About this talk
This talk, presented by August Bournique from Bow Shock Consulting, delves into the complexities and challenges associated with the development of Cyber Resilience Act (CRA) standards throughout Europe. It outlines the evolving processes that began following the CRA's adoption in 2024, focusing on product-level cybersecurity requirements and the implications for development lifecycles. The speaker highlights the intricate landscape of concurrent standard development, affected by factors such as limited coordination and the need for industry participation, while also addressing the limitations of traditional consensus-based approaches. The session emphasizes the significance of open source communities in fostering collaboration and technical expertise to ensure standards remain practical and relevant in a rapidly changing regulatory environment. Consequently, it suggests that CRA standards will need to evolve iteratively, necessitating continuous updates and broad stakeholder engagement.