Preparing for CRA Compliance – From Guidance to Action

In this webinar, Antti Tolvanen, Product Cybersecurity Strategy Consultant at DNV Cyber, will summarize the most important interpretations from the CRA guidance, discuss the key changes compared to the draft version, and explain what organizations should be doing now to prepare for compliance.

The Cyber Resilience Act (CRA) is moving from interpretation to implementation. 

Following the publication of the European Commission's CRA guidance and the introduction of CRA manufacturer reporting obligations on 11 September 2026, organizations supplying products with digital elements to the European market are entering a new phase of CRA compliance.  
 
While many companies have spent the past year assessing whether the CRA applies to them and initiating investments in product cybersecurity, attention is now shifting towards how the requirements should be implemented in practice across products and processes, and how manufacturers can fulfil their reporting obligations.

The reporting obligations begin to apply on 11 September 2026, ahead of the CRA's full application in December 2027. 

The CRA guidance provides greater clarity on several key aspects of the Regulation, helping organizations better understand the applicability of the CRA, the scope of products with digital elements, standalone software products and complex systems, substantial modifications, and the practical expectations placed on manufacturers, importers and distributors.  

In this webinar, Antti Tolvanen, Product Cybersecurity Strategy Consultant at DNV Cyber, will summarize the most important interpretations from the CRA guidance, discuss the key changes compared to the draft version, and explain what organizations should be doing now to prepare for compliance. 

The latest developments related to the applicability of the CRA to maritime products and systems outside the scope of the Marine Equipment Directive (MED) will also be discussed. 
 
Key takeaways:  

  • Key changes and interpretations introduced in the CRA guidance 
  • Main tasks in fulfilling CRA manufacturer reporting obligations  
  • A strategic perspective on CRA-related investments: necessary burden, business enabler, or competitive advantage? 
  • How to prepare products, processes and supply chains for full CRA application in December 2027 
  • Latest CRA developments affecting maritime sector products 
     

Speaker 

Antti Tolvanen is a Product Cybersecurity Strategy Consultant at DNV Cyber, with extensive experience in EU product safety and cybersecurity regulations in the context of connected and software-driven products. He works closely with organizations across industries to understand emerging regulatory and market requirements and translate them into practical, implementable product cybersecurity strategies.