You’re STILL not ready for the CRA
You’re STILL not ready for the CRA
At the premises of SafeShark
The EU Cyber Resilience Act (CRA) is moving ever closer – so, are you any more ready than you were in July?
Following the success of our ‘You’re not ready for the CRA’ event in July, the IoT Security Foundation is bringing the conversation back to London on Thursday 8th October for ‘You’re STILL not ready for the CRA’.
The CRA represents a major shift in the way cybersecurity must be approached across the lifecycle of connected products and software. For manufacturers, importers, distributors and other organisations operating in the digital product ecosystem, the requirements are significant – and the clock is ticking.
This follow-up event, hosted at the premises of SafeShark?, will bring together experts and industry practitioners to look at what has changed, what organisations should be doing now, and where the biggest challenges still lie.
Expect practical insight, candid discussion and real-world perspectives on navigating the CRA – from understanding your obligations and preparing for compliance, to tackling cybersecurity requirements across product development, supply chains and the product lifecycle.
Whether you attended the July event or you’re coming to the conversation for the first time, this is an opportunity to get up to speed, ask the difficult questions and find out what you should be doing NOW to prepare.
The message from July hasn’t changed, the CRA is coming. The question is – are you STILL not ready?
Agenda
09:30 – Registration
10:00 Opening address
10:20 CRA reporting obligations (Article 14) – What are the real world reporting timelines? A fireside chat with Richard Marshall (BSI CEN/CLC/JTC 13/WG 9 “Horizontal cybersecurity for products with Digital Elements” working group chair and Xitex) and Joe Lomako (TUV SUD)
10:40 Panel discussion – Article 14 in practice: Richard Marshall (chair), Mustanir Ali (Element), Viktor Petersson (Screenly) and Jonathan Marshall (SafeShark)
11:15 Coffee and networking break
11:35 CRA standards update CEN/CLC/JTC 13/WG 9, EN 40000 series standards and ETSI vertical standards – BSI update from CEN JTC13/WG9 : Richard Marshall (IST33/-/9 Chair)
11:55 CRA compliance implications: Paul Phillips (Residio)
12:15 CRA conformity assessment – Lessons learnt from RED/PSTI: Jonathan Marshall (SafeShark)
12:30 Lunch (included with your ticket)
13:15 CRA conformity assessment – Product classification: Mustanir Ali (Element)
13:35 CRA conformity assessment – Risk assessment (EN 40000-1-2 preview)
13:55 CRA conformity assessment – Threat modelling: Jonny Tyers (Threatplane)
14:15 Product documentation – Architectural description: David Pashley (Direct Insight)
14:35 Coffee and networking break
14:55 Vulnerability handling (EN 40000-1-3 preview)
15:15 Technical requirements and controls (EN 40000-1-4 preview) – BSI update from CEN JTC13/WG9: Richard Marshall (IST33/-/9 Chair)
15:35 An introduction to secure boot: Ian Pearson (Microchip)
15:55 CRA Q&A session
16:30 Valedictory and event close








