Sep 4, 2026 | English
Jon explores how the EU Cyber Resilience Act (CRA) can be approached not simply as a regulatory challenge, but as a framework for building more resilient and competitive products.
The presentation covers the CRA’s key cybersecurity requirements, including risk management, vulnerability handling, secure software updates, documentation, and conformity assessment. Jon explains why software updates and vulnerability management are central to long-term cybersecurity resilience, and how manufacturers remain responsible for the security of their products and supply chains.
The talk also examines CRA standards, self-certification, vertical standards, presumption of conformity, and the practical implications for important and critical products.
A Q&A session addresses common questions around automatic updates, offline devices, USB-based updates, risk assessments, and regulatory interpretation.