IoT Insider is bringing together cybersecurity and connected-device experts next week to examine what the EU Cyber Resilience Act (CRA) means for manufacturers as the new rules become applicable.
The webinar, The Cyber Resilience Act is here: What happens next for IoT security?, will take place on Tuesday 15 September at 2pm UK time, four days after the legislation takes effect.
The CRA represents a significant change in the regulation of connected products sold in the EU, introducing cybersecurity requirements across their lifecycle, from design and development to vulnerability management, software updates and post-market support.
Lucy Barnard, Editor of IoT Insider, will host a panel including David Pashley, Managing Director of Direct Insight; Joe Lomako, Cybersecurity Lab Manager at TÜV SÜD; Harrison Parker, Regional Sales Manager for QNX across the UK, Ireland and Nordics; and Richard Marshall, Managing Consultant at Xitex.
The panel will consider how the regulation will affect manufacturers in practice, including how they will need to adapt product development processes, software supply chains and approaches to identifying and addressing vulnerabilities.
Pashley, who is a member of the IoT Security Foundation’s Regulatory Watch Working Group, will bring his experience in embedded systems and digital resilience to the discussion.
Lomako will provide a compliance perspective, drawing on more than 25 years of experience helping manufacturers meet regulatory requirements for connected products and bring them to international markets.
Parker will examine the role of secure-by-design software in connected and safety-critical systems, including software supply-chain visibility, vulnerability management and long-term product support.
Marshall, who chairs the BSI working group responsible for coordinating UK input into CRA standardisation, will discuss the development of the standards supporting the regulation. He has also contributed to several key IoT security standards, including ETSI EN 303 645.
The CRA has been years in development, but its application on 11 September marks the beginning of a new phase for manufacturers. Companies will need to determine which requirements apply to their products and how to demonstrate compliance, while also establishing processes for handling vulnerabilities and providing security updates.
The webinar will examine the practical implications of the legislation, including the relationship between the CRA and emerging European cybersecurity standards, the impact on software and hardware supply chains, and the challenges of maintaining security throughout a product’s lifecycle.
To register for the event, click here and fill in the form at the bottom of the page.
