Category: articles | 30 July 2026

Your AV Tender Has a September Deadline You Have Not Written In

Brian Iselin

Brian Iselin

News and Trends Writer (EMEA), AVIXA

View Author

The contract you sign this summer to install AV in a conference centre, a hospital ward, or a university lecture theatre will still be governing that equipment in 2029. The manufacturer who supplied the codec, the networked display, and the DSP will be operating under new legal obligations beginning on 11 September 2026. In most tenders dropping right now, there is not a single clause that acknowledges this.

The Cyber Resilience Act (CRA) entered into force in December 2024. Its full product compliance requirements apply from December 2027. But the vulnerability reporting obligations — the part that governs how a manufacturer responds when something goes wrong in a deployed system — apply as of 11 September 2026. Tenders going out this month will close before that deadline. The products they specify will be in service well after that date.

This is not about your own compliance. It is about what you demand of your supply chain before you award the tender.

What the 24-Hour Clock Actually Means

Under Article 14 of the CRA, manufacturers of products with digital elements must notify the European Union Agency for Cybersecurity (ENISA) and their designated national Computer Security Incident Response Team (CSIRT) within 24 hours of becoming aware of an actively exploited vulnerability. That is the early-warning duty. A fuller technical notification follows within 72 hours. A final report, including any corrective or mitigating measures, is due within 14 days for actively exploited vulnerabilities or within one month for severe incidents.

The 24-hour clock starts from awareness, not confirmation. Manufacturers do not get to wait for a forensic conclusion before triggering the duty. The CRA defines active exploitation as a situation where a malicious actor makes use of a flaw — and if there is a reasonable belief that this is happening, the deadline is already running. For a company without automated vulnerability monitoring and a pre-cleared escalation path, discovering an exploited flaw on a Friday evening and filing with ENISA by Saturday morning is not merely a communications challenge. It is an operational capability most have not yet built.

EMBED VIDEO HERE: https://www.avixa.org/explore/videos/cybersecurity-in-av-regulation-responsibility-and-buying-decisions-barco

Fines for non-compliance reach €15 million or 2.5 per cent of global annual turnover, whichever is higher. The small-to-medium sized enterprise (SME) carve-out in Article 64 provides limited relief on the 24-hour early-warning timing — but only for companies with fewer than 50 employees and turnover below €10 million, and only for that one element. The 72-hour detailed notification carries no SME relief at all. Most AV manufacturers supplying enterprise and institutional projects in Europe fall outside the carve-out entirely.

There is also a user notification duty. Manufacturers must tell the users of affected products without undue delay. In AV terms, a manufacturer discovering a vulnerability in a deployed collaboration endpoint or networked display is not just reporting to regulators. They are legally obliged to notify the organisations running those systems. If you manage an estate of that equipment on behalf of a client, that notification is your responsibility to act on — and your contract determines what you do with it.

Why AV Products Are Squarely in Scope

The CRA defines a product with digital elements as any software or hardware product — including components placed on the market separately — that processes, stores, or transmits digital data. Conference room cameras. Networked DSPs. Codecs. Digital signage players. AV-over-IP encoders and decoders. Room booking panels. Control processors. Every one of these products sits in scope, and there is no threshold of connectivity below which the obligation disappears.

AVIXA has a dedicated webinar, Strengthening Cybersecurity in Digital Signage, which examines how the CRA and ETSI EN 303 645 — the IoT cybersecurity standard now underpinning both EU and UK regulatory requirements — are reshaping what signage network procurement looks like. The regulatory picture is more detailed than most integrators currently account for. It is worth an hour of your time before the next signage spec lands on your desk.

The reporting obligation applies to all in-scope products on the EU market — including those placed there before December 2027. Legacy equipment is not exempt. Age is not a defence. The codec your client installed three years ago, running on a firmware branch the manufacturer has quietly deprioritised, carries the same Article 14 exposure as a product shipped today. If a vulnerability in that device is actively exploited after 11 September 2026, the manufacturer’s 24-hour duty fires. 

The reporting obligation is also not filtered by product classification tier. The CRA categorises products into default, Important Class I, Important Class II, and Critical tiers, with different conformity assessment routes for CE marking. But Article 14 reporting applies to all in-scope products regardless of classification. A standard conference room display carries the same 24-hour duty as a product on the critical list.

The Gap in Your Current Tender Templates

Pull out a tender template you have used in the past twelve months for an enterprise AV project. Find the section on manufacturer obligations, software maintenance, and incident notification. Now read it against three questions: does it require the manufacturer to notify you within a defined timeframe if an actively exploited vulnerability is discovered in a supplied product? Does it require evidence of a tested vulnerability management process? Does it specify who gets notified — the end client, the integrator, or both?

For most templates, the answer to all three is no. The reason is simple: before the CRA, there was no mandatory reporting clock. Security patching obligations existed in some government and critical infrastructure contracts. But a 24-hour early-warning duty tied to a named regulation, backed by eight-figure fines, is new. The template has not caught up.

Tenders dropping in May, June, and July will govern installations running into the late 2020s. A contract signed before September without these clauses operates in a regulatory gap from the moment Article 14 comes into force. The products do not know that. The fines do not know that. Your client certainly does not know that.

The AVIXA Recommended Practice for Security in Networked Audiovisual Systems sets out what sound security governance in AV looks like across a project lifecycle. Use it as a baseline reference when building supplier questions and evaluating the responses you get back.

Six Questions for Every Supplier Submission

These are not aspirational — they are the minimum due diligence for any AV procurement covering networked products placed on the EU market after September 2026.

1. Does your organisation have a documented, tested vulnerability management process for the products in this tender?

Ask for evidence. A policy that exists on paper but has never been exercised in  a live incident will not get a manufacturer through a 24-hour window.

2. How will you notify the contracting authority and appointed integrator if an actively exploited vulnerability is discovered in a supplied product?

Name the channel, the responsible individual, and the maximum elapsed time. The CRA gives manufacturers 24 hours to reach ENISA. You should hear from them faster.

3. Do you maintain a software bill of materials (SBOM) for the products in this tender?

 The CRA’s Annex I requires manufacturers to identify and document all components in their products in a machine-readable format. Without an SBOM, a manufacturer has no reliable method to determine whether a published CVE affects a specific product in a specific deployment. That gap makes the 24-hour clock functionally impossible to meet without guesswork.

4. What is your declared security update support period for these products, and what happens at end-of-life?

The CRA requires manufacturers to handle vulnerabilities across the product lifecycle. A manufacturer who stops issuing security patches before your installation reaches the end of its useful life is not meeting that obligation — and the operational shortfall lands with you.

5. Will you have a registered point of contact on the ENISA Single Reporting Platform by 11 September 2026?

ENISA is building the platform now, with a testing period before the deadline. A manufacturer who cannot confirm this is signalling something about the state of their September readiness.

6. If emergency patching is required during a contracted service period, who deploys it, within what timeframe, and at whose cost?

The CRA mandates reporting. It does not mandate that remediation is free. Your contract does — or should. Make sure it says so explicitly.

What This Means If You Are in the Middle

Integrators sitting between the manufacturer and the end client are where the operational weight lands. If a manufacturer reports a vulnerability to ENISA and notifies the user, and that user is your client, you need a clause in your managed service or maintenance agreement that defines your role. Patch deployment authority. Advisory obligations. Liability exposure if you do not act quickly enough. These are not hypotheticals — they are the questions your client’s legal team will ask after the first incident.

None of this requires a lawyer at the tendering stage. It requires the right questions in the right section of the supplier submission document. The answers will also give you a useful read on manufacturer maturity. A supplier who cannot answer these six questions before September 2026 will not suddenly become capable of hitting a 24-hour deadline after that date. 

The NIS2 piece in February and the Product Liability Directive piece in April covered what regulators expect of AV operators and integrators. The CRA completes the triangle: what you now need to require of your supply chain. Each regulation creates obligations pointing in a different direction. A procurement contract drafted as if it were still 2022 now carries exposure from three directions simultaneously — and none of those directions cares when the contract was last reviewed.

Raise this with clients who hold the procurement decision but depend on you for specification. A hospital facilities manager signing off on a collaboration system this July has no reason to know that their new equipment will fall under a mandatory vulnerability reporting regime in seven weeks. Surfacing that, and helping them frame the supplier questions, is exactly the kind of work that distinguishes a specifier from an order-taker. The conversation is not difficult. The contract clause it produces is not expensive. Skipping both of them will be.

My Verdict

The December 2027 date is not your deadline. It really never was. From 11 September 2026, manufacturers of networked AV products are under active legal reporting obligations for every vulnerability actively exploited in systems running in the EU — including the ones you specified and the ones your clients are still running from three years ago. Add the six questions above to every tender involving networked AV before that date. If a manufacturer cannot answer them, that is not a compliance gap for them to fix later. It is a procurement risk for you to manage now.

Solutions in this article