The IoT Security Foundation (IoTSF) has today published a new practical guide to help organisations procure connected building technology securely, while balancing cybersecurity, sustainability, compliance and operational efficiency.

Building technology has changed significantly. Lighting, heating, ventilation, access control, lifts, CCTV, energy meters and other systems are increasingly connected to shared IP networks, creating new opportunities for efficiency and better data – but also introducing new cybersecurity risks.

The ‘Building technology procurement guide: Procuring building technology securely’ has been developed to help procurement teams, and the stakeholders they work with, address those risks from the very beginning of the procurement process.

The guide recognises that procurement decisions made today can determine the security, resilience and operational performance of building systems for many years to come. It, therefore, takes a lifecycle approach, encouraging organisations to consider security not as an additional requirement, but as an integral part of the business case for connected building technology.

Bringing the right people together

A central recommendation of the guide is the creation of a ‘Procurement Project Steering Group (PPSG)’ for individual building technology procurements.

The PPSG brings together the people who need to have a voice in the decision – including procurement, cybersecurity, IT and network teams, facilities and property, sustainability, physical security, legal and compliance, finance and the relevant risk owner.

The objective is simple: ensure that the right expertise is involved early enough to influence the requirements, rather than attempting to address cybersecurity and other risks after a system has already been selected.

Six principles for secure procurement

The guide sets out six core principles for organisations procuring connected building technology:

– Plan early, plan together
– Buy secure by design
– Demand evidence, not promises
– Protect the whole lifecycle
– Treat data integrity as critical
– Keep stakeholders informed

These principles are supported by a practical procurement lifecycle covering pre-planning, planning, sourcing, installation and management, operation and maintenance, and eventual decommissioning.

The guide also provides practical questions that procurement teams can put directly to suppliers, including requirements around vulnerability disclosure, security assurance, software updates, remote access and Software Bills of Materials (SBoM).

Matching security requirements to risk

The guide makes use of the IoTSF’s Assurance Framework to help organisations establish proportionate security requirements.

By assigning an appropriate Assurance Class to the technology being procured, organisations can set a consistent and evidence-based security baseline. The guide provides examples ranging from lower-impact sensors through to systems such as HVAC, lifts, lighting control, access control and CCTV.

It also includes a ready-to-use supplier question sheet that procurement teams can incorporate into requests for proposals, alongside a template agenda for the first PPSG meeting.

Addressing AI in building technology

With AI increasingly being incorporated into building systems – from predictive maintenance and energy optimisation to occupancy analytics, CCTV and access control – the guide also includes a dedicated section on AI procurement.

It provides a set of due-diligence questions covering issues such as AI risk classification, ISO/IEC 42001, training data, human oversight, bias testing, explainability, model updates, data flows and AI incident response.

A practical resource for the built environment

The guide is intended for anyone responsible for, or contributing to, the purchase of technology that connects to a building network. This includes procurement professionals, property and facilities managers, sustainability teams, physical and cybersecurity teams, risk, legal and compliance professionals and others involved in building technology decisions.

The guide draws on the Royal Institution of Chartered Surveyors (RICS) practice information ‘Digital risks in buildings’, alongside the IoTSF’s own security frameworks and best-practice guidance.

‘Building technology procurement guide: Procuring building technology securely’ is available now from the IoT Security Foundation.

The IoT Security Foundation would like to thank the members of its Smart Built Environment working group, and all contributors and peer reviewers whose expertise helped shape this publication.

Webinar

The IoTSF Smart Built Environment working group will be taking part in a procurement guide webinar special on Thursday 17th September 2026. Click HERE to register.