📆 Date: Wednesday 14th October 2026
🕒 Time: 3:30 PM BST
🌐 Online Event: Join from anywhere
Many device makers have products already in production and already sold to customers, with plans to keep selling them for years to come. The EU Cyber Resilience Act (CRA) doesn’t apply retroactively to units already in the field; it applies to any unit placed on the market after it comes into force in December 2027. So if a device maker wants to keep selling an existing product past that date, every unit shipped from then on must meet the CRA’s essential cybersecurity requirements. This webinar exists to help device makers in exactly that position: it lays out a concrete, practical path to bring an existing product into compliance so it can keep being sold, without pulling it from the market or redesigning it from scratch.
Rather than treating this as an abstract compliance exercise, we’ll follow the realistic journey a manufacturer would actually take, anchored around a running example: a fictional but representative device that launched before the CRA existed and that its manufacturer wants to keep selling beyond the 2027 deadline. We’ll carry this one product through every stage of the session, so each concept is grounded in something tangible rather than left as theory.
The session is split into 4 phases:
-
We start by introducing the product and framing the compliance problem, then sketch the high-level roadmap we’ll follow for the rest of the hour.
-
From there, we establish the product’s boundary and core functionality to determine its classification, and use that to identify the applicable conformity assessment route and the harmonised standards that apply.
-
With that foundation set, we run a gap analysis against the CRA’s requirements, paired with a cybersecurity risk assessment, to surface exactly where the product falls short.
-
The final phase is about closing those gaps and sustaining compliance over time: using software supply-chain scanning to detect CVEs, upgrading and maintaining core components, handling vendor end-of-life, meeting support-period obligations, sustaining long-term support (LTS) for kernels and Board Support Packages (BSPs), and assembling the technical documentation and evidence pack that proves it’s all been done.
Attendees will leave with more than an explanation of the CRA. They’ll have watched the full process applied to a realistic product. The goal is for you to walk out ready to run this same exercise against your own products: knowing what questions to ask, what evidence to produce, and what it takes to remain compliant throughout the life of your product.