Olle E. Johansson

Welcome to Stockholm, Sweden November 4-6 for the Nordic Software Security Summit Fall ’26!

When I started this conference together with our partner organisations in 2024, I saw the huge change coming for the software industry. We need to meet do discuss, learn and move forward together – users, manufacturers, regulators and consultants.

The CRA is all about creating resilient products and overall in the society, resilience is an important issue. Can we build digital infrastructures with a high degree of resilience? We also need to discuss the balance between compliance, which is the lower level, and security for our users – which is the goal of the CRA!

The CRA became EU-wide law in December 2024 and will come into full force in December 2027, with a first step in the second half of 2026. The clock is ticking and it’s time for your team to get your products compliant and if needed certified by a third party.

We are currently working on the programme and have started discussions with speakers, partners and sponsors. The Call for papers is out – we want to hear your ideas!

Let’s meet in Stockholm November 4-6 to discuss this and learn more, share experiences and network!

/Olle E. Johansson


Speakers at NSSS Spring 2026

Mikaël Barbero
Head of Security, Eclipse Foundation
Johanna Parikka Altensted
Johanna Parikka Altenstedt
Cybernode.SE, RI.SE
Peter Jonegård
Peter Jonegård
NCSC, CERT-SE
Thomas Graf, Siemens
Thomas Graf
Siemens AG
Anthony Harrison
Anthony Harrison
APH10, SBOM Europe
Andreas Bielk, SBOM Observer
Andreas Bielk
SBOM Observer
Open Source Security Foundation
OWASP Foundation
Open regulatory compliance working group (ORCWG.ORG)

This is a conference you can't afford to miss!

The Cyber Resilience Act will come into force three yours from now. It will change software development forever. Are your organisation ready for this?

Networking

Meet collegues and discuss their steps to get ready in time. Learn from our excellent speakers and sponsors!

Process

Learn about the process - how does this affect your agile development, you compliance process and your release strategy?

Compliance

The Cyber Resilience Act will extend the CE mark and include Cyber Security. Vendors need to keep products secure and up to date for the life time of the product.

Software Transparency News

News about the summit and related topics