ONVIF TLS Configuration Add-on v1.0: manage the transition without guessing

ONVIF is ending new v1.0 conformance submissions on March 31, 2027. Version 2.0 is scheduled, not yet a final conformance target, so plans need vendor evidence.

Executive summary

What you need to know

ONVIF is ending new v1.0 conformance submissions on March 31, 2027. Version 2.0 is scheduled, not yet a final conformance target, so plans need vendor evidence.

Potentially affected

Organizations procuring or operating ONVIF clients and devices that claim the TLS Configuration Add-on, or that depend on centrally configured TLS for physical-security traffic.

DSE recommendation

Inventory exact add-on claims, certificate and trust dependencies, and vendor transition plans while testing current TLS behavior without assuming a future specification.

What version 1.0 establishes

Source fact: The ONVIF TLS Configuration Add-on provides a standardized way for a conformant client to perform the initial configuration and later update of TLS settings on a conformant device. It addresses encrypted communication between ONVIF clients and devices using Transport Layer Security.

Support is required on both sides. A client with the add-on can configure a device only when that device supports the same add-on. The version 1.0 specification, dated December 2023, also states that ONVIF Network Interface Specifications version 22.06 or later are required for conformance.

ONVIF’s current lifecycle notice says the last date for product conformance submissions for version 1.0 is March 31, 2027. The page says version 2.0 is scheduled for early 2027 to replace it. As of this review, that is schedule information, not a final version 2.0 specification or a confirmed product capability. Procurement and migration decisions should not invent requirements for an unpublished final release.

What the add-on does not prove

Add-on conformance does not establish that every physical-security protocol or media stream is encrypted. It does not validate an organization’s certificate authority, trust-store distribution, certificate names, renewal process, cipher policy, or operational response to expiration. Those outcomes depend on product implementation, configuration, client/device compatibility, and the wider architecture.

A product’s general TLS capability is also not the same as an official add-on claim. Exact model and firmware or software records should be checked in ONVIF’s database. Version 1.0 deployments remain real systems to manage; the submission deadline does not itself disable them.

DSE transition checklist

DSE recommendation: This is DSE operational synthesis. It does not predict the content or release date of version 2.0.

  1. Inventory each client and device, exact firmware or software, claimed add-on version, and official database record.
  2. Map which control, event, configuration, and media paths actually use TLS and which do not.
  3. Record certificate issuer, subject names, trust stores, expiry, renewal owner, and recovery access.
  4. Ask manufacturers for documented support and transition plans; separate commitments from roadmaps.
  5. Test initial configuration, renewal, expired or untrusted certificates, reconnect behavior, and client compatibility in a lab.
  6. Avoid specifying version 2.0 details until ONVIF publishes a final specification and conformant products are listed.
  7. Review ONVIF and manufacturer notices on a defined cadence and update the plan when evidence changes.

Official references

Primary reference

Review the official source

ONVIF — TLS Configuration Add-on · Verified July 19, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE