Testing Services
Industry
EU CRAFDA & MDRPayment & FinanceNewsAbout Us
EN繁中
Contact Us
← Back to news
News

CRA Full-Compliance Countdown

August 26, 2026
CRA Full-Compliance Countdown

Event overview

The EU Cyber Resilience Act's incident-reporting obligation is now in force — but for companies entering, or already selling into, the EU market, that was only the warm-up.

Between now and December 11, 2027, when the CRA's main product requirements apply in full, companies still face product scope and classification, conformity assessment, SBOM, vulnerability management, technical documentation, and continuous post-market security maintenance.

Counting from today, roughly 15 months remain before full application.

On September 18, Jose Ruiz Gualda, Cybersecurity Business Unit Director at Applus+ Laboratories, flies in from Spain to walk through the CRA — from regulatory requirements to the practical execution of product conformity assessment — drawing on front-line European product-security assessment experience.

This session doesn't start from "what is the CRA". It goes straight to the questions companies face once compliance work actually begins: Does your product fall under the CRA? Which conformity-assessment route should it take? And how do your existing EN 18031 results, SBOMs, and security-testing evidence carry over?

Five things to prepare before the CRA applies in full

  1. Set up an incident-reporting mechanism — when a vulnerability or major incident occurs, does your organization have a clear process to assess, handle, and report it within the statutory deadlines?
  2. Confirm product scope and classification — product class determines the conformity-assessment route; establishing whether and where your product falls under the CRA is the first step of any plan.
  3. Map against the Annex I essential requirements — the CRA builds security into design and development; review Secure-by-Design requirements at the product level rather than bolting on testing before launch.
  4. Build SBOM and vulnerability management — an SBOM is not a one-off document; post-market vulnerability monitoring, CVE handling, security updates, and ongoing maintenance all need standing mechanisms.
  5. Plan conformity assessment and technical documentation — from the assessment route and security-testing evidence to the technical file, EU Declaration of Conformity, and CE marking, plan ahead according to your product's situation.

Why this session is different

The market has no shortage of CRA overviews and introductory courses. This session is about where products actually get stuck once compliance work begins.

Jose Ruiz Gualda brings years of product-security assessment and international certification experience. Visiting from Spain, he'll share the European practice view of the CRA and product security — and discuss, live, the questions Taiwanese companies most often face on product applicability, conformity assessment, and technical preparation.

The event is an in-person exchange: CRA product classification, EN 18031, SBOM, vulnerability management, technical documentation, support periods, and conformity-assessment routes are all open for discussion on the spot.

Secure Vectors is a local ISO/IEC 17025-accredited security laboratory in Taiwan, providing product security testing, technical documentation, and compliance-planning support — combined with Applus+ Laboratories' international certification resources to carry you into the conformity assessment itself.

From product classification and security testing to conformity assessment: the CRA isn't just about understanding the regulation — it's about knowing what to do next.

Session highlights

  • 🌏 CRA practice from the European front line: the latest CRA developments and practical direction, seen from European product security and conformity assessment.
  • 🔍 Product classification and conformity assessment: clarifying product scope, classification, and the assessment routes available to different products.
  • 🛠️ Corporate compliance preparation: from SBOM, CVE and vulnerability management, and product security testing to technical documentation — what to finish before full application.
  • 💬 Live exchange and product Q&A: the Applus+ Laboratories and Secure Vectors teams on site, discussing real execution issues in the CRA process directly.

Event details

📅 2026.09.18 (Fri) — check-in 13:30, session starts 14:00

📍 Secure Vectors Lab (MRT Nanjing Fuxing Station Exit 8 / Songjiang Nanjing Station Exit 6)

🎟️ Seats are limited

🔗 Register now →

Agenda

  • 13:30 — Check-in
  • 14:05–14:10 — Opening remarks — Host: Tina
  • 14:10–14:50 — Taiwanese companies and the CRA: from regulatory requirements to product readiness — Vincent Huang | CEO, Secure Vectors
  • 14:50–15:05 — Break
  • 15:05–15:50 — The CRA from Europe: product conformity assessment in practice — Jose Ruiz Gualda | Cybersecurity Business Unit Director, Applus+ Laboratories
  • 15:50–16:05 — From CRA requirements to execution: the next step for Taiwanese companies — Tina Wu | VP of Business Development, Secure Vectors
  • 16:05–16:20 — Panel discussion & Q&A — All speakers
  • 16:20– — Closing & networking

Speakers

Vincent Huang

CEO, Secure Vectors. A veteran security consultant holding all three international assessor qualifications — PCI DSS QSA, 3DS QSA, and PIN Security QPA. His team has long provided payment security testing, assessment, and consulting, and is one of the few in Taiwan qualified across domains including payment security assessment.

Jose Ruiz Gualda

Cybersecurity Business Unit Director, Applus+ Laboratories. Based in Spain, with over 14 years in product security evaluation; has led Common Criteria certification services and contributed to more than 40 international security certifications. Currently driving Applus+'s CRA conformity-assessment and Notified Body programs, combining technical assessment with regulatory implementation.

Tina Wu

VP of Business Development, Secure Vectors. Long responsible for Secure Vectors' international business development and partnerships, with compliance-project experience across PCI DSS, ISO 27001, and product security. In recent years she has driven the lab's business development, the partnership with Applus+ Laboratories, and EU product-compliance services covering EN 18031, the CRA, and the MDR.

#CRA #CyberResilienceAct #網路韌性法案 #EUCompliance #SBOM #CVE #NotifiedBody #EN18031

Keep Reading

More from the lab