The industry’s most widely deployed camera-interoperability standard has a shutdown date. Most estate owners don’t yet know their exposure — and the real risk arrives earlier, and more quietly, than the headline deadline suggests.
If your organisation operates IP cameras — across a building, a campus, a transport network or a national estate — there is a date you need on your risk register: 31 March 2027. That is when ONVIF, the global standards body behind IP-camera interoperability, ends support for Profile S, the profile that has underpinned basic video streaming between cameras and video management software since 2011.
This is not a niche technical footnote. Profile S has been the default interoperability layer for well over a decade, and ONVIF now counts more than 33,000 conformant products across its ecosystem. A large share of the cameras and recorders installed in the UK, EU and US today were specified, procured and integrated around it.
The good news: nothing switches off overnight on 31 March 2027. The uncomfortable news: the actual risk to a working estate can arrive before that date, on an ordinary Tuesday, triggered by something as routine as a firmware update — and most operators currently have no way of knowing which of their devices are exposed.
- What: ONVIF is deprecating Profile S; last conformance submissions are 31 March 2027.
- Why: Profile S mandates username token authentication, which ONVIF says is no longer consistent with current cybersecurity recommendations.
- The successor: Profile T (introduced 2018) carries virtually all of Profile S’s features, plus stronger authentication — digest and TLS/HTTPS.
- The catch: conformance can break on a firmware update, and mixed-profile estates can silently lose interoperability.
Why ONVIF is retiring Profile S — it’s security, not obsolescence
It would be easy to assume a fourteen-year-old standard is being retired because the technology moved on. It hasn’t. Profile S still streams video perfectly well. The reason is narrower and more serious: the authentication method Profile S mandates is no longer considered safe.
Profile S requires username token authentication. In ONVIF’s own words, that method “is no longer consistent with current cybersecurity recommendations,” and is “regarded as too weak today to protect against unauthorized access to devices.” In an era where a compromised camera is a foothold into an entire network, an authentication scheme that can’t reliably keep intruders out of the device is a liability, not a convenience.
Profile T, the recommended successor, was introduced back in 2018 and supports digest authentication and TLS (the encryption behind HTTPS). Crucially, ONVIF states that the majority of conformant devices and clients on the market today already support both S and T. For a lot of estates, that means the fix is a configuration change rather than a forklift replacement — but only if you know which devices are which, and that is exactly the information most operators don’t have to hand.
The risk most operators are missing: it doesn’t wait for 2027
Here is the part that deserves attention from anyone responsible for a camera estate, because it inverts the usual “we’ll deal with it before the deadline” instinct.
An existing Profile S product stays conformant only “until the manufacturer decides to withdraw the Declaration of Conformance.” And ONVIF is strongly encouraging manufacturers and end users to discontinue username token authentication. Read those two facts together and the implication is uncomfortable: as vendors ship newer firmware that removes or hardens username token authentication in line with ONVIF’s guidance, a device’s Profile S conformance — and the interoperability that depends on it — can change underneath a live system.
In practice, that means a routine, well-intentioned security firmware update could alter how a camera authenticates, and a video management system that was relying on the old behaviour could lose the device. Not on the deadline. On whatever day that update lands. If your estate depends on username token authentication anywhere — and many do, often without anyone having documented it — you are carrying an invisible operational risk with a cybersecurity label attached to it.
The mixed-estate trap
There is a second, quieter failure mode that catches large and long-lived estates in particular: the profile mismatch.
Interoperability is only as strong as the weakest side of the connection. A modern Profile T camera talking to an older recorder or VMS that only supports Profile S will fall back to the lower common denominator — and inherit its weaknesses, including the very authentication method being deprecated. Estates that have grown over years, with equipment from multiple vendors installed across multiple procurement cycles, almost always contain these mismatches. Nobody sees them, because everything appears to work — right up until a firmware update or a security audit surfaces the exposure.
One migration detail worth knowing before you plan
Migration from Profile S to Profile T is usually straightforward, because Profile T contains virtually all of Profile S’s features. But “usually” is not “always,” and the exceptions matter. The handful of capabilities that don’t map cleanly across include username token authentication itself, IP address filtering, and older media formats such as MJPEG and MPEG-4. If any part of your estate genuinely depends on those, migration is a project rather than a checkbox — and identifying that dependency before you commit to a plan is what separates a smooth transition from a nasty surprise.
What camera estate owners should do now
The single most valuable thing you can do well ahead of March 2027 is turn an invisible risk into a known one. That means understanding your estate at a level of detail most inventories don’t capture:
- Enumerate the estate at the profile-and-authentication level. Not just “how many cameras” — but which profile each device and each client actually supports, and crucially, which authentication method each connection is currently using. This is the data that tells you where the exposure is.
- Identify the Profile S dependencies. Which devices are Profile S only? Which clients (recorders, VMS) can’t yet speak Profile T? Which links are relying on username token authentication today?
- Find the mismatches. Where is a capable device being dragged down to a weaker common denominator by the other end of the connection?
- Cross-check conformance claims. ONVIF maintains the only authoritative database of genuinely conformant products; claimed conformance and registered conformance are not always the same thing.
- Build a dated migration plan. Separate the config-change cases (most of them) from the genuine replacements (the MJPEG / IP-filtering / Profile-S-only exceptions), and sequence the work against the 2027 date and your own firmware-update cycles.
Done properly, this is a low-drama exercise that replaces uncertainty with a clear, prioritised picture — which devices are safe, which need a setting changed, which need replacing, and by when. Done not at all, it leaves you exposed to a failure whose timing you don’t control.
Not sure where your estate stands?
DevSpark’s ONVIF & Video Interoperability practice helps camera estate owners and integrators assess Profile S exposure, identify authentication and mismatch risks, and plan a clear migration to Profile T — before a firmware update or an audit does it for you.
DevSpark Ltd is a UK-based deep-tech engineering consultancy headquartered in Manchester, specialising in embedded systems, ONVIF video-infrastructure compliance, and applied engineering for regulated and critical-infrastructure environments.
See also: What ONVIF Profile V means for cloud video → — the forward-looking companion to this article, covering the new draft standard for interoperable cloud surveillance.
Sources: ONVIF, “Profile S Deprecation Q&A”; ONVIF press release, “ONVIF to End Support for Profile S; Recommends Profile T as Replacement” (9 October 2025); ONVIF Profile S and Profile T profile pages. Deadline, authentication rationale, 33,000+ conformant products figure, and Profile T feature-parity all per ONVIF primary sources. Regulatory and technical details current at the date of publication; verify against ONVIF before acting.
