Harald Fischer, Security Aspect Lead at Balena

We will be talking about the most foundational requirement of the Cyber Resilience Act (CRA): the cybersecurity risk assessment.

This cybersecurity risk assessment is crucial because, without it, demonstrating compliance with the essential cybersecurity requirements becomes problematic. It also hinders a comprehensive understanding of your product’s cybersecurity risk posture, making it difficult to declare conformity and assume full responsibility.

Therefore, we will review the specific obligations outlined in the CRA regulation. We will then map these obligations to existing industry standards and guidance from standardization organizations.

Finally, using these established tools and inspirations from industry standards, we will define practical steps for conducting a risk assessment that supports your conformity assessment process.

Focus on the Cyber Resilience Act


Open Source Security Foundation
OWASP Foundation
Open regulatory compliance working group (ORCWG.ORG)