loader image

HomeEvents

Webinar: EU Cyber Resilience Act (CRA)

What is
CRA?

The EU Cyber Resilience Act (CRA) sets binding cyber­se­cu­rity require­ments for digital prod­ucts sold in Europe. It ensures cyber­se­cu­rity is consid­ered throughout the entire life­cycle of digital prod­ucts.

CONTENT
RECAP

  • The webinar provided a struc­tured overview of the Cyber Resilience Act (CRA) and its prac­tical impact on manu­fac­turers of digital prod­ucts. The CRA links cyber­se­cu­rity directly to CE marking. Without compli­ance, prod­ucts cannot be placed on the Euro­pean market. This applies to hard­ware and soft­ware and affects any company aiming to sell in Europe.
  • The session explained the neces­sary steps for meeting the require­ments. These include tech­nical docu­men­ta­tion, an EU decla­ra­tion of confor­mity, and clear instruc­tions for users on how to operate prod­ucts securely. Compa­nies must perform cyber­se­cu­rity risk assess­ments and manage vulner­a­bil­i­ties across the product life­cycle. The require­ments cover secure config­u­ra­tions, protec­tion against unau­tho­rized access, data confi­den­tiality, and the provi­sion of timely secu­rity updates.
  • Prac­tical advice focused on how to struc­ture internal processes, from managing soft­ware compo­nents with Soft­ware Bills of Mate­rials (SBOMs) to setting up tools for vulner­a­bility moni­toring and secu­rity testing. The webinar also outlined the CRA time­line and encour­aged early prepa­ra­tion to avoid delays and ensure compli­ance with future market access condi­tions.

Presen­ta­tion by IFM

Presen­ta­tion by admeritia