- Johnson Controls
- Trust Center
- Trust Center website update
Trust Center
EU Cyber Resilience Act (CRA)
The EU Cyber Resilience Act (CRA) is a landmark regulation designed to strengthen cybersecurity across the European Union by setting mandatory requirements for products with digital elements (PDEs)— including hardware, software, and connected devices.
- What is the EU Cyber Resilience Act?
- Purpose: To ensure that all digital products sold in the EU are secure by design and remain secure throughout their lifecycle.
- Scope: Applies to nearly all connected products, including IoT devices, embedded systems, cloud-based software, and industrial equipment.
- Key Requirements:
- Products must be free of known vulnerabilities at launch.
- Manufacturers must provide security updates throughout the product’s lifecycle.
- A Software Bill of Materials (SBOM) must be maintained and disclosed.
- Vulnerability reporting mechanism must be in place.
- Products must be configured securely by default.
-
Johnson Controls Product Lifecycle Information
We believe in transparency and helping our customers plan with confidence. Here you will find lifecycle details for our product range, from launch through to end of patching. Each product includes:
Release Date – Initial Product release date
End of Patching – The date after which security updates and patches are no longer provided, along with guidance on upgrade or replacement product.
CRA conformity – Certificate of conformity for the EU Cyber Resilience Act Market
By sharing this information, we aim to help you maximize product value, ahead of transitions, and make more sustainable decisions.
-
Johnson Controls Cybersecurity
Cyber Solutions
Johnson Controls -
Digital Services and Solutions
Digital Services and Solutions Product Name Version Initial Release Date End of Patching (EOP) Date Replacement Product Information OpenBlue Cloudvue Rev A 01/01/2020 01/01/2024 Cloudvue v2 OpenBlue Companion Rev B 06/02/1999 11/20/2025 Companion -
Controls / HVAC
Controls / HVAC Product Name Version Initial Release Date End of Patching (EOP) Date Replacement product information Metasys Release 14.1 02/03/2015 06/09/2025 Upgrade Instructions YORK YZ/YK AA 7/15/2021 5/9/2026 Link -
Security
Security/Tyco Product Name Version Initial Release Date End of Patching (EOP) Date Replacement product information Illustra Gen4 LPR Camera 2.1 01/01/2020 01/01/2024 Pro Gen4 LPR Camera v2.0 Illustra Pro Flex 1.0 06/02/1999 11/20/2025 Cameras -
Fire
SafeLINC
-
Product Lifecycle Announcement
The CRA introduces mandatory cybersecurity requirements for products with digital elements sold within the EU. These include secure-by-design principles, vulnerability management, software transparency, and long- term support obligations. Johnson Controls is committed to meeting these standards across our portfolio of connected products and services.
- Our Compliance Efforts Include:
- Conducting a comprehensive audit of all applicable products
- Integrating secure-by-default architecture into product development
- Establishing robust vulnerability reporting and patching protocols
- Maintaining Software Bills of Materials (SBOMs) for transparency
- Collaborating with EU regulatory bodies and industry partners
We view the CRA not only as a regulatory requirement but as an opportunity to reinforce our commitment to cybersecurity, customer trust, and operational excellence. Our teams are working diligently to meet all CRA milestones ahead of the enforcement deadlines, with vulnerability reporting obligations beginning September 2026 and full compliance required by December 2027.
For questions or additional information, please contact our EU CRA Compliance Team at TrustCenter@jci.com.

















.jpg?la=en&h=320&w=720&hash=244C75B74F0F77521D56164450973BCD)














.jpg?la=en&h=310&w=720&hash=8D9823F26AA80B2B75C3E4B2E61770DC)


.jpg?la=en&h=320&w=719&hash=13CA7E4AA3E453809B6726B561F2F4DD)
.jpg?la=en&h=306&w=720&hash=F21A7CD3C49EFBF4D41F00691D09AEAC)

.png?la=en&h=320&w=720&hash=18CFCCD916C92D922F600511FABD775D)


