ONEKEY WEBINAR: Cyber Resilience Act – A Practical Guide to Scope, Obligations and Implementation | Mandarin Webinar

READY TO UPGRADE YOUR RISK MANAGEMENT?
Make cybersecurity and compliance efficient and effective with ONEKEY.
.avif)
Tanja Sommer
tanja.sommer@onekey.com
Join us for an exclusive ONEKEY webinar in Mandarin on September 24, 2026, at 8:00 a.m. (CEST) / 2:00 p.m. (GMT+8)!
The Cyber Resilience Act is changing the requirements for bringing connected hardware and software to the EU market. Learn what the CRA means for your products, responsibilities, and processes — from scope and Annex I requirements to conformity, reporting, and implementation.
Cyber Resilience Act – A Practical Guide to Scope, Obligations and Implementation
The Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for hardware and software products with digital elements throughout their lifecycle. Manufacturers need to assess cybersecurity risks, implement the essential requirements of Annex I, demonstrate conformity, and continue vulnerability handling after products have entered the market.
With the CRA’s mandatory reporting obligations now in effect and the main requirements applying from December 11, 2027, organizations need to understand not only whether their products fall within scope, but also what the regulation means for their responsibilities, technical processes, and compliance activities.
CRA compliance is not a one-time exercise. It affects the entire product lifecycle — from risk assessment, secure design and development to conformity assessment, market entry, vulnerability handling, security updates, and reporting.
What You’ll Learn
In this 45-minute Mandarin-language webinar, Jen-Chih Lo will provide a practical overview of the Cyber Resilience Act, covering its scope, key obligations, conformity requirements, reporting obligations, implementation, and the role of the emerging EN 40000 standards.
You’ll learn:
- Which products and economic operators fall within the scope of the CRA and how responsibilities differ across the supply chain
- What manufacturers need to consider throughout the entire product lifecycle — before, at, and after market entry
- Which cybersecurity, vulnerability handling, and SBOM requirements apply under Annex I
- How product classification affects conformity assessment, technical documentation, and CE marking
- Which reporting obligations and timelines apply for actively exploited vulnerabilities and severe security incidents
- How to structure CRA implementation toward December 2027 and how the emerging EN 40000 standards can support risk management, vulnerability handling, and technical evidence
The webinar will also look at DIN EN 40000-1-2 and DIN EN 40000-1-3, and how these emerging standards can help translate CRA requirements into structured approaches for cybersecurity risk management and vulnerability handling.
Who Should Attend?
This webinar is designed for professionals working in:
- Product Cybersecurity
- Compliance
- Product Development
- Product Management
- Vulnerability Management
- Embedded Software Development
- Technical and Regulatory Functions
Whether you are currently assessing which products fall within the scope of the CRA or already working on implementation, this webinar provides a practical overview of the requirements and the key workstreams organizations need to address.
Prepare for CRA Compliance
The CRA’s mandatory reporting obligations are already in effect, while the main product requirements will apply from December 11, 2027.
Now is the time to ensure that product scope, responsibilities, cybersecurity controls, vulnerability processes, conformity evidence, and reporting readiness are addressed in a structured manner.
Join us on September 24 for a practical guide to the CRA and the steps organizations should take on their path toward compliance.
Can’t join live? Register anyway and you’ll receive the on-demand recording after the webinar.
Meet us there

SPEAKERS
ON-SITE TEAM

Jen Chih-lo
Jen-Chih has years of experience with customers within semi-conductor industry and industrial automation specifically in East Asia. His expertise helps customer understanding how to increase ROI by reducing repetitive monitoring tasks.
RELATED Events

ONEKEY Webinar: From Firmware to SBOM: Building Evidence-Based Software Inventories
Learn how binary firmware analysis can identify software components and generate evidence-based, actionable SBOMs. Join our ONEKEY webinar on September 10.
About Onekey
ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life.

CONTACT:
Sara Fortmann
Senior Marketing Manager
sara.fortmann@onekey.com
euromarcom public relations GmbH
team@euromarcom.de
Ready to automate your Product Cybersecurity & Compliance?
Make cybersecurity and compliance efficient and effective with ONEKEY.


