The EU Cyber Resilience Act is moving from something organisations need to understand to something they need to prepare for. On Thursday 8th October, the IoT Security Foundation is bringing together experts from across the industry to look at what that means in practice.

Following the success of our sold-out ‘You’re not ready for the CRA’ event in July, the IoT Security Foundation is returning to London on Thursday 8th October with a follow-up event: ‘You’re STILL not ready for the CRA’ – in partnership with SafeShark.

Click HERE to register

Hosted at 89 Albert Embankment (adjacent to MI6), the event is designed for OEMs and organisations that are already thinking about the Cyber Resilience Act – but still have unanswered questions about what they actually need to do.

And there are plenty of questions to answer.

The CRA is not simply another compliance exercise. It introduces new obligations around vulnerability handling, reporting, risk assessment, technical documentation, conformity assessment and security requirements – with implications stretching across product development, engineering, cybersecurity, compliance and business operations.

So, what should you expect on Thursday 8th October?

From regulation to real-world reporting

The day will open with one of the areas where the CRA is likely to have a particularly significant practical impact: vulnerability reporting.

Richard Marshall (Xitex), chair of the CEN/CLC/JTC 13/WG 9 working group on horizontal cybersecurity for products with digital elements, will join Joe Lomako of TÜV SÜD for a fireside chat examining Article 14 and the real-world reporting timelines.

That will be followed by a panel discussion looking at Article 14 in practice, bringing together perspectives from Richard Marshall, Mustanir Ali (Element), Viktor Petersson (Screenly) and Jonathan Marshall (SafeShark).

This is an opportunity to get beyond the text of the regulation and explore what the requirements could mean for organisations actually dealing with vulnerabilities in products.

Where are the standards now?

The CRA depends heavily on standards – and understanding where those standards are heading is therefore critical.

Richard Marshall will provide a BSI update on the work of CEN JTC13/WG9, including the emerging EN 40000 series and the relationship with relevant ETSI vertical standards.

The session will provide an important opportunity to understand where the standards landscape currently stands and what organisations should be watching as they prepare for CRA compliance.

What does CRA compliance actually mean?

There is a big difference between knowing that you need to comply with the CRA and understanding what compliance will look like for an individual product.

Paul Phillips (Residio) will look at the compliance implications of the CRA, before the programme moves into a series of sessions focused on conformity assessment.

Jonathan Marshall (SafeShark) will explore lessons learnt from RED and PSTI, while Mustanir Ali (Element) will look at product classification.

These sessions will be particularly relevant to organisations trying to establish exactly where their products sit within the CRA and what assessment route may apply.

Risk assessment and threat modelling

The afternoon will get deeper into the technical detail.

A session on risk assessment, including a preview of EN 40000-1-2, will be followed by a dedicated look at threat modelling from Jonny Tyers (Threatplane).

For organisations developing connected products, this is where the conversation starts to move from “What does the CRA say?” to “How do we actually demonstrate that our products meet these requirements?”.

Documentation matters

Another important area of the CRA is product documentation.

David Pashley (Direct Insight) will look at architectural description, examining an area that can sometimes be overlooked when organisations focus primarily on technical security controls.

The message is straightforward: being secure is one thing. Being able to demonstrate, document and maintain that security throughout the product lifecycle is another.

Vulnerability handling and technical controls

The final part of the programme will turn back to some of the core technical requirements.

Attendees will get a preview of EN 40000-1-3 on vulnerability handling, followed by an update on technical requirements and controls under EN 40000-1-4, again from Richard Marshall and the BSI/CEN JTC13/WG9 perspective.

Ian Pearson (Microchip) will then provide an introduction to secure boot, before the day concludes with an open CRA Q&A.

That final session is particularly important. After a day of presentations, technical discussions and regulatory detail, attendees will have the opportunity to put their own questions to the experts.

A practical day for people who need to get this right

The CRA affects more than just cybersecurity teams.

Product managers, engineers, security professionals, compliance teams, technical authors, manufacturers, product owners and senior decision-makers all have a role to play in understanding what the regulation means for their organisation.

And while the CRA may still feel like something happening in the future, the work required to prepare for it is happening now.

That was one of the central messages from our July event. The follow-up in October is about going further: examining the reporting obligations, standards, conformity assessment, product classification, risk assessment, threat modelling, documentation, vulnerability handling and technical controls that organisations will need to understand.

The CRA is coming. The question is no longer whether organisations need to prepare, but how prepared they really are.

Join us in London on Thursday 8th October

‘You’re STILL not ready for the CRA’ takes place on Thursday 8 October 2026 at 89 Albert Embankment, London SE1 7TP (adjacent to MI6), the nearest tube station is Vauxhall (Victoria line).

The event runs from 09:30 to 16:30, with registration, coffee breaks and lunch included.

Whether you attended our July event or this is your first IoTSF CRA event, this is an opportunity to hear directly from experts working on the standards, compliance, assessment and technical aspects of the Cyber Resilience Act – and to ask the questions that matter to your organisation.

Come along, ask the difficult questions, roll some grenades and find out what you should be doing NOW to prepare.

You’re STILL not ready for the CRA.

Click HERE to see the full agenda.

Click HERE to register.

Click HERE to watch what happened at our July event.