
Buy the controller, app, cloud service and support promise as one system.
Map seven layers: hardware, firmware, app, cloud, accounts, installation and incidents.
Every installer and operator should have attributable access that can be removed.
Cloud failure must leave a documented safe local state, not a guessing exercise.
CRA reporting starts on 11 September 2026 for products that fall within its scope.
A CE mark doesn't replace the exact declaration, scope analysis and support end date.
Remote control removes a walk to the cabin, but it also creates an access path to a hot appliance. We build finished saunas rather than loose projects, so I apply the same discipline to the digital chain. By the end, you'll have a written question set that exposes who owns access, outages, updates and incidents before the order is placed.
The cybersecurity questions to ask about a remote sauna start with who owns every digital layer: controller hardware, firmware, mobile app, cloud account and remote-start permissions. Demand written answers on unique accounts, access removal, security updates, the support end date, vulnerability reporting, outage behaviour, local control, data deletion and incident notices. Ask which EU rules apply to the exact product configuration. A Wi-Fi badge and a CE mark don't answer these questions. If the supplier can't map responsibility, you're inheriting an unmanaged access path.

Real heater and product context showing the physical appliance layer. The pictured heater is not presented as a remotely controlled model.
The controller on the wall is only the visible part. Remote control may also depend on firmware, a phone app, an account service, a cloud platform and an internet connection. If one of those belongs to another company, the commercial product has more than one technical owner.
That doesn't make the system poor. It makes the boundary important.
The EU Cyber Resilience Act covers commercially supplied products with digital elements. It applies when the product's intended or reasonably foreseeable use includes a data connection to a device or network. That connection can be direct or indirect, logical or physical.
Its legal text also explains that a manufacturer's remote data-processing solution can fall inside the product boundary when the product needs it to perform a function. That includes some app and cloud arrangements. Read the official Regulation (EU) 2024/2847, then ask the supplier how it mapped the exact configuration you are buying.
Do not declare the complete sauna "CRA compliant" from a controller brochure. The supplier must first identify the product, its digital components, the responsible economic operators and any other applicable legislation. That analysis is specific. A generic logo isn't.
Put a company name beside every layer. Then put a document beside the company. The result should survive staff turnover, an installer leaving the market and the property changing hands.
Layer | Question to answer in writing | Evidence to keep |
|---|---|---|
Controller hardware | Who placed this exact model on the EU market? | Model identity and EU declaration of conformity |
Firmware | Who signs, distributes and tests security updates? | Update policy and supported version record |
Mobile app | Who publishes it, and what happens if it is withdrawn? | Publisher identity and fallback instructions |
Cloud service | Who operates it, and which functions depend on it? | Service description and outage route |
User accounts | Who creates, reviews and removes access? | Named administrator and access register |
Installation | Who commissions remote access for this site? | Dated commissioning and handover record |
Incident response | Who receives a vulnerability report and tells operators? | Reporting contact and notification process |

Fill every owner and evidence blank before installation handover. A blank box is an unresolved responsibility.
A component brand isn't a responsibility map. Wood Architects fits established heater brands such as Harvia and HUUM, but that approved company fact says nothing about a particular controller's cyber scope or support. The exact model and configuration still need their own file.
So, what cybersecurity questions should you ask about a remote sauna? Ask for the responsibility file, not a promise that "the app is secure".
Ask for a live demonstration using a new site account. The supplier should show how the first administrator is created, how another user is added, what each role can do and how access is revoked. Shared installer credentials are a poor handover because nobody can tell who acted or remove one person cleanly.
Here's how you check it. Create a temporary user. Give that user only the rights needed for daily operation. Remove the user. Confirm that the old session and any saved device access no longer work. Keep a screenshot or exported record with the commissioning file.
Ask the same question about ownership transfer. A hotel changes managers. A holiday property changes operator. A private cabin changes owner. The old administrator must not remain the invisible master account.
The CRA's published requirements point in the same direction. For products in scope, Annex I includes secure-by-default configuration, protection from unauthorised access and mechanisms for secure updates. ENISA's Secure by Design and Default Playbook, published on 30 July 2026, turns those principles into repeatable work for smaller organisations.
Remote convenience must fail into a known state. Ask the supplier to disconnect the internet during commissioning and show what remains possible at the cabin. The answer must separate three failures: the phone cannot reach the internet, the vendor cloud is unavailable, or the physical controller has lost communications.
For each failure, record whether the heater continues, stops or stays locally controllable. Record how the operator sees the fault. Record the authorised recovery step. Do not accept "restart everything" as the whole procedure.

Separate the failed layer, then use only the local functions allowed by the selected product instructions.
Cybersecurity doesn't replace electrical safety or the product's remote-start safeguards. The electrician and product installer still need the exact instructions for the selected heater and controller. Our separate guide to wiring an outdoor sauna heater explains why the connection and commissioning file matter.
Ask for a written scope analysis, not a one-word claim.
As of 17 August 2026, the CRA's reporting duties start on 11 September 2026 for products that fall within its scope. The main obligations apply from 11 December 2027.
The Commission's current manufacturer guidance describes risk assessment, technical documentation, support periods and vulnerability handling. Its reporting page states that an early warning is due within 24 hours and a full notification within 72 hours for reportable cases.
Radio equipment has a second transition to understand. Delegated Regulation (EU) 2022/30 has applied defined cybersecurity requirements to specified classes of radio equipment since 1 August 2025. For example, one requirement applies to internet-connected radio equipment.
A Commission act adopted on 16 February 2026 is intended to repeal that delegated regulation from 11 December 2027 to avoid overlap with the CRA. Whether the controller you are buying falls within today's RED scope depends on its radio and data functions. The official Delegated Regulation (EU) 2022/30 is the place to start.
A CE mark alone is not an EU approval badge. The Commission says it is the manufacturer's declaration that applicable CE requirements are met. Ask for the declaration itself and check which acts, model numbers and standards it names. The Commission's CE marking guidance makes that responsibility clear.
Copy these questions into one email. Require one coordinated reply for the complete remote-control configuration, not seven unrelated brochures.
What are the exact model and software identifiers for the controller, app and cloud service?
Which company owns security for each layer, and where can vulnerabilities be reported?
Which EU laws apply to this exact configuration today, and what evidence supports that conclusion?
What is the security-support end date, and how will customers receive update notices?
Are accounts unique, role-based and removable, including old installer access?
Which functions depend on the internet or vendor cloud?
What does the physical controller do during each communication failure?
How is ownership transferred and old access removed?
How can operating data and credentials be deleted at decommissioning?
Who informs the buyer after a relevant vulnerability or severe security incident?
You don't need a penetration test before every order. Start with this reply, the exact declaration, the update policy and a witnessed outage test. Put them beside the electrical commissioning record. If those four items don't agree, remote control is still a promise, not a supported product.
Not automatically. The CRA covers commercially supplied products with digital elements that have direct or indirect data connections, but the exact product boundary and exclusions still require assessment. Reporting duties for in-scope products begin on 11 September 2026. The main obligations begin on 11 December 2027.
No. CE marking is the manufacturer's declaration of conformity with the EU requirements applicable to that product. It doesn't show a buyer which cyber legislation, model or software configuration was assessed. Ask for the EU declaration of conformity, the written scope analysis and the security-support end date.
Yes, where the system supports named accounts. Separate access lets the administrator remove one installer without changing every user's routine and provides a clearer activity trail. Ask the supplier to demonstrate account creation, restricted permissions, revocation and ownership transfer before the commissioning record is signed.
The cabin should enter a documented state that the operator can identify and manage locally. The supplier must explain separately what happens when the phone, internet connection, vendor cloud or controller link fails. Test those states during commissioning and keep the recovery instructions at the physical sauna.
The supplier's file should name a vulnerability contact, the responsible manufacturer and the route for telling operators. Under the CRA, manufacturers of in-scope products face specific reporting duties from 11 September 2026. Buyers still need their own contact chain so that a platform notice reaches every installed site.
Get an email when Giedrius publishes
More from
Giedrius Patlaba →Should Your Outdoor Sauna Use Tiles Over a Heated Mat?
Key Takeaways Heated tile can work, but its most important downside is ownership: the cable, sensor and wet-area interfaces disappear below a rigid finish. Official records include a bathroom fire believed to have been caused by an electrical fault in underfloor heating and…
Should Your Prefabricated Outdoor Sauna Have a Tiled Floor?
Key Takeaways Ceramic and porcelain tiles are finishes, not complete waterproof floors. Bonded tile asks a lightweight timber module to behave like a rigid wet room. The structure, dead load, drainage, waterproofing and movement joints must be designed together. Low water…
What National Rules Apply After Your Sauna's CE and DoP Review?
Key Takeaways CE marking reports declared product performance, not automatic approval of a sauna project. First confirm whether each construction product is covered by the applicable CPR route. Compare declared performance with the destination's requirements for the intended use…