Format: Keynote · Required preknowledge: Intermediate · Room: EG01
Time: 14:00–14:30
Topics: Data Protection & Privacy, Cybersecurity
Article 14 of the Cyber Resilience Act introduces strict reporting obligations for manufacturers of products with digital elements when actively exploited vulnerabilities or severe security incidents occur. In practice, the challenge is not only understanding the legal thresholds, but also making fast, coordinated decisions under tight deadlines.
Using a practical product-security scenario, this session follows the reporting process from detection and initial assessment through the 24-hour early warning, 72-hour notification and subsequent reporting steps. It will examine how legal, technical, security and communications teams can coordinate their response, when users need to be informed, and how CRA reporting interacts with parallel obligations under regimes such as GDPR, NIS2 and DORA.
Speakers: Alexander Wagner, Adrian Fonger, Peter Fischer