
The Cyber Resilience Act: From Regulatory Requirements to Verifiable Compliance
CRA obligations are clear; conformity isn’t. Learn which evidence assessors accept, what RED/EN 18031 covers, and gaps.
Topic
When & Where
Details
Format:
it-sa insights
Language:
German
Session description
Speaker: Florian Schmidt
The Cyber Resilience Act defines obligations – but not how conformity is demonstrated in day-to-day practice. This is exactly where many preparation projects currently struggle: processes exist on paper, while robust technical evidence is missing.
From the perspective of an independent assessment body, this presentation shows how regulatory requirements become verifiable reality: which documentation, processes and technical evidence will be expected – from security verification and validation to penetration testing and vulnerability management.
Attendees will learn what auditors look for, where the gap between ambition and reality is widest, and how to build a sustainable testing strategy with clear governance and responsibili ...

