Speaker:
Piet De Vaere,
Product Security Consultant, Computer Scientist, Product Security Guru
Piet explains why the EU Cyber Resilience Act (CRA) deliberately avoids prescribing fixed technical security requirements for every product. Instead, manufacturers are expected to assess their own product risks and implement appropriate security measures.
The talk covers:
- Why CRA standards cannot provide one-size-fits-all security requirements
- The role of risk assessment and secure product development
- CRA conformity assessment and product classifications
- Lessons from the Radio Equipment Directive
- Why manufacturers remain responsible for third-party components
- What using Toradex, NXP, open-source software and other dependencies means for CRA responsibility
- Why supplier due diligence is essential
The key message: CRA compliance is not simply about checking a list of security features. It requires understanding your product, its risks, and building security into the development lifecycle.