embedded world NA 2025

Understanding the EU Cyber Resilience Act: What Software Publishers & Electronics Manufacturers Need to Know (Room 303C)

05 Nov 25
10:25 AM - 10:50 AM

Tracks: Embedded Security - Regulations

Speaker(s): Colin Duggan

The European Union’s Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for all network-connected products sold in the EU, with particularly strong implications for software, electronics, and embedded systems. The regulation has global reach: if your company sells connected products in the EU, the CRA applies—regardless of where you're based.
 
With enforcement deadlines approaching and GDPR-like penalties of up to €15 million or 2.5% of global annual revenue, the CRA demands urgent attention from product developers, compliance teams, and executive leadership in North America.
 
This panel will discuss the CRA and explain what you need to know.
 
Topics to be covered include:

-Key milestones and the regulatory timeline
-Device classification: how the CRA applies to your products
-Relevant cybersecurity standards that can aid compliance
-Required organizational commitments
-Essential product development practices: cybersecurity-by-design, vulnerability handling, and secure updates
 
Whether you're building connected consumer devices, industrial IoT systems, or critical digital infrastructure, this session will equip you with the insight and tools needed to begin your CRA compliance journey with confidence.