Three key EU legal acts – the EPBD, NIS2 and CRA – all of which are directly relevant to the building automation industry, are currently being implemented in 27 different ways, with 27 sets of national interpretations, and with a compliance burden that hits the smallest players the hardest. This is not simply bureaucratic inefficiency – it is a real trade barrier that weakens the EU's competitiveness.
| 27 National interpretations of the same EU directives | 713 billion. Euro and potential GDP contribution from removing internal market barriers (European Parliament) | 4 27 EU countries' NIS2 implementation deadline October 2024 | 15 million. euro — maximum fine for non-compliance with CRA |
The internal market — the promise and the reality
The EU’s internal market is one of the world’s most ambitious trade constructs: one set of rules, 27 markets, free competition. The reality is somewhat different. The European Central Bank documented in 2026 that barriers within the internal market originate from four primary sources: differences in national rules, burdensome administrative procedures, inconsistent application of EU rules, and “gold-plating” – where member states add extra national requirements on top of EU directives.
For an industry such as building automation — technically complex, heavily regulated, and with products sold and installed across national borders — the consequences are significant. A Danish system integrator wishing to offer its services in Sweden, Norway, or the Netherlands does not encounter one set of regulations, but three.
EPBD: A directive — 27 building regulations
The EU's Energy Performance of Buildings Directive EPBD (Directive 2024/1275) came into force on 28 May 2024 and must be transposed into national legislation in all EU countries by 29 May 2026. Buildings account for 40 percent of the EU's energy consumption, and 75 percent of the existing building stock is not energy-efficient — the directive is necessary and justified.
The problem arises in the transposition. The EPBD is a directive, not a regulation, and explicitly allows countries to go beyond minimum requirements. In practice, this means that the same product may require separate documentation, certification, and adaptation in each country it is sold. A company selling BACS solutions in three EU countries must deal with three sets of national building regulations – all implementations of the same EU requirements, but with national additions and interpretations.
NIS2: Only 4 countries met the deadline
The NIS2 directive (Directive 2022/2555) had to be implemented nationally by 17 October 2024. For the building automation sector, NIS2 is directly relevant – Operational Technology (OT) systems such as HVAC controllers, lighting control, and access systems are explicitly within the directive's scope.
For a BACS provider operating in just three countries, this means three sets of requirements, three sets of documentation requirements, and potentially three sets of audits—even if all three are based on the same EU directive. The technical foundation for NIS2 compliance in OT environments is IEC 62443—the international standard for the security of industrial automation and control systems, recommended by ENISA.
CRA: A regulation — but with an SME challenge
The EU's Cyber Resilience Act (CRA, Regulation 2024/2847) is a regulation – not a directive – and therefore applies directly in all EU countries without national implementation. This resolves the transposition issues. However, it creates another problem: the compliance burden is proportionally far greater for SMEs than for large companies.
The CRA applies to all products with digital elements — practically the entire BACS product portfolio. Manufacturers must conduct cybersecurity risk assessments, secure products in a secure default configuration, manage vulnerabilities throughout the product's lifecycle, report incidents to ENISA within 24 hours, and retain technical documentation for at least 10 years.
| 11 September 2026 | Requirements for vulnerability reporting apply |
| 11 December 2027 | All other CRA obligations apply |
| Fine for non-compliance | Up to 15 million euros or 2.5% of global turnover |
The Paradox: Regulation as a Competitive Advantage for Large Players
The EU's regulation is designed to create a level playing field. However, fragmented and complex regulation in practice benefits large players who have the resources to manage the complexity, and acts as a barrier for smaller players who do not. A large multinational manufacturer absorbs the CRA requirements relatively effectively. A Danish or Scandinavian SME with specialised BACS components faces the same absolute requirements – with a fraction of the resources.
What should happen
Three concrete improvements would make a significant difference: regulations rather than directives where harmonisation is the goal; mandatory SME impact assessments for all new compliance requirements; and a single European compliance framework for OT security in buildings based on IEC 62443 – recognised in all EU countries with one certification process valid across the entire market.
Frequently asked questions
What is the EPBD and what does it require of building owners?
The EPBD (Energy Performance of Buildings Directive, directive 2024/1275) entered into force on 28 May 2024. Among other things, it requires the installation of BACS in commercial buildings over 290 kW from 31 December 2024, and in buildings over 70 kW from 31 December 2029. The directive is implemented nationally – in Denmark via the Building Regulations.
What is NIS2 and is it relevant for building automation?
The NIS2 Directive (Directive 2022/2555) raises the cybersecurity level for critical infrastructure and essential sectors. For building automation, it is directly relevant – OT systems such as HVAC controllers, lighting control, and access systems are explicitly within the directive's scope. The technical foundation for compliance is IEC 62443, recommended by ENISA.
What is the Cyber Resilience Act and when does it apply?
The CRA (Regulation 2024/2847) applies to all products with digital elements – including practically the entire BACS product portfolio. Requirements for vulnerability reporting apply from 11 September 2026. All other obligations apply from 11 December 2027. Fines can reach up to €15 million or 2.5 percent of global turnover.
Hvad er forgyldning?
Gold-plating is when an EU Member State implements a directive with additional national requirements beyond the actual minimum requirements of the directive. The OECD defines it as “over-implementation of an EU directive through national requirements that go beyond the directive's actual requirements.” The European Commission has for years urged Member States to refrain from this practice – but it continues and creates real trade barriers.
Sources
- The European Central Bank (ECB): The untapped potential of the EU Single Market lies in several key areas: * **Deepening and Harmonising Regulations:** While the Single Market has removed many barriers, significant differences in national regulations and standards still exist. Greater harmonisation in areas such as digital services, environmental standards, and professional qualifications could unlock further economic integration and efficiency. * **Completing the Digital Single Market:** The digital economy is rapidly evolving, and the EU is still grappling with issues like data flows, cybersecurity, and fair competition for digital platforms. Further progress here could fuel innovation and create new business opportunities. * **Strengthening the Capital Markets Union:** A more integrated and deeper capital market would make it easier for businesses, especially SMEs, to access finance and for investors to allocate capital across borders. This could boost investment and economic growth. * **Improving Services Trade:** While goods trade has been largely liberalised, barriers to services trade remain more persistent. Addressing these, particularly in areas like business services, financial services, and creative industries, could yield significant economic benefits. * **Enhancing the Free Movement of People:** Fully realising the benefits of labour mobility, including mutual recognition of qualifications and better integration of mobile workers, can help address skills shortages and boost productivity. * **Leveraging the Green Transition:** The Single Market can be a powerful engine for the green transition by setting common standards for sustainable products and services and facilitating trade in green technologies and renewable energy. * **Expanding to New Members and Neighbours:** The potential impact of extending the principles of the Single Market to new member states or integrating neighbouring economies more closely could bring significant economic advantages to all involved. * **Making it More Resilient and Strategic:** In the face of global challenges, the Single Market's potential for fostering greater European resilience and strategic autonomy in critical sectors (e.g., healthcare, defence, raw materials) is immense. Essentially, the untapped potential comes from moving beyond the initial liberalisation of trade to a more integrated, harmonised, and future-oriented market that can adapt to new economic and societal challenges. Economic Bulletin, 2026. ecb.europa.eu
- The European Cyber Security Organisation NIS2 Directive Transposition Tracker (2025). ecs-org.eu
- ENISA: IEC 62443 as a framework for NIS2 compliance in OT environments. enisa.europa.eu
- European Commission Cyber Resilience Act (Regulation 2024/2847). digital-strategy.ec.europa.eu
- European Commission Energy Performance of Buildings Directive (2024/1275). EUR-Lex: CELEX:32024L1275
- Pinsent Masons EU takes ‘leap’ with new energy performance of buildings law (2024). pinsentmasons.com