Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

The CRA - Why Even Your Fridge Might Need a Lawyer

Eclipse Foundation via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore the legal implications of the Cyber Resilience Act (CRA) for open source software in this comprehensive webinar featuring IT compliance attorney Pedro Demolder from Timelex. Understand how the CRA functions as both cybersecurity and product legislation, defining what constitutes a "product with digital elements" and how manufacturers must approach due diligence when integrating open source components. Learn the practical framework for CRA compliance including fact-finding, staging, implementation, and maintenance phases, while examining real-world applications across servers, software, and cloud services. Discover how the CRA intersects with other regulations like GDPR, AI Act, NIS2, and Data Act, and gain insight into CE marking requirements and security attestations. Participate in live Q&A sessions covering API responsibilities, remote data processing, user consent, and the evolving roles of open source stewards. Examine how legal teams collaborate with engineers during implementation phases and understand how CRA compliance can serve as a business differentiator through industry standards. Address critical questions about product liability and whether CRA compliance can limit legal exposure, while exploring the broader implications for the open source ecosystem and community preparedness for regulatory changes.

Syllabus

00:00 - Introduction and welcome
01:37 - How IT lawyers interpret CRA and related legislation
05:05 - CRA as a combination of cybersecurity and product legislation
07:00 - What is a “product with digital elements”?
09:50 - Applying CRA: legal scoping of material, personal, and territorial relevance
12:20 - Practical steps: fact-finding → staging → implementation → maintenance
16:35 - CRA applied to real-world components: servers, software, cloud
21:00 - Due diligence and third-party components, including FOSS
23:20 - CE marking, security attestations, and the manufacturer’s responsibility
26:00 - Overlapping legislation: CRA, GDPR, AI Act, NIS2, Data Act
28:00 - Live Q&A: API responsibilities, remote data processing, user consent
36:30 - Clarifying roles for open source stewards and attestations
43:00 - How lawyers work with engineers on staging and implementation
46:45 - CRA as a business differentiator and the role of standards
52:00 - CRA and Product Liability: can compliance limit legal exposure?
56:00 - Wrap-up and where to find Pedro online

Taught by

Eclipse Foundation

Reviews

Start your review of The CRA - Why Even Your Fridge Might Need a Lawyer

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.