Technology
ONVIF Profile S Is Being Retired: What It Means for Your Cameras

March 31, 2027 is the last date for new product conformance submissions under ONVIF Profile S. That is the whole change, and it is worth stating precisely because overstating it would be exactly the kind of error that costs an integrator credibility. It is not a date on which existing cameras stop working. Your cameras will keep streaming. Your recorder will keep recording. What changes is what you should be writing into new purchase specifications between now and then.
What ONVIF is, in buyer terms
ONVIF is a vendor-neutral interface for physical security devices. It defines how a camera describes itself, how a client discovers it, how a stream is requested and how events are delivered. The value to a buyer is simple: it is the difference between being able to change cameras without changing platforms, and being locked to one manufacturer's ecosystem for the life of the system.
That is not an abstract concern. A camera fleet lives seven to ten years. Over that period manufacturers get acquired, product lines get discontinued and supply gets erratic. Open interfaces are how you keep the ability to buy whatever is actually available next year.
The profile map
- Profile S, 2011: video streaming and configuration. The original and still the most widely implemented.
- Profile C, 2013: access control runtime, doors and events.
- Profile G, 2014: edge recording and playback.
- Profile A, 2017: access control configuration, credentials and schedules.
- Profile T, 2018: advanced streaming including H.265, analytics and tamper events. This is the current baseline for new deployments.
- Profile D, 2021: peripherals such as relays and sensors.
- Profile M, 2021: analytics metadata and configuration.
Profile Q was deprecated in 2022. If a specification you inherited still references it, that document has not been reviewed in a while and probably needs a wider look than one line.
Why Profile S is being retired
Profile S mandates an authentication method that no longer meets current security guidance. That is the actual reason, and it is a better reason than age. A profile that requires a weak authentication scheme cannot be brought forward, because conformance would mean certifying something a security team should be turning off.
Profile T carries the streaming functionality forward with a modern security posture. So this is a deprecation for cause, not a version bump for its own sake, and it tells you what to prioritize: authentication and firmware, not conformance badges.
What a buyer should actually do
- Specify Profile T on new camera purchases. Put it in the bid document so every response is comparable.
- Do not panic about an existing Profile S fleet. Nothing breaks on a date, and a forced fleet replacement driven by a conformance deadline is the wrong project.
- Audit which of your cameras still receive firmware updates. That matters far more than which profile they conform to.
- Check how your platform actually connects to each camera. Native manufacturer drivers in a major platform frequently support older cameras better than ONVIF does, and a platform with a deep device pack will often drive a camera that has no useful ONVIF stack at all.
- Plan replacement by risk and by supportability, oldest and least patchable first.
On that fourth point: in a Genetec deployment we generally prefer the native device integration over generic ONVIF when both are available, because the native path usually exposes more of the camera and behaves better through firmware changes. ONVIF is the fallback that keeps you free, not always the best day-to-day driver.
The reason to replace old cameras is security, not conformance
Here is the framing that makes this actionable. A camera from before roughly 2015 often has no usable TLS, hardcoded or undocumented default credentials, no available firmware updates and no 802.1X support. It may stream perfectly. It is still an unpatched Linux device sitting on your network with a network stack nobody maintains.
That is a far better reason to plan replacement than a conformance submission deadline, and it is the argument that actually lands with an IT director. Frame the camera refresh as removing unpatchable endpoints from the network, segment what you cannot replace yet onto its own VLAN with no route to anything interesting, and put the remaining devices on a firmware review cycle.
What we do on assessment
When we walk an existing system we inventory every camera by model year, current firmware, available firmware, authentication capability, ONVIF profile support and how the platform connects to it. That produces a replacement order based on risk and supportability, plus an honest list of which cameras are fine to keep. Usually more of them are fine than the last integrator suggested.
Where to go next
For the wider specification argument, see open architecture versus proprietary. For the state of an inherited fleet, see our existing camera assessment page. Healthcare teams can apply the same audit principles through our Colorado healthcare facility security guide. If your building still has coax in the walls, analog versus IP cameras covers what encoders do and do not solve. Questions on a specific fleet: 303 596 7819.
Frequently asked questions
- Will my Profile S cameras stop working in 2027?
- No. March 31, 2027 is the last date for new product conformance submissions under Profile S. It is not a shutdown date. Existing cameras keep streaming and existing integrations keep working.
- What should I specify on new camera purchases?
- Profile T. It covers H.265, analytics and tamper events and is the current baseline for new deployments.
- Why is Profile S being retired?
- It mandates an authentication method that no longer meets current security guidance. The driver is security, not obsolescence.
- Is ONVIF conformance the best measure of a camera's usefulness?
- No. Firmware support matters more. A conformant camera with no available firmware updates is a bigger problem than a non-conformant camera that a platform drives with a native device pack.


