CRA 2026: The new standard for High-Tech and Industrial Equipment OEMs.
Ein informatives Webinar unseres Herstellers Dassault Systèmes
The Cyber Resilience Act is coming. Let's build a secure future together.
Context
From September 2026, OEMs selling products with digital elements in the EU will face strict CRA reporting obligations, including a 24-hour warning and a 72-hour incident notification window. For high-tech and industrial equipment companies, cybersecurity is no longer only an IT topic, it is now a market-access and product-safety requirement. Without traceability and continuous vulnerability management, organizations risk regulatory exposure, CE marking delays, and penalties up to €15M (or 2.5% of global annual turnover).
Abstract
In this webinar, we break down what the Cyber Resilience Act means in practical terms for High-Tech and Industrial Equipment OEMs. You will learn which products are in scope, what “secure by design and by default” requires, and why manual tracking in spreadsheets cannot support CRA readiness. We will show how a live Software BOM (SWBOM), linked to physical components, enables end-to-end traceability, faster incident response, and continuous compliance. The session also covers a platform-based approach to risk monitoring, vulnerability workflows, investigation requests, and CE conformity support across the full lifecycle.
What attendees will learn
- What changes in September 2026
- The 24h / 72h CRA reporting obligations and operational impact
- Why SWBOM is now essential for compliance and auditability
- How to link software, hardware, and requirements for full traceability
- How to protect CE marking and market access through continuous vigilance