
For years, vendor security review meant a spreadsheet, a few email threads, and no clear owner. Three EU regulations just made it a legal duty.
The Cyber Resilience Act turns every software supplier into a producer of security evidence: SBOMs, VEX, and conformity documentation. NIS2 Article 21 and DORA Articles 28 to 30 then require the companies buying that software to assess their suppliers and prove they did it.
This talk shows the practical method that connects the two sides. It covers how to triage vendors by criticality, how to turn supplier artifacts into a defensible assessment instead of a questionnaire, and how to map concentration risk before a regulator or an incident finds it first.
The takeaway is a repeatable way to run third-party security reviews under CRA, NIS2 and DORA, drawn from building this exact workflow for EU-regulated fintechs.

Conference partners







Organiser
