Following the success of our ‘You’re not ready for the CRA’ event in July, the IoT Security Foundation is bringing the conversation back to London on Thursday 8th October for ‘You’re STILL not ready for the CRA’.

This follow-up event, hosted at the Marylebone premises of Which?, will bring together experts and industry practitioners to look at what has changed, what organisations should be doing now, and where the biggest challenges still lie.

Whether you attended the July event or you’re coming to the conversation for the first time, this is an opportunity to get up to speed, ask the difficult questions, roll some grenades and find out what you should be doing NOW to prepare.

The message from July hasn’t changed, the CRA is coming. You’re STILL not ready!

Click HERE to register.

Presentation slides from the first CRA event are available via our members’ platfom, go to Plenary> Docs & Files.

Watch 5 expert sessions from our July CRA event on our YouTube channel.

Agenda (subject to change)

09:30 – Registration
10:00 Opening address
10:20 CRA reporting obligations (Article 14) – What are the real world reporting timelines? A fireside chat with Richard Marshall (BSI CEN/CLC/JTC 13/WG 9 “Horizontal cybersecurity for products with Digital Elements” working group chair and Xitex) and Joe Lomako (TUV SUD)
10:40 Panel discussion – Article 14 in practice: Richard Marshall (chair), Mustanir Ali (Element), Viktor Petersson (Screenly) and Jonathan Marshall (SafeShark)

11:15 Coffee and networking break

11:35 CRA standards update CEN/CLC/JTC 13/WG 9, EN 40000 series standards and ETSI vertical standards – BSI update from CEN JTC13/WG9 : Richard Marshall (IST33/-/9 Chair)
11:55 CRA compliance implications: Paul Phillips (Residio)
12:15 CRA conformity assessment – Lessons learnt from RED/PSTI: Jonathan Marshall (SafeShark)

12:30 Lunch (included with your ticket)

13:15 CRA conformity assessment – Product classification: Mustanir Ali (Element)
13:35 CRA conformity assessment – Risk assessment (EN 40000-1-2 preview)
13:55 CRA conformity assessment – Threat modelling: Jonny Tyers (Threatplane)
14:15 Product documentation – Architectural description: David Pashley (Direct Insight)

14:35 Coffee and networking break

14:55 Vulnerability handling (EN 40000-1-3 preview)
15:15 Technical requirements and controls (EN 40000-1-4 preview) – BSI update from CEN JTC13/WG9: Richard Marshall (IST33/-/9 Chair)
15:35 An introduction to secure boot: Ian Pearson (Microchip)
15:55 CRA Q&A session
16:30 Valedictory and event close