At the centre of the guidance are five questions buyers of physical security technology should ask suppliers when reviewing product security, transparency and long-term support.

Five questions The first issue Genetec highlights is how long a product will receive security updates and support.

Under the rules, manufacturers must provide security updates and vulnerability handling for at least five years, making support periods a more prominent factor in purchasing decisions.

The final question is how providers support long-term cyber resilience.

It may also increase pressure on suppliers to show that product security is documented and maintained over several years.