The front door remains the primary access point during a break-in. In light of this observation, the high-security lock market is evolving rapidly, driven by innovations that combine mechanical resistance and digital technologies. The regulatory framework itself is transforming: the classic A2P certification, focused on physical robustness, now coexists with new requirements related to the cybersecurity vulnerabilities of connected locks.
A2P@ Certification and Digital Risks: What the CNPP Evaluation Changes
The A2P certification, issued by the CNPP, classifies locks according to their resistance to mechanical break-ins. There are three levels, from the most accessible to the most resistant. This standard has long been sufficient to guide the choices of individuals and insurers.
The A2P@ certification now incorporates digital attacks into its scope. It evaluates the connected lock as a whole: physical mechanism, communication protocols, and software layer. A product certified A2P@ has therefore been tested against traditional forcing attempts, as well as against intrusions via the network or control application.
For individuals considering the solutions from Serrurerie Valbusa, it is possible to identify equipment that complies with these recent standards, whether they are traditional multi-point locks or connected models.
Field feedback varies on this point: not all installers are yet familiar with the specifics of this mixed certification. Checking the standard and the list of certified products directly with the CNPP remains the most reliable approach before any purchase.

Cyber Resilience Act: New Obligations for Connected Locks in Europe
The European Cyber Resilience Act (CRA) imposes obligations on manufacturers of connected devices regarding cybersecurity. Connected locks fall within its scope as soon as they incorporate digital elements linked to a device or network.
Specifically, manufacturers will need to monitor software vulnerabilities and provide security updates throughout the reasonable lifespan of the product. This point deserves attention: a connected lock without updates becomes a vulnerability after a few years, even if its physical mechanism remains intact.
The question of the duration of software support is rarely addressed at the time of purchase. A mechanical cylinder certified A2P can function for decades without intervention. A connected lock, however, depends on the manufacturer’s longevity and its software maintenance policy.
What the CRA Does Not Resolve
The regulation sets a framework, but the available data does not yet allow for measuring its real impact on the quality of marketed products. The first concrete effects will depend on the rigor of inspections and penalties applied to non-compliant manufacturers.
Connected Lock and Home Insurance: The Trap of the Replaced Cylinder
Installing a connected lock does not automatically guarantee the maintenance of the conditions of your insurance contract. The technical distinction is as follows:
- A connected lock installed on the surface retains the existing cylinder. If this cylinder was certified, the certification of the whole remains valid in principle.
- A model that replaces the original cylinder may eliminate the certification of the initial equipment. The insurer may then consider that the door no longer meets the contract requirements.
- The determining factor is not the brand or type of lock, but the compliance of the entire installation with the specific conditions of the insurance contract.
Before any installation, it is essential to review the specific conditions of your home insurance. Some contracts explicitly require a certified A2P multi-point lock. Others are satisfied with a more vague mention of the level of protection. In any case, contacting your insurer to validate compatibility avoids unpleasant surprises in the event of a claim.

Mechanical Protection and Digital Protection: Two Distinct Evaluations
Recent recommendations emphasize a often overlooked point: the physical resistance and cybersecurity of a connected lock must be evaluated separately. A lock can achieve an excellent level of resistance to picking while using an outdated Bluetooth protocol, vulnerable to interception.
The criteria to check are divided into two categories:
- On the mechanical side: A2P certification level (one, two, or three stars), number of locking points, quality of the cylinder, and resistance to drilling.
- On the digital side: communication protocol used (Bluetooth, Wi-Fi, Zigbee), encryption of exchanges between the lock and the application, frequency of software updates, and manufacturer’s support policy.
- On the insurance side: compatibility of the entire system (lock, cylinder, door) with the contract requirements, rather than isolated certification of a component.
This dual evaluation framework remains little known among consumers. Most buying guides focus on user comfort (smartphone opening, temporary access sharing) without detailing the robustness of encryption or the duration of software support promised by the manufacturer.
Multi-Point Lock or Connected Lock: Not Always a Binary Choice
Some devices allow adding a connected layer to a already certified multi-point lock, without replacing the cylinder. This hybrid approach maintains the level of mechanical protection while adding remote access management. It also limits the risk of losing insurance compliance.
However, these hybrid solutions depend on the compatibility between the existing cylinder and the connected module. Not all cylinder formats are supported, and installation may require the intervention of a qualified locksmith to ensure proper operation.
The high-security lock market stands at the crossroads of two logics: proven physical robustness developed over decades and newer digital security, still in the process of being structured. The Cyber Resilience Act and A2P@ certification lay down milestones, but the final choice rests on the verification of each component (mechanical, software, insurance) rather than on a broad marketing promise.



