Default image of it-sa 365

Cyber Resilience Act: How DevSecOps can be used efficiently

Der Cyber Resilience Act ist da! Wir schauen uns an, was da kommt und wo sich DevSecOps und Compliance die Hände reichen.

Topic

Legislation, standards, regulations

When & Where

calendar_month

Tue, 10/07/2025, 16:12 - 16:24

location_on

Forum, Booth 9-105

Download session as iCaldownload_for_offline

Details

  • Format:

    Technology lecture

  • Language:

    German

Session description

The CyberResilience Act (CRA) is an EU legal framework that will apply from December 11, 2027, to all products with digital elements that have a logical or physical data connection to devices or networks. Its goal is to create a uniform level of cybersecurity and market conformity, thus protecting consumers, businesses, and critical infrastructure from cyber risks. Exceptions include medical devices, specific EU regulations, pure open source software without commercial distribution, and products solely for national security.

For software manufacturers, the CRA means that security must be integrated into the design and development process, a systematic risk assessment must be documented, and comprehensive vulnerability management must be implemented: components must be identified, ...

Sponsored by

Moderator

Products

CRANIS CRA-Navigator

To the product

CRANIS SBOM-Steward

To the product