
A Spreadsheet Is Not a Threat Model. A PDF Is Not Compliance.
The right way to run threat analysis (TARA) under ISO 21434 & IEC 62443 – and how vulnerability and compliance evidence can be automated.
Topic
When & Where
Details
Format:
Technology lecture
Language:
German
Session description
Speaker: Amirhossein Rashidi
Starting September 2026, the EU Cyber Resilience Act (CRA) introduces binding reporting and evidence obligations for vulnerabilities and security incidents. NIS2, IEC 62443, and ISO/SAE 21434 each demand their own, often overlapping documentation. The foundation for all of it is often the same: a threat analysis (TARA) living in a spreadsheet, and compliance evidence gathering dust as a PDF in a folder.
In this session, we show how to build a robust TARA under ISO/SAE 21434 and IEC 62443 — from asset identification through threat scenarios to risk scoring — including the most common mistakes we see manufacturers make in practice.
In the second half, we show how this methodology can be turned into a continuous, audit-ready process — from the ...

