ONVIF Updates Cybersecurity and Encryption Requirements with TLS Add-on 2.0 Release Candidate
ONVIF is increasingly using add-ons for security-related conformance requirements, which can be updated as technologies and threats change.
SAN RAMON, Calif. – September 9, 2026. ONVIF®, whose standards-based specifications make IP-based physical security products interoperable worldwide, today published the release candidate of the ONVIF TLS Configuration Add-on 2.0, the specification that gives manufacturers and users a standardized way to establish secure, encrypted communication between ONVIF conformant devices and video management systems. Version 2.0 adopts stronger methods of protecting that communication, keeping ONVIF standards aligned with current cybersecurity best practices.
Manufacturers, integrators and end users face growing expectations to demonstrate the cybersecurity of the devices they build, install and operate, from government guidance and regulation to procurement requirements. ONVIF conformance to the TLS Configuration Add-on gives manufacturers a common, testable approach to configuring TLS protection across products from different vendors. ONVIF is increasingly using versioned add-ons for security-related conformance requirements that must evolve as technologies and threats change.
Add-ons are flexible, support version handling and extend ONVIF conformance to features that address a specific use case or end user need. Profiles are permanent, fixed feature sets that a complete product can be built on, which preserves backwards compatibility for products already deployed in the field. Products must conform to an ONVIF profile before claiming conformance to an add-on, so the two are complementary.
“By publishing security requirements in add-ons rather than in profiles, ONVIF can respond to changes in the security needs without asking the industry to wait for a new profile cycle, or to rebuild systems that already work,” said Leo Levit, Chairman, ONVIF Board of Directors. “Our release candidates for the TLS Configuration Add-on 2.0 and the Profile V Security Add-on are both examples of that approach in practice.”
ONVIF has also applied the same cybersecurity approach with Profile V, its Release Candidate for cloud-based video surveillance. Profile V conformant products must implement the ONVIF Profile V Security Add-on, which defines authentication and authorization for cloud connections as well as encryption requirements for cloud recordings. ONVIF intends to apply this model to future profiles whose security requirements need to evolve independently.
The first ONVIF add-on to be introduced, the TLS Configuration Add-on lets a conformant video management system configure or update TLS settings in a conformant device.
ONVIF members can now access the TLS Configuration Add-on 2.0 Release Candidate and the associated test tools on the ONVIF Member Portal at https://members.onvif.org. ONVIF expects to release the final specification at the end of 2026.
About ONVIF
Founded in 2008, ONVIF is a leading industry forum driving interoperability for IP-based physical security products. With a global network of roughly 500 companies in the camera, video management system, and access control markets, ONVIF continues to expand the interoperability of physical security solutions.
For more information about ONVIF conformant products and member companies, visit www.onvif.org.
For press inquiries, please contact:
Andrea Gural
Eclipse Media Group on behalf of ONVIF
Phone: +1.207.233.7507
E-mail: agural@eclipsemediagroup.net