing IEC 62443 into tenders. Most BAS manufacturers will meet both in the same eighteen months.
The protocols are the starting condition
BACnet, KNX, Modbus and LonWorks were designed when the building network was a closed system reached from a locked riser cupboard. Authentication was largely absent by design, because the medium was the control. A well-formed write to a setpoint is obeyed because it is well-formed, not because the sender proved anything.
What changed is not the protocol. It is that the BMS now has a cloud portal, a vendor VPN for remote service, a tenant app, and an analytics feed — each a legitimate business requirement, and collectively an assumption that no longer holds.
What the CRA asks a BAS manufacturer first
Classification, by core functionality — not by feature list (Art 7(1)). Most controllers, gateways and supervisory software land as default products, which may self-assess under module A (Art 32(1)). That is the good news and it covers the bulk of a typical catalogue.
The exceptions are worth checking deliberately, because Annex III names things a building portfolio often contains:
- Smart-home products with security functionalities — smart door locks, security cameras, alarm systems — are Annex III Class I.
- Routers, internet-facing modems and switches, and network management systems, are Class I. An edge gateway that is fundamentally a router is not saved by being sold as a building product.
- Identity and privileged access management software or hardware, including biometric readers — Class I. Access control is a building-automation product line.
- Firewalls and IDS/IPS are Class II: notified body, always (Art 32(3)).
An embedded Class I component does not reclassify the host product. But a module sold separately carries its own classification and its own conformity route — which catches OEMs who both build a controller in and sell it as a spare.
The access-control line is the one to check today
If your portfolio includes door controllers, credential readers or the software that administers them, you are plausibly in identity and access management territory, and therefore Class I. Class I self-assessment is conditional on applying harmonised standards, common specifications or an EUCC scheme at assurance level “substantial” or above (Art 32(2)) — and CRA harmonised standards are still being written. Plan for the possibility that a notified body is on your critical path, and find out in 2026 rather than 2027.
Where 62443 arrives
Specifiers on institutional projects — hospitals, data centres, universities, government estates — increasingly cite IEC 62443 in the specification. For a BAS OEM that means two parts in particular:
- 62443-4-1, your secure development lifecycle. It is also the best-value CRA preparation available, because it produces much of what Annex I asks for as a by-product of development rather than as a compliance project.
- 62443-4-2, the technical requirements your controllers must meet, reported as a capability vector across the seven foundational requirements — not as a single number.
Your customers will meet 62443-3-2 as well, and its separation rules read like a critique of the average building network: business assets separated from automation assets, safety-related assets separated, temporarily connected devices separated, wireless separated, and anything reachable over external networks separated. A flat BMS VLAN spanning tenant systems, life-safety interfaces and a vendor remote-access tunnel fails several of those at once.
What to do in the next two quarters
- Classify the catalogue. Per product: core functionality, Annex III match, sold separately or embedded. Most will be default — find the ones that are not.
- Decide the support period per line, remembering the five-year floor and that buildings outlive product roadmaps.
- Get security-only updates working. Annex I Part II asks for security updates shipped separately from functional ones where feasible. Buildings cannot always take a feature release; they can take a patch.
- Stand up vulnerability handling — contact point, disclosure policy, SBOM in a machine-readable format. Unconditional, and independent of classification.
- Design remote access into a DMZ, not into the automation zone. It is the finding that appears in nearly every building assessment, and it is architectural rather than expensive.
We work with manufacturers on both tracks — the CRA classification and Annex I evidence, and the 62443-4-1 lifecycle that makes the next product easier than this one. If a specifier has just sent you a 62443 clause or you are unsure where your access-control line classifies, that is the conversation to have now.
If you would rather work through the CRA side yourself, the CRA Workbench carries the classification logic and Annex I evidence structure as a workspace.