The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Getting Ready for the EU CRA
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe. Application Security Architect and OWASP SAMM core team member Nariman Aga-Tagiyev explains what manufacturers need to know about product classes, conformity assessments, vulnerability handling, software components, and enforcement. He and the hosts explore why global software companies should care, how the rules apply to commercial uses of open source, and what implementation may look like as regulators and assessors mature. Nariman then connects compliance to practical improvement through OWASP SAMM, BSIMM, DSOMM, and openCRE. His recommendation is to start with a maturity assessment now, identify gaps team by team, and use the regulation as leverage for sustainable security rather than a last-minute paperwork exercise.
Connect with Nariman Aga-Tagiyev:
→ Nariman Aga-Tagiyev on LinkedIn
→ OWASP SAMM
Mentioned in this episode:
→ EU Cyber Resilience Act
→ OWASP SAMM
→ BSIMM
→ OWASP DevSecOps Maturity Model
→ openCRE
→ Linux Foundation
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Nariman Aga-Tagiyev
02:48 From competitive programming to AppSec
05:40 Learning security through software architecture
09:21 Nariman's work with OWASP
09:49 What the EU Cyber Resilience Act changes
13:12 Product classes and conformity assessment
16:15 Will certification work across Europe?
17:17 How complicated is CRA compliance?
18:49 Does the Act reference OWASP SAMM?
20:49 Why should companies care?
21:44 Three perspectives on the regulation
25:40 Assessing readiness team by team
28:20 How the CRA treats open source
30:04 Commercial activity in the supply chain
34:19 How enforcement may develop
36:37 Start with a maturity framework
38:27 Mapping requirements with openCRE
39:49 Closing thoughts
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo