Watch the Dutch-spoken webinar
Within one hour up to speed with the Cyber Resilience Act (CRA)
The CRA’s reporting obligations take effect from now and your organisation needs to be fully compliant by the end of 2027. High time to work out what this means for you.
In just one hour, you’ll find out whether the CRA applies to your situation and what the most urgent action points are. We’ll look at the topic from three angles: legal, technical and security.
- 17 September 2026
- 13:00
- Online webinar
- 🇳🇱 NL
Gain access to our webinar
CRANIUM protects your data. Sharing knowledge is at our core so providing this eBook is a service provided by CRANIUM. However, we will only use the information you have entered to respond to your query or to contact you with relevant information about the eBook you have downloaded. We will not use your data for other purposes and will only contact you about topics directly related to this eBook. You will also always have the opportunity to oppose the use of your data for these direct marketing purposes via electronic mail. Want to know more about how we safeguard your privacy? Then read our privacy statement.
What is the webinar about?
A vulnerability in your product is being actively exploited. From that moment, the clock starts ticking under the Cyber Resilience Act (CRA): an initial notification to ENISA within 24 hours, a full notification within 72 hours, followed by a final report. Who’s liable if those deadlines aren’t met?
That’s not a technical question, it’s a legal one. The CRA places obligations on manufacturers, importers and distributors, and these differ depending on your role in the chain. Who counts as a manufacturer the moment you modify or resell a product under your own name? Most organisations haven’t worked this out legally yet.
Together with Cingulum and Refracted Security, we’ll help you get a clear picture of that liability: what the regulation actually requires, and where the limits of your responsibility lie.
Who are the hosts?
Head of Digital Law at CRANIUM
Bernd guides organisations through the legal and contractual impact of new regulation such as the Cyber Resilience Act, with a strong focus on practical applicability within existing processes and contracts. Bernd helps companies throughout the entire chain, from suppliers to customers, to do business in a compliant and future-proof way.
Expert Consultant at Cingulum
Stijn’s interest in cybersecurity started early: as a child, he spent so much time behind the computer that his father had to lock the door to keep him out. He started his career on the technical side, as a pentester and in development, and grew from there into broader security challenges. Today, he helps companies embed security not just technically, but organisationally too.
Cybersecurity Advisor at Refracted
Siebe De Roovere is Security Advisor and CISO at Refracted Security, where he helps manufacturers turn CRA obligations into working product security. He is certified in the EU Cyber Resilience Act and OWASP SAMM, and has been a guest lecturer in cybersecurity strategy at UGent and KU Leuven for over eight years.
Blogpost
Who is liable when the clock starts ticking?
From who counts as a manufacturer to the impact on your contracts: Digital Law Consultant Michael Thomas sets out the key questions on the CRA.