Insight session image of Knowledge Forum A

The Cyber Resilience Act: From Regulatory Requirements to Verifiable Compliance

CRA obligations are clear; conformity isn’t. Learn which evidence assessors accept, what RED/EN 18031 covers, and gaps.

Topic

Education and trainingGovernance, Riskmanagement and Compliance

When & Where

calendar_month

Thu, 10/29/2026 01:30 PM - 02:00 PM

location_on

Forum A, Booth 6-216

Download session as iCaldownload_for_offline

Details

  • Format:

    it-sa insights

  • Language:

    German

Session description

Speaker: Florian Schmidt 

The Cyber Resilience Act defines obligations – but not how conformity is demonstrated in day-to-day practice. This is exactly where many preparation projects currently struggle: processes exist on paper, while robust technical evidence is missing. 

From the perspective of an independent assessment body, this presentation shows how regulatory requirements become verifiable reality: which documentation, processes and technical evidence will be expected – from security verification and validation to penetration testing and vulnerability management. 

Attendees will learn what auditors look for, where the gap between ambition and reality is widest, and how to build a sustainable testing strategy with clear governance and responsibili ...