The EU Cyber Resilience Act (CRA) is reshaping how connected products are designed, maintained, and secured — but compliance looks very different across industries with long product lifecycles, complex supply chains, and safety-critical environments. While many discussions focus on regulatory language or technical requirements alone, the real challenge for embedded teams is operationalizing secure-by-design principles in real-world products and development environments.
This cross-industry roundtable brings together leaders from industrial controls, automotive systems, and medical device security to discuss how organizations are preparing for CRA requirements and aligning with frameworks such as IEC 62443. Panelists will explore the practical realities behind vulnerability management, SBOM readiness, secure update strategies, legacy system constraints, supplier risk, and long-term product support obligations.
The session will also examine the CRA enforcement timeline and what organizations should prioritize ahead of two key milestones: the September 11, 2026 requirement for mandatory vulnerability and incident reporting through the ENISA platform, and the December 11, 2027 deadline when the full CRA requirements take effect, including secure-by-design obligations, vulnerability management lifecycle requirements, technical documentation, conformity assessments, and CE marking for products with digital elements.
Rather than a technical deep dive or compliance checklist, this session focuses on the organizational and engineering decisions teams are making now to prepare for implementation. Attendees will gain practical insight into how different industries are balancing security, safety, operational continuity, and regulatory pressure — and what embedded product teams should prioritize over the next 12–24 months to move from compliance planning to operational readiness.
This session is part of our “CRA Virtual Conference". Registration/event page here.
Senior Cybersecurity & Compliance SME, May Mobility
Hemanth Tadepalli serves as the Senior Cybersecurity & Compliance Subject Matter Expert (SME) at May Mobility, a company revolutionizing transportation through advanced autonomous vehicle mobility. His career spans notable roles at prestigious...
Joe Saunders is Founder & CEO of RunSafe Security. He leads a team of former national security cyber experts on a mission to make critical infrastructure safe. Working with companies such as Lockheed Martin, GE Vernova, and Vertiv as well as the...
Andy has more than four decades of software development experience across multiple industries. He has worked at Schneider Electric since 2001. At Schneider Electric, Andy has managed numerous process control engineering teams. As a result of this...
Shantanu Shastri is a cybersecurity professional with over 9 years of experience specializing in IoT security, penetration testing, cloud security, and connected healthcare device security. He currently leads IoT Security initiatives at GE...