The Cyber Resilience Act in practice: One regulation, many ecosystems
About this talk
This panel discusses the practical challenges of implementing the Cyber Resilience Act (CRA) across various sectors, featuring insights from industry leaders and representatives from the European Commission and the Centre for Cybersecurity Belgium. The speakers address how the CRA aims to create a unified regulatory framework while highlighting the complexities of coordination among stakeholders with diverse operational models. Key issues identified include the absence of fully defined standards, the evolving nature of regulatory guidance, and interpretations of roles within open source software stewardship, especially given the concerns about liability and compliance expectations. The panel advocates for iterative implementation supported by collaborative efforts, standardisation, and clear communication between manufacturers and open source projects, emphasizing the importance of timely preparation for compliance with new regulations in the software supply chain.