The Application Security Podcast

Getting Ready for the EU CRA

Chris Romeo and Robert Hurlbut Season 12 Episode 15

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 40:46

The EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe. Application Security Architect and OWASP SAMM core team member Nariman Aga-Tagiyev explains what manufacturers need to know about product classes, conformity assessments, vulnerability handling, software components, and enforcement. He and the hosts explore why global software companies should care, how the rules apply to commercial uses of open source, and what implementation may look like as regulators and assessors mature. Nariman then connects compliance to practical improvement through OWASP SAMM, BSIMM, DSOMM, and openCRE. His recommendation is to start with a maturity assessment now, identify gaps team by team, and use the regulation as leverage for sustainable security rather than a last-minute paperwork exercise.

Connect with Nariman Aga-Tagiyev:
Nariman Aga-Tagiyev on LinkedIn
OWASP SAMM

Mentioned in this episode:
EU Cyber Resilience Act
OWASP SAMM
BSIMM
OWASP DevSecOps Maturity Model
openCRE
Linux Foundation

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Nariman Aga-Tagiyev
02:48 From competitive programming to AppSec
05:40 Learning security through software architecture
09:21 Nariman's work with OWASP
09:49 What the EU Cyber Resilience Act changes
13:12 Product classes and conformity assessment
16:15 Will certification work across Europe?
17:17 How complicated is CRA compliance?
18:49 Does the Act reference OWASP SAMM?
20:49 Why should companies care?
21:44 Three perspectives on the regulation
25:40 Assessing readiness team by team
28:20 How the CRA treats open source
30:04 Commercial activity in the supply chain
34:19 How enforcement may develop
36:37 Start with a maturity framework
38:27 Mapping requirements with openCRE
39:49 Closing thoughts

Follow the Application Security Podcast:

➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo