Bye summer, hello easy access.

Get 20% off the Home Set Pro NFC. For a limited time only.

Happy mom and happy son with football coming home.

What does the Cyber Resilience Act mean for your front door?

The new EU regulation, explained in simple terms

Coming home after a long day, your mind is still on work, dinner, or whatever else is waiting. One thing you do not need to think about? Your keys.

As you approach your front door, your Nuki Smart Lock opens automatically. You step inside and carry on with your evening. The technology — and the security work behind it — stays in the background.

That is exactly how smart home technology at your front door should feel: simple, reliable, secure. Security is embedded in our product DNA. At Nuki, a consistent Security-by-Design approach has shaped our product development from the very beginning. Because access to your home deserves strong protection.

But the security of connected products should not depend on the individual manufacturer. It should be a priority across the industry. That is where the European Union’s Cyber Resilience Act (CRA) comes in.

So, what does this new EU regulation actually mean for you, your home, and your Nuki Smart Lock?

The short answer? Very little changes in your daily life. Most of the work happens behind the scenes.

What changes behind the scenes?

Already own a Nuki Smart Lock? No need to change your routine. For manufacturers, however, requirements are increasing.

At Nuki, IT security from the very first line of code has always been the standard. The CRA now makes cybersecurity throughout the product lifecycle a general obligation for manufacturers.

They must consider cybersecurity throughout the entire product lifecycle: during development, at market launch, and throughout product maintenance. That also includes managing vulnerabilities.

What does that mean for you? Security in digital products should no longer be just a promise of quality. It should become a binding requirement.

What the CRA means for you

  • More security from the development stage: Manufacturers must integrate cybersecurity into product development from the start and systematically assess risks.
  • More reliable vulnerability management: Manufacturers must systematically address vulnerabilities during the defined support period and provide security updates.
  • More transparency: Among other things, manufacturers must state how long a product will be supported and provide users with the information they need to operate it securely.

Rolling out the CRA: Why 24 and 72 hours suddenly matter

The first important CRA deadline is just around the corner. From September 11, 2026, the new reporting obligations for manufacturers will apply.

What happens if a vulnerability is actively exploited or a severe security incident occurs? Manufacturers must act quickly. An initial early warning is due within 24 hours. A more detailed notification follows within 72 hours, with final reporting required later.

This fundamentally changes what is expected of manufacturers’ security organizations.

One security test before market launch? That is no longer enough. Manufacturers must remain ready after launch: identify security issues, assess them, and take action.

They must also determine exactly which products and versions are affected.

That is exactly why cybersecurity is an ongoing process, not a one-time quality check.

Security-by-Design: Why Nuki did not wait for the CRA

A new law creates binding minimum requirements. But secure product development starts much earlier. At Nuki, Security-by-Design has been part of product development since the company was founded.

Security is not added to a finished product as an afterthought. It is considered from the concept stage onward and throughout development.

This includes:

  • end-to-end encryption for communication between the relevant components
  • systematic threat and risk analyses
  • regular security updates delivered over the internet
  • hardware-based security mechanisms, including secure elements and additional memory protection
  • safeguards against tampering attempts
  • independent security testing by external experts

This approach goes beyond meeting individual legal requirements. Security should be part of the entire process — product development, product maintenance, vulnerability management.

What does this mean for your data?

A smart lock has a particularly sensitive job: it controls access to your home. So, two questions matter. Which data needs to be processed? And how is communication between the individual components protected?

Our architecture is designed with these questions in mind. Sensitive information does not generally need to be stored in a central cloud.

Much of the security-relevant information remains on the devices or within local communication.

Communication between the smartphone and Smart Lock is encrypted. Modern security mechanisms protect it against unauthorized interception or copying.

Independent testing builds additional trust

Manufacturers can say a lot about the security of their own products. Independent testing adds an external perspective.

All generations of our Smart Locks have been tested by independent security experts at the AV-TEST Institute. These tests look beyond theory. They can reveal technical vulnerabilities in practical implementation. Nuki devices have carried the AV-TEST “Approved IoT Product” seal since the first product generation.

Concept. Implementation. Testing.

All three matter in a comprehensive IT security approach. After all, a product can be secure on paper and still become vulnerable through implementation errors.

A work desk from AV-Test with three computers and many testing utensils on the table.

What the CRA means for the smart home market

The Cyber Resilience Act is more than another regulatory requirement for manufacturers. It changes what is expected of digital products. Cybersecurity is moving from a voluntary quality decision to a binding requirement.

From our perspective, this is an important step. Why? Because trust is essential when people use digital technology in sensitive areas of daily life. And few places feel more sensitive than the front door.

Conclusion: Security should be a given

The Cyber Resilience Act creates a new framework for connected products in Europe. What does that mean for you as a Nuki user? You do not need to change your daily routine.

Most of the changes happen behind the scenes. Manufacturers must integrate security more systematically. They must manage vulnerabilities, provide security updates, and communicate more transparently about product maintenance.

At Nuki, this approach has been part of our product development for many years. So, the CRA does not mark a new beginning for us. Instead, it confirms the direction we have followed from the start: Security-by-Design, continuous product maintenance, and independent testing. Together, these three elements should build trust in smart access.

In the end, a smart lock should feel like any other good technology in your daily life. Simple. Reliable. Secure.