PortaRegulus
HOME
21 // INTEL · ANALYSIS

Zero of forty-four.

The security argument about surveillance cameras is fought over source code escrow and country of origin. We measured something plainer. Across 44 EU-headquartered video surveillance manufacturers, none published a disclosure policy a researcher could find.

PortaRegulus Intel CRA · Article 14 · Video surveillance 30 Aug 2026

On 27 August 2026 Help Net Security published an interview with Rob Janssens, EMEA Cyber Security Director at Hikvision Europe. He was asked about the two demands European buyers now put to camera vendors, source code escrow and restrictions based on where a company is from. His answers are the interesting part, because they point at a third question that almost nobody is asking.

On escrow, "having access to source code is not, by itself, evidence that a product is secure." On origin, "nationality alone should not replace objective, technical security evaluation." A vendor has an obvious interest in both positions. That does not make either one wrong, and the second half of each sentence describes a real gap in how the sector is procured.

So we went to our own data and asked what the sector does on the one control that is objective, technical, free, and verifiable from outside the company. Can a researcher who finds a flaw in a camera tell anyone about it?

What the scan found

On 29 July 2026 we scanned 342 EU manufacturers of products with digital elements, drawn from published trade association member directories. One of the sector cells is video surveillance, at 44 manufacturers. Every company in it is headquartered in the EU, because the frame excludes members headquartered elsewhere.

MeasureVideo surveillance, n=44All sectors, n=342
Publishes a security.txt3 · 6.8%34 · 9.9%
Publishes one that meets RFC 91163 · 6.8%24 · 7.0%
Discoverable disclosure policy0 · 0%20 · 5.8%
Neither35 · 79.5%257 · 75.1%
Not determinable6 · 13.6%45 · 13.2%

The three files that exist are all valid, which is the one bright spot and a better conformance rate than the frame as a whole manages. The zero is the finding. Video surveillance and robotics are the two cells in the study, 44 manufacturers each, that returned no discoverable coordinated disclosure policy at all.

Six of the 44 are recorded as not determinable. A 403, a bot-protection challenge or a transport failure says nothing about whether a file exists, so the study never counts one as an absence. Even if all six turned out to publish a policy, the cell would sit at 13.6 percent.

Hikvision is not in this number

Hikvision is headquartered outside the EU, so it was never in the frame. Nothing here measures it, and nothing here should be read as a claim about its products.

The company states in the interview that its vulnerability reporting process is certified under ISO/IEC 29147 and ISO/IEC 30111, and that it holds ISO/IEC 42001 for AI management. The published text prints the second number as 30011, which reads as a typographical slip, because 30111 is the standard for vulnerability handling processes. Those two standards are the operational content behind what the Cyber Resilience Act asks of a manufacturer under Annex I Part II. 29147 governs how a report reaches you and how the sender is answered. 30111 governs what the company does with it internally.

Which produces an uncomfortable arrangement. A vendor that European buyers scrutinise on grounds of origin publishes a certified disclosure process. The EU-headquartered sector selling into the same buildings published, at the end of July, no discoverable disclosure policy at all.

Why this is the test that matters in September

Article 14 of Regulation (EU) 2024/2847 applies from 11 September 2026. From that date a manufacturer that becomes aware of an actively exploited vulnerability in its product has 24 hours to send an early warning to its coordinating CSIRT and ENISA, 72 hours for the vulnerability notification, and 14 days from a corrective or mitigating measure being available for the final report.

The clock starts at awareness. Nothing in the regulation requires a manufacturer to be findable, and no authority will penalise a missing security.txt. The consequence is quieter than a penalty and worse. A researcher who cannot find a contact publishes, or reports to a national CSIRT that then has to identify and reach you. In both cases the 24 hour clock started before the manufacturer knew there was one.

Escrow and origin rules answer questions about trust in a supplier. Neither one shortens that gap by a minute. A published contact and a published policy are what decide whether the manufacturer is the first to know or the last.

The specific reason cameras are exposed here

A camera fleet is commissioned once and runs for a decade. Janssens makes the point in the interview that the customer owns the system and "should not be dependent on a particular installer to keep control of it." Under the CRA that stops being a design preference. Article 13(8) requires a support period matching how long the product is expected to be in use, with a five year floor in most cases, and the vulnerability handling duty in Annex I Part II runs for the whole of it.

So a security update has to be produced by the manufacturer, delivered to a fleet whose administrative path may have left with an integrator, on the strength of a report that arrived through a channel the sector has not published. Three separate failure points, and only one of them takes an afternoon to fix.

The longer write up of the ownership and support period half of this, and what a manufacturer has to put in place, is on the CVD Portal blog.

The short version

Of 44 EU-headquartered video surveillance manufacturers measured on 29 July 2026, three publish a security contact and none publish a discoverable disclosure policy. The debate the sector is having concerns source code and nationality. The control it is missing costs nothing, takes an afternoon, and decides who learns about an exploited vulnerability first, twelve days before Article 14 applies.

The full study, the per-sector breakdown, the sampling frame and the limitations are published at CRA Exposure Study 2026. The aggregate dataset is CC BY 4.0 and names no individual company. To check a single domain, the exposure scanner probes the same paths the study used and needs no account.

Can a researcher reach you?