
The EU Cyber Resilience Act's incident-reporting obligation is now in force — but for companies entering, or already selling into, the EU market, that was only the warm-up.
Between now and December 11, 2027, when the CRA's main product requirements apply in full, companies still face product scope and classification, conformity assessment, SBOM, vulnerability management, technical documentation, and continuous post-market security maintenance.
Counting from today, roughly 15 months remain before full application.
On September 18, Jose Ruiz Gualda, Cybersecurity Business Unit Director at Applus+ Laboratories, flies in from Spain to walk through the CRA — from regulatory requirements to the practical execution of product conformity assessment — drawing on front-line European product-security assessment experience.
This session doesn't start from "what is the CRA". It goes straight to the questions companies face once compliance work actually begins: Does your product fall under the CRA? Which conformity-assessment route should it take? And how do your existing EN 18031 results, SBOMs, and security-testing evidence carry over?
The market has no shortage of CRA overviews and introductory courses. This session is about where products actually get stuck once compliance work begins.
Jose Ruiz Gualda brings years of product-security assessment and international certification experience. Visiting from Spain, he'll share the European practice view of the CRA and product security — and discuss, live, the questions Taiwanese companies most often face on product applicability, conformity assessment, and technical preparation.
The event is an in-person exchange: CRA product classification, EN 18031, SBOM, vulnerability management, technical documentation, support periods, and conformity-assessment routes are all open for discussion on the spot.
Secure Vectors is a local ISO/IEC 17025-accredited security laboratory in Taiwan, providing product security testing, technical documentation, and compliance-planning support — combined with Applus+ Laboratories' international certification resources to carry you into the conformity assessment itself.
From product classification and security testing to conformity assessment: the CRA isn't just about understanding the regulation — it's about knowing what to do next.
📅 2026.09.18 (Fri) — check-in 13:30, session starts 14:00
📍 Secure Vectors Lab (MRT Nanjing Fuxing Station Exit 8 / Songjiang Nanjing Station Exit 6)
🎟️ Seats are limited
CEO, Secure Vectors. A veteran security consultant holding all three international assessor qualifications — PCI DSS QSA, 3DS QSA, and PIN Security QPA. His team has long provided payment security testing, assessment, and consulting, and is one of the few in Taiwan qualified across domains including payment security assessment.
Cybersecurity Business Unit Director, Applus+ Laboratories. Based in Spain, with over 14 years in product security evaluation; has led Common Criteria certification services and contributed to more than 40 international security certifications. Currently driving Applus+'s CRA conformity-assessment and Notified Body programs, combining technical assessment with regulatory implementation.
VP of Business Development, Secure Vectors. Long responsible for Secure Vectors' international business development and partnerships, with compliance-project experience across PCI DSS, ISO 27001, and product security. In recent years she has driven the lab's business development, the partnership with Applus+ Laboratories, and EU product-compliance services covering EN 18031, the CRA, and the MDR.
#CRA #CyberResilienceAct #網路韌性法案 #EUCompliance #SBOM #CVE #NotifiedBody #EN18031