EPISODE · Aug 20, 2025 · 40 MIN
Getting Ready for the EU CRA
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
The EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe. Application Security Architect and OWASP SAMM core team member Nariman Aga-Tagiyev explains what manufacturers need to know about product classes, conformity assessments, vulnerability handling, software components, and enforcement. He and the hosts explore why global software companies should care, how the rules apply to commercial uses of open source, and what implementation may look like as regulators and assessors mature. Nariman then connects compliance to practical improvement through OWASP SAMM, BSIMM, DSOMM, and openCRE. His recommendation is to start with a maturity assessment now, identify gaps team by team, and use the regulation as leverage for sustainable security rather than a last-minute paperwork exercise.Connect with Nariman Aga-Tagiyev:→ Nariman Aga-Tagiyev on LinkedIn→ OWASP SAMMMentioned in this episode:→ EU Cyber Resilience Act→ OWASP SAMM→ BSIMM→ OWASP DevSecOps Maturity Model→ openCRE→ Linux FoundationFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Nariman Aga-Tagiyev02:48 From competitive programming to AppSec05:40 Learning security through software architecture09:21 Nariman's work with OWASP09:49 What the EU Cyber Resilience Act changes13:12 Product classes and conformity assessment16:15 Will certification work across Europe?17:17 How complicated is CRA compliance?18:49 Does the Act reference OWASP SAMM?20:49 Why should companies care?21:44 Three perspectives on the regulation25:40 Assessing readiness team by team28:20 How the CRA treats open source30:04 Commercial activity in the supply chain34:19 How enforcement may develop36:37 Start with a maturity framework38:27 Mapping requirements with openCRE39:49 Closing thoughts
Embed this episode
What this episode covers
The EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe. Application Security Architect and OWASP SAMM core team member Nariman Aga-Tagiyev explains what manufacturers need to know about product classes, conformity assessments, vulnerability handling, software components, and enforcement. He and the hosts explore why global software companies should care, how the rules apply to commercial uses of open ...
Ready to play
Getting Ready for the EU CRA
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.