Resources
>
Events
>
ONEKEY WEBINAR: Cyber Resilience Act – A Practical Guide to Scope, Obligations and Implementation

ONEKEY WEBINAR: Cyber Resilience Act – A Practical Guide to Scope, Obligations and Implementation | Mandarin Webinar

ONEKEY WEBINAR: Cyber Resilience Act – A Practical Guide to Scope, Obligations and Implementation
Tanja Sommer

READY TO UPGRADE YOUR RISK MANAGEMENT?

Make cybersecurity and compliance efficient and effective with ONEKEY.

Book a Demo
Tanja Sommer

Tanja Sommer
tanja.sommer@onekey.com

Join us for an exclusive ONEKEY webinar in Mandarin on September 24, 2026, at 8:00 a.m. (CEST) / 2:00 p.m. (GMT+8)!

The Cyber Resilience Act is changing the requirements for bringing connected hardware and software to the EU market. Learn what the CRA means for your products, responsibilities, and processes — from scope and Annex I requirements to conformity, reporting, and implementation.

Cyber Resilience Act – A Practical Guide to Scope, Obligations and Implementation

The Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for hardware and software products with digital elements throughout their lifecycle. Manufacturers need to assess cybersecurity risks, implement the essential requirements of Annex I, demonstrate conformity, and continue vulnerability handling after products have entered the market.

With the CRA’s mandatory reporting obligations now in effect and the main requirements applying from December 11, 2027, organizations need to understand not only whether their products fall within scope, but also what the regulation means for their responsibilities, technical processes, and compliance activities.

CRA compliance is not a one-time exercise. It affects the entire product lifecycle — from risk assessment, secure design and development to conformity assessment, market entry, vulnerability handling, security updates, and reporting.

What You’ll Learn

In this 45-minute Mandarin-language webinar, Jen-Chih Lo will provide a practical overview of the Cyber Resilience Act, covering its scope, key obligations, conformity requirements, reporting obligations, implementation, and the role of the emerging EN 40000 standards.

You’ll learn:

  • Which products and economic operators fall within the scope of the CRA and how responsibilities differ across the supply chain
  • What manufacturers need to consider throughout the entire product lifecycle — before, at, and after market entry
  • Which cybersecurity, vulnerability handling, and SBOM requirements apply under Annex I
  • How product classification affects conformity assessment, technical documentation, and CE marking
  • Which reporting obligations and timelines apply for actively exploited vulnerabilities and severe security incidents
  • How to structure CRA implementation toward December 2027 and how the emerging EN 40000 standards can support risk management, vulnerability handling, and technical evidence  

The webinar will also look at DIN EN 40000-1-2 and DIN EN 40000-1-3, and how these emerging standards can help translate CRA requirements into structured approaches for cybersecurity risk management and vulnerability handling.

Who Should Attend?

This webinar is designed for professionals working in:

  • Product Cybersecurity
  • Compliance
  • Product Development
  • Product Management
  • Vulnerability Management
  • Embedded Software Development
  • Technical and Regulatory Functions

Whether you are currently assessing which products fall within the scope of the CRA or already working on implementation, this webinar provides a practical overview of the requirements and the key workstreams organizations need to address.

Prepare for CRA Compliance

The CRA’s mandatory reporting obligations are already in effect, while the main product requirements will apply from December 11, 2027.

Now is the time to ensure that product scope, responsibilities, cybersecurity controls, vulnerability processes, conformity evidence, and reporting readiness are addressed in a structured manner.

Join us on September 24 for a practical guide to the CRA and the steps organizations should take on their path toward compliance.

Can’t join live? Register anyway and you’ll receive the on-demand recording after the webinar.

See Event Here

Meet us there

ONEKEY WEBINAR: Cyber Resilience Act – A Practical Guide to Scope, Obligations and Implementation

SPEAKERS

ON-SITE TEAM

Jen Chih-lo

Jen Chih-lo

Sales Manager

Jen-Chih has years of experience with customers within semi-conductor industry and industrial automation specifically in East Asia. His expertise helps customer understanding how to increase ROI by reducing repetitive monitoring tasks.

Share

RELATED Events

ONEKEY Webinar: From Firmware to SBOM: Building Evidence-Based Software Inventories
ONEKEY Webinar: PSIRT – Start Small, but Start | CRA Implications on Notification Obligations
ONEKEY Webinar: CRA Phase I: Incident Reporting & Operational Readiness

About Onekey

ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life.

CONTACT:
Sara Fortmann

Senior Marketing Manager
sara.fortmann@onekey.com

euromarcom public relations GmbH
team@euromarcom.de

Make cybersecurity and compliance efficient and effective with ONEKEY.