About this talk
This talk, presented by Mélanie Bats from Obeo, focuses on operationalizing the EU Cyber Resilience Act by converting its regulatory requirements into structured development workflows. The speaker outlines a comprehensive approach that transforms CRA into a series of deliverables related to risk management, security lifecycle, governance, and continuous evidence generation. By emphasizing compliance as an integrated process rather than a simple checklist, the session highlights the importance of defining system context, assessing risks, and applying mitigation strategies, while leveraging automation for tasks like SBOM generation and vulnerability scanning. The implementation of version-controlled templates alongside application code facilitates reuse and alignment with CI pipelines, allowing teams to effectively monitor their compliance status. This discussion is crucial as it provides software producers with actionable insights necessary to meet the Cyber Resilience Act's obligations while maintaining efficiency and security standards.