
Key takeaways
- The Cyber Resilience Act (CRA) sets cybersecurity requirements for products with digital elements, not directly for buildings.
- Because modern buildings contain increasingly more connected systems, digital security is becoming more relevant for real estate quality and management.
- The CRA has been in force since 10 December 2024, the reporting obligations will apply from 11 September 2026, and the regulation becomes fully applicable on 11 December 2027.
- An IT-label is not a CRA certification, but it does make visible, through the IT-label classification, what digital infrastructure a building has.
- The core question for property owners: do you actually know which digital products your building contains, who manages them, and how long they will be supported?
How many devices in a modern office are actually connected to a network? Think of access control, cameras, climate systems, sensors, charging points, lighting, elevators, meeting rooms, routers, wifi and building management systems. What used to be separate installations is now a coherent whole of software, data and connections.
We are making buildings increasingly smart. This raises a new question that has little to do with bricks or square meters: how digitally secure are all these systems actually? And does anyone know exactly which digital products are part of the building?
At the European level, a new piece of regulation is being added: the Cyber Resilience Act, or CRA for short. This article explains what the law entails and why it is becoming increasingly relevant for real estate, even though it targets products rather than buildings. This is explicitly not legal advice, nor a claim that every building falls under all its obligations.
What is the Cyber Resilience Act?
The Cyber Resilience Act is European legislation for the cybersecurity of hardware and software products with digital elements. The idea is simple: digital products should not only function, they should also be designed, maintained and supported securely. The CRA therefore sets requirements throughout the entire lifecycle of a product.
The regulation places responsibilities on manufacturers. Among other things, they must develop securely, address vulnerabilities and make security updates available. To keep these terms understandable, here is a brief explanation.
- Cybersecurity: digital security.
- Vulnerability: a weak spot in software or hardware.
- Security by design: digital security is factored in from the design stage onward.
- Security update: a software update that resolves a security issue.
- Product with digital elements: hardware or software that can be directly or indirectly digitally connected.
- CE marking: a marking with which a manufacturer indicates that a product meets applicable European requirements.
The CRA therefore focuses on the product, not on the building in which that product ends up. Yet this distinction is less sharp than it appears, and that is precisely what makes the law interesting for real estate. Official information can be found at the European Commission and the Dutch NCSC.
Why is the CRA relevant for real estate?
The CRA is about digital products. Modern buildings contain increasingly more of those products. As a result, the cyber resilience of technology indirectly becomes more relevant to the quality and management of real estate, even though a building as such does not fall under the law.
A building used to consist mainly of stone, steel and installations. A modern building increasingly consists of stone, installations, software, sensors, networks and data. Put more simply: a building is increasingly acquiring a digital layer. A door can be digital, a thermostat connected, a camera hangs on the network and a charging point contains software.
This raises a real estate question that was barely asked until recently: who actually knows which digital products are part of the building, and how secure and up to date those products are? This question touches on the broader theme of cybersecurity in real estate, which for a long time remained outside the scope of the property market.
More connected technology in a building does not automatically mean more quality. It mainly means more digital dependency that someone needs to keep managing.
From Smart Building to cyber resilient building
The real estate market talks extensively about Smart Buildings, IoT, AI, building data, smart sensors and automation. But more connected technology also means more digital dependency. A Smart Building is therefore not automatically a digitally sound building.
The systems in such a building also need to be secure, maintained, updated, manageable and transparent. A building does not become smarter simply by adding more technology. It becomes smarter when that technology is applied securely, manageably and understandably. This aligns with the idea that IT infrastructure forms the foundation of a Smart Building.
Security by design, with a real estate metaphor
When designing a building, we already think about fire safety. We don't build the building first and only afterward decide where the emergency exits should go. Digital security should work according to the same principle.
Not: build the building, install the technology, arrange security later. But: design, determine the digital infrastructure, factor in security, install, manage and maintain. Digital security should not be pasted onto a building afterward, any more than an emergency exit is.
Curious about your building's IT-label?
Discover how your property scores on digital infrastructure.
Request IT-labelA digital product does not stop after delivery
This is a fundamental difference between traditional building products and digital products. A steel beam does not change after installation. A digital product does: vulnerabilities can be discovered, software updates appear, security updates become necessary and new threats emerge.
That is why it matters not only what has been installed, but also who keeps it secure and for how long it will be supported. The NCSC indicates that the support period in principle covers the expected service life of a product, with a minimum, and that security updates for discovered vulnerabilities must be made available free of charge. Always check the exact conditions with the official source.
A building can last for decades. Digital products often last much shorter. That creates a tension: what happens when the building still has 30 years ahead of it, but a digital system is no longer supported after just a few years? This touches on asset management, technical management and multi-year maintenance planning in the MJOP.
Who is responsible for digital security?
In a rented property, a digital system can be managed or owned by the landlord, the tenant, the property manager, an IT supplier, an installer, a telecom provider or a Smart Building supplier. Who installs the system is one question. Who keeps it digitally secure afterward is another.
Think of updates, passwords, access rights, monitoring, incidents, replacement and support. This digital demarcation is becoming increasingly important, and is closely related to the question of who is responsible for the IT infrastructure in a building.

This question of responsibility also comes up during real estate transactions. When renting or buying, we ask about the energy label, the installations, maintenance, technical condition and service costs. But do we also ask which connected systems are present, what software runs on them, whether those systems are still supported and who is responsible in the event of a vulnerability? These are questions that, according to IT-Label, are becoming increasingly relevant in digital due diligence.
CRA, NIS2 and the IT-label: what is the difference?
These concepts are easily confused, but they serve different purposes. In short: the CRA looks at the product, NIS2 looks at the organization, and the IT-label makes the digital real estate layer understandable. They can overlap, but they are not the same thing.
The CRA mainly looks at products with digital elements that are placed on the European market. The NIS2 Directive, implemented in the Netherlands as the Cybersecurity Act, looks at the digital resilience of organizations and essential or important services. The IT-label looks at the digital delivery level and digital quality of real estate. You can read more about the organizational side in our article on the Cybersecurity Act and the digital building layer.
| Framework | What does it look at? |
|---|---|
| CRA | Products with digital elements |
| NIS2 / Cybersecurity Act | Digital resilience of organizations |
| IT-label | Digital delivery level and quality of real estate |
It is important to emphasize: an IT-label does not prove that a building is CRA compliant and is not a statutory CRA certification. The CRA and the IT-label serve different purposes, but they touch on the same development: digital quality is becoming less and less optional.
Curious about your building's IT-label?
Discover how your property scores on digital infrastructure.
Request IT-labelKey dates of the Cyber Resilience Act
The introduction of the CRA takes place in phases. This allows organizations and manufacturers to prepare step by step, but the first concrete obligations are approaching faster than is often assumed.
- 10 December 2024: the CRA entered into force.
- 11 September 2026: the reporting obligations for manufacturers will apply.
- 11 December 2027: the CRA becomes fully applicable.
These dates come from official European information. Always use the most current official sources, such as the European Commission, the NCSC and the Radiocommunications Agency's digital infrastructure inspectorate, to verify them when making decisions.
Why this matters now
The date of 11 September 2026 makes this topic current. From that point on, the reporting obligations will apply. This is a good moment to ask the real estate sector a broader question: do we actually know which digitally connected products our buildings contain? And do we know who is responsible when a vulnerability is discovered in them?
Cybersecurity is becoming part of real estate quality
Cybersecurity used to be mainly a matter for the IT department. But as buildings become dependent on digital systems, cybersecurity also touches on business continuity, safety, user experience, management, maintenance, lettability and future readiness.
Cybersecurity is thus slowly shifting from a purely IT issue to a component of real estate quality. This does not mean every real estate professional needs to become a cybersecurity specialist. Quite the opposite: complex digital information needs to be made understandable for real estate. This aligns with the idea that digital infrastructure is becoming a value driver of real estate.
A digital passport for a building should therefore not only indicate which technology is present, but also provide insight into system type, supplier, connectivity, management, responsibility, support, service life and replaceability. This makes visible what is currently still invisible.
How cyber resilient is your building?
The question "does my building comply with the CRA?" is legally too simplistic, because the law targets products. Better questions are: which digital products are actually in my building, who manages them, who keeps them secure, and how long will they be supported? The questions below can help with this.
- Which connected digital systems are present?
- Which systems are connected to the internet or the internal network?
- Who are the suppliers?
- Who manages the systems?
- Who installs security updates?
- How long will the products be supported?
- What happens when support ends?
- Who is responsible in the event of a vulnerability?
- Is it clear which systems communicate with each other?
- Is this information recorded centrally?
If you cannot answer several of these questions, that may well be the most important outcome of this checklist. The insight that the information is missing is often more valuable than the individual answers.
Curious about your building's IT-label?
Discover how your property scores on digital infrastructure.
Request IT-labelFrequently asked questions
What is the Cyber Resilience Act?
The Cyber Resilience Act (CRA) is European legislation for the cybersecurity of hardware and software products with digital elements. Among other things, the law requires manufacturers to develop securely and address vulnerabilities throughout a product's lifecycle.
When does the CRA take effect?
The CRA entered into force on 10 December 2024. The reporting obligations apply from 11 September 2026, and the regulation becomes fully applicable on 11 December 2027. Always check these dates with official sources.
Does the CRA apply to real estate?
The CRA targets products with digital elements, not buildings directly. Because modern buildings contain increasingly more of these products, insight into cybersecurity and service life is becoming more relevant for real estate.
Which products fall under the CRA?
The CRA covers hardware and software products with digital elements that are placed on the European market and can be directly or indirectly connected. Think of software, routers, cameras, sensors and other connected equipment.
What does the CRA mean for Smart Buildings?
A Smart Building contains many connected systems that may fall under the CRA. This makes it important to know which systems are present, who manages them, and how long they will keep receiving security updates.
What is security by design?
Security by design means that digital security is factored in from the design stage onward, rather than added afterward. Compare it to fire safety: emergency exits are planned during design, not after construction.
What is the difference between the CRA and NIS2?
The CRA looks at products with digital elements. NIS2, implemented in the Netherlands as the Cybersecurity Act, looks at the digital resilience of organizations and services. The frameworks can overlap, but they have a different starting point.
What role can the IT-label play in real estate cybersecurity?
The IT-label is not a CRA certification and not proof of compliance. It makes the digital delivery level and digital infrastructure of real estate visible, including topics such as connectivity, redundancy and cybersecurity, and helps raise the right questions earlier in the process.
How to take the next step
We are making buildings smarter, more connected, more data driven and more automated. As a result, we also need to make them more secure, more transparent and better manageable. The future of real estate is not only about how much technology a building has, but also about how secure and future ready that technology is.
So do not start with the law, start with insight. Map out which connected systems your building contains, who manages them, and how long they will be supported. If you would like to see that digital reality translated into understandable real estate terms and a clear delivery level, take a look at how the IT-label works and what information a classification provides. That way, you make visible what is currently still invisible.


