From Regulation to Reality - Automating CRA Compliance for Default Products using the OSS Review
Eclipse Foundation via YouTube
Lead AI Strategy with UCSB's Agentic AI Program — Microsoft Certified
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Explore how European SMEs can navigate the mandatory cybersecurity requirements of the European Cyber Resilience Act (CRA) through automated compliance solutions in this 17-minute conference talk. Learn about the regulatory landscape affecting approximately 90% of software products categorized as "default" products, where manufacturers can self-assess their compliance. Discover practical insights from the EU-funded OCCTET project and the Eclipse Open Regulatory Compliance Working Group's standardization efforts. Follow a comprehensive compliance journey that maps pre- and post-market obligations for SMEs, focusing on the CRA-mandated cybersecurity risk assessment process that enables proper scoping of security activities. Examine how the OSS Review Toolkit (ORT) and Eclipse-hosted ORT-Server can automate critical compliance tasks including software asset identification, management oversight, work prioritization, Software Component Analysis (SCA), source code scanning, vulnerability analysis, rule evaluation, SBOM generation, and audit trail documentation. Understand the current gaps between available tooling and regulatory requirements, and gain clarity on which processes can be automated versus those requiring manual intervention to ensure cyber resilience compliance.
Syllabus
From Regulation to Reality: Automating CRA Compliance for Default Products using the OSS Review
Taught by
Eclipse Foundation