The Home of Smart Buildings, Smart Equipment & IoT

From Product Compliance to System Responsibility: A Practical View for Integrators and Designers

Written by J2 Innovations | 03 September 2026
 
This week we are featuring a guest blog from Salvatore Cataldi, Global Standards & Regulations Lead at Belimo. Salvatore joined us for FIN Connect 2026 in Verona to discuss the Cyber Resilience Act and its implications for system integrators.
 
The Cyber Resilience Act (CRA) will not only affect manufacturers. It will also change what customers expect from system integrators and designers. The regulation is product-based. It applies to products with digital elements placed on the EU market, and the main obligations will apply starting December 11th, 2027. Reporting obligations start earlier, on September 11th 2026.
 
But a building automation system is not simply a product. It is an integration of products. This distinction is essential. A manufacturer can place a compliant product on the market. The system integrator decides how that product is used in a real building. The designer defines the architecture, the specification and often the expectations that the integrator must meet. The owner or facility manager then operates the system across many years.
 
Cybersecurity therefore becomes a lifecycle question. Who updates the components? Who decides whether a firmware update is acceptable if interoperability could be affected? Who monitors vulnerabilities? Who documents the assumptions? Who explains to the customer when a component must be replaced because it can no longer be securely updated?
 
These are not abstract questions. They define the future service offering of system integrators. At FIN Connect 2026, I suggested three practical actions.
 

Take a position

Decide where your role starts and where it ends in the lifecycle. Are you only integrating compliant products as intended? Are you importing or distributing products? Are you rebranding devices? Are you modifying software or firmware in a way that could change your responsibility? The role depends on what you do, not on how you describe yourself.
 

Update your offer

Customers will need more than installation. They will need help with update management, vulnerability awareness, secure configuration, documentation and operational support. Not every project will need the same level of cybersecurity, but every project will need a conscious decision.
 

Make your choices explicit

Put them in the contract, in the architecture and in the documentation. If a product is selected for a certain environment, say why. If updates are part of the service, say who performs them. If updates are excluded, say what the consequence is.
 
Designers also need new practical skills. They do not need to become cybersecurity engineers. But they need to understand architecture, lifecycle, risk assessment, support periods, update mechanisms, access concepts and the difference between a simple product feature and a maintainable system.
 
The FIN Connect 2026 material summarized this as five skills:
  1. Understanding architecture
  2. Reading a cyber offer
  3. Thinking in terms of risk assessment
  4. Understanding lifecycle
  5. Orchestrating actors.
This is the opportunity.
 
The system integrator who can orchestrate cybersecurity responsibilities becomes more valuable. The designer who can specify lifecycle-aware systems becomes more relevant. The manufacturer who provides clear product information becomes easier to integrate. The CRA will make product compliance visible. The market will decide who can turn that compliance into secure buildings.