139. Cyber Resilience Act: What Developers Need to Know
Betabit
0:00 / 0:00
139. Cyber Resilience Act: What Developers Need to Know
124 просмотра · 13 дней назад
Betabit
869 подписчиков
124 просмотра · 13 дней назад
Jelle and Christian explore the European Cyber Resilience Act (CRA), which takes (partial) effect on September 11, 2026. They summarize what it means for software engineers and show a handy way to detect whether the CRA applies to your software product. They of course cover key requirements such as security by design, patching, incident communication, and software bills of materials (SBOMs). They also discuss the impact on development teams and how following the security requirements in the CRA may be worthwhile even if they are not required for your team, as they can strengthen your DevSecOps practices.
Links for more information:
https://www.cracowi.eu/cra-scope-check/
https://digital-strategy.ec.europa.eu...
SBOM betatalks: • 130. How SBOMs Expose Vulnerabilities in Y...
Timestamps:
00:00 - The Cyber Resilience Act (CRA): security as a regulatory requirement
02:06 - How does the CRA fit into the broader EU landscape of security and privacy laws?
03:06 - Which products are in scope of the CRA?
05:00 - Doing a CRA Scope Assessment
08:24 - What will we need to do?
09:10 - Why are the EUs objectives with the CRA?
09:48 - What are the core CRA requirements?
12:08 - What is the impact of the CRA on my team?
12:42 - The biggest impact: risk, release and report
13:28 - Why you shouldn't ignore the CRA requirements even if it isn't applicable
14:18 - Why is it named Resilience Act instead of Security Act?
15:26 - Why the CRA applies to products instead of software
16:20 - Closing remarks and wrap-up
There is more to come!