Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Viktor Petersson. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Viktor Petersson or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

CRA Explained: What the Cyber Resilience Act Means for Device Manufacturers

1:05:33
 
Share
 

Manage episode 524692325 series 3621860
Content provided by Viktor Petersson. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Viktor Petersson or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In this episode of "Nerding Out with Viktor," host Viktor Petersson sits down with Sarah Fluchs, CTO and OT cybersecurity expert, to unpack the EU's Cyber Resilience Act and what it means for anyone building connected devices.

Sarah shares her journey from engineering into the world of OT security, and explains her involvement in the CRA expert group that's shaping how the regulation gets implemented. Together, they explore what CRA compliance looks like in practice—from the requirement to provide five years of vulnerability support, to the constraints around over-the-air updates, and the rising importance of Software Bills of Materials (SBOMs) in embedded systems.

The conversation dives into the practical challenges facing device manufacturers, including how to structure security workflows, manage firmware lifecycles, and prepare for regulatory scrutiny. Sarah offers clear, grounded insights into the timeline, scope, and enforcement mechanisms of the CRA, helping listeners understand what's required and what's still being defined.

Viktor and Sarah also discuss the broader implications of the CRA for the embedded and IoT ecosystem, exploring how the regulation intersects with existing standards and what it means for both large enterprises and smaller hardware teams. They examine common misconceptions about compliance and share strategies for teams looking to get ahead of the requirements.

Whether you're managing firmware, building security workflows, or navigating hardware compliance, this episode offers a practical guide to understanding the CRA and preparing your organization for what's ahead.

  continue reading

47 episodes

Artwork
iconShare
 
Manage episode 524692325 series 3621860
Content provided by Viktor Petersson. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Viktor Petersson or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In this episode of "Nerding Out with Viktor," host Viktor Petersson sits down with Sarah Fluchs, CTO and OT cybersecurity expert, to unpack the EU's Cyber Resilience Act and what it means for anyone building connected devices.

Sarah shares her journey from engineering into the world of OT security, and explains her involvement in the CRA expert group that's shaping how the regulation gets implemented. Together, they explore what CRA compliance looks like in practice—from the requirement to provide five years of vulnerability support, to the constraints around over-the-air updates, and the rising importance of Software Bills of Materials (SBOMs) in embedded systems.

The conversation dives into the practical challenges facing device manufacturers, including how to structure security workflows, manage firmware lifecycles, and prepare for regulatory scrutiny. Sarah offers clear, grounded insights into the timeline, scope, and enforcement mechanisms of the CRA, helping listeners understand what's required and what's still being defined.

Viktor and Sarah also discuss the broader implications of the CRA for the embedded and IoT ecosystem, exploring how the regulation intersects with existing standards and what it means for both large enterprises and smaller hardware teams. They examine common misconceptions about compliance and share strategies for teams looking to get ahead of the requirements.

Whether you're managing firmware, building security workflows, or navigating hardware compliance, this episode offers a practical guide to understanding the CRA and preparing your organization for what's ahead.

  continue reading

47 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play