ONVIF has released the draft of Profile V — a standard designed to bring cloud video surveillance out of proprietary silos. Here’s what it does, why it matters for anyone specifying cameras in the next two years, and how to prepare while it’s still taking shape.
For fifteen years, ONVIF’s profiles have answered one question for the physical security industry: will this camera work with that recording system, even though they’re from different vendors? Profile S standardised basic streaming. Profile T added modern security and advanced video. Profile G covered edge recording. Now ONVIF has turned its attention to the one part of the modern surveillance stack that has remained stubbornly proprietary — the cloud.
On 9 July 2026, ONVIF released the Release Candidate for Profile V, a draft standard for cloud-based video surveillance. If you specify, integrate, or own IP video systems, this is the standard that will shape how cloud deployments are built from 2027 onward — and understanding it early is a genuine advantage.
- What: a draft ONVIF standard for cloud video surveillance, released as a Release Candidate on 9 July 2026.
- Why it matters: it lets cloud VMS platforms and cameras from different vendors work together — ending single-vendor cloud lock-in.
- How it works: cameras make a secure outbound connection and stream over WebRTC — reaching devices behind a firewall without port forwarding or VPNs.
- Security: a mandatory Security Add-on built on OAuth 2.0, with encrypted recordings to cloud storage such as Amazon S3 or Azure Blob.
The problem Profile V solves: cloud lock-in
Cloud video surveillance has grown quickly, but most of it has been built inside proprietary ecosystems. If your cloud VMS, your cameras and your storage all had to come from the same supplier, you were locked in: changing one component often meant redesigning the whole system. That’s the opposite of what ONVIF exists to prevent, and it’s the gap Profile V is designed to close.
Profile V extends ONVIF’s brand-independent approach to the cloud. In practice, that means a system integrator or end user can build a cloud video deployment using a cloud VMS from one vendor and cameras from another, and expect them to interoperate — and can replace individual components later without ripping out the whole system. For anyone who has been burned by a proprietary cloud platform, that flexibility is the headline.
How it works — and why the firewall detail matters
The technical design of Profile V is quietly clever, and one detail in particular will matter to anyone who has fought with network configuration on a camera project.
A Profile V conformant camera establishes a secure outbound connection to the cloud video management system, then streams live video (and audio where applicable) over WebRTC to an ONVIF client or an authorised standard web client. Devices can also send event notifications to the cloud VMS to trigger actions.
The significance of “outbound” is easy to miss but large in practice: because the camera reaches out to the cloud rather than the cloud reaching in to the camera, a conformant cloud VMS can reach cameras behind a local firewall, typically without port forwarding or VPN configuration. Anyone who has managed multi-site camera estates knows how much cost, risk and helpdesk time goes into port forwarding and VPN tunnels. Removing that requirement is a meaningful simplification — and a meaningful reduction in attack surface, since you’re no longer opening inbound holes in site firewalls.
Security is built in, and built to evolve
Profile V doesn’t repeat the mistake that is currently retiring Profile S. Security isn’t an optional extra or a weak default — it’s mandatory, and it’s modern.
Every Profile V conformant product must implement the ONVIF Profile V Security Add-on, which does two things: it uses the OAuth 2.0 framework so that only authorised devices, clients and cloud services can connect and exchange data; and it encrypts recordings on their way to cloud storage platforms such as Amazon S3 or Microsoft Azure Blob Storage.
There’s a design decision here worth flagging, because it signals how ONVIF is thinking about security going forward. The security requirements were deliberately placed in a separate add-on rather than baked into the profile itself — so that the security layer can be updated to keep pace with evolving threats without rewriting the entire Profile V specification. Given that the reason Profile S is being retired is precisely an authentication method that aged badly, this modular approach is a direct lesson learned. It’s a sign the standard is being built to last.
Hybrid systems: Profile V doesn’t replace what you have
An important reassurance for anyone with an existing estate: Profile V is additive, not a rip-and-replace. ONVIF states it can be combined with its existing video and access control profiles for integrated or hybrid systems. A realistic near-future deployment might use Profile T for on-premise streaming and recording, Profile V for the cloud layer, and access-control profiles alongside — all interoperating. Cloud isn’t an all-or-nothing switch; Profile V is designed to slot into mixed architectures.
What this means for you — by role
If you’re an end user or estate owner
Profile V is your route out of cloud vendor lock-in. When you next evaluate a cloud VMS, “Profile V conformance on the roadmap” should become a procurement question — it protects your ability to change cameras or platforms later without a full redesign. There’s no urgency to act today, but there is real value in not signing a long proprietary cloud contract in the window before Profile V products arrive.
If you’re a system integrator or consultant
This is a competitive-advantage window. Cloud video is where the market is heading, and Profile V is about to become the vocabulary clients use to talk about it. Integrators who understand the outbound-connection model, the WebRTC streaming path, and the OAuth 2.0 security add-on before the standard finalises will be the ones trusted to design cloud deployments in 2027. The firewall-traversal advantage alone is a strong story to bring to multi-site clients.
If you’re a device or VMS manufacturer
The draft is open for review now, and finalisation is expected by year-end. The lead time to build conformant products, implement the Security Add-on correctly, and validate WebRTC interoperability is not trivial. Early engagement with the specification is how you avoid being late to a market that will move quickly once the standard lands.
How to prepare while Profile V is still a draft
- Treat cloud lock-in as a live procurement risk now. Any proprietary cloud commitment you make in the next 12 months should be weighed against a near-future world where Profile V gives you options.
- Map your cloud readiness. Understand which of your existing cameras could participate in a Profile V deployment, and where WebRTC and outbound-connection support would need to come from.
- Fold it into your Profile S migration. If you’re already planning a Profile T migration ahead of the March 2027 Profile S deadline, that same estate review is the natural moment to plan your cloud path — do the analysis once.
- Watch for finalisation. The specification may change before it’s ratified at the end of 2026. Design around the direction, confirm against the final text.
Planning a cloud video deployment — or a Profile S migration?
DevSpark’s ONVIF & Video Interoperability practice helps estate owners, integrators and manufacturers navigate ONVIF’s evolving profiles — from Profile S migration through to cloud-ready, Profile V-aware architecture and interoperability testing.
DevSpark Ltd is a UK-based deep-tech engineering consultancy headquartered in Manchester, specialising in embedded systems, ONVIF video-infrastructure compliance, and applied engineering for regulated and critical-infrastructure environments.
Sources: ONVIF press release, “ONVIF Releases Profile V Draft for Cloud Video” (9 July 2026); ONVIF Profile V Release Candidate technical FAQ; reporting in Security Systems News, SecurityInfoWatch, Security Today and Benchmark. WebRTC/outbound-connection model, firewall traversal, OAuth 2.0 Security Add-on, encrypted cloud storage (Amazon S3 / Azure Blob), hybrid-profile support, and end-of-2026 finalisation timeline all per ONVIF primary sources. Profile V is a draft Release Candidate; details may change before ratification — verify against ONVIF before acting.
