Secure communication

The path to enhanced cybersecurity

The Cyber Resilience Act (CRA) is an EU regulation designed to enhance the cybersecurity of products with digital elements. Starting December 11, 2027, all such products placed on the EU market must comply with the CRA requirements.

Your security is our priority

Stricter cybersecurity guidelines for heat pump manufacturers

In today’s digital world, heat pump manufacturers face the growing challenge of protecting their systems against cyber threats. Cybersecurity is no longer just a technical issue—it's a decisive factor for the long-term success and safety of your products and your customers.

Our advanced control solutions are the ideal response to these challenges. As a control system supplier for the heat pump industry, we understand the specific requirements and potential security vulnerabilities in your sector.

In line with cybersecurity regulations, we are committed to minimizing all attack vectors that hackers could exploit. In addition, we are dedicated to safeguarding connected devices within customer networks and continuously enhancing the security level of our products.

Our security strategy

Regular updates and encrypted communication

To ensure a consistently high level of security, we provide regular software updates to our customers that include critical security improvements. A fundamental step toward secure data transmission was the implementation of encrypted communication channels within the local network. This ensures that only authorized users can access the heating control system, with all communication fully encrypted.

Our proven KEBA remote maintenance solution, trusted for years, also ensures secure remote access via the internet—granted only to authorized personnel and protected by encrypted communication.

Moreover, data exchange between heating controllers in a heat pump cascade only takes place after the devices have been paired and mutually verified. This high level of security also applies to touchscreen remote controls, which can only connect once approved by an authorized user.

All of these enhancements have been made possible thanks to our extensive expertise in cryptography, allowing us to proactively prepare our hardware for future security requirements.

Why are we taking action today?

Because it’s no longer a question of if the Cyber Resilience Act will be enforced—it is already confirmed. EU member states are now tasked with incorporating the CRA into national legislation.

We began some time ago to adopt "best practice" approaches from other industries and apply them to heating control systems. This proactive work ensures ongoing software improvements both now and in the future—so that the transition remains manageable for our OEM partners and end customers.

Our top priority remains the ability to continuously deliver compliant products—meeting CE marking requirements and more—throughout and beyond 2027.

Discover our innovative heating controllers

Please select your preferred language
Your browser is out of date
Internet Explorer is no longer supported. Please switch to a current browser to use keba.com to its fullest extent.

Edge

Chrome

Safari

Firefox

KEBA - Automation by innovation.