Getting Ready for the EU CRA episode artwork

EPISODE · Aug 20, 2025 · 40 MIN

Getting Ready for the EU CRA

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

The EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe. Application Security Architect and OWASP SAMM core team member Nariman Aga-Tagiyev explains what manufacturers need to know about product classes, conformity assessments, vulnerability handling, software components, and enforcement. He and the hosts explore why global software companies should care, how the rules apply to commercial uses of open source, and what implementation may look like as regulators and assessors mature. Nariman then connects compliance to practical improvement through OWASP SAMM, BSIMM, DSOMM, and openCRE. His recommendation is to start with a maturity assessment now, identify gaps team by team, and use the regulation as leverage for sustainable security rather than a last-minute paperwork exercise.Connect with Nariman Aga-Tagiyev:→ Nariman Aga-Tagiyev on LinkedIn→ OWASP SAMMMentioned in this episode:→ EU Cyber Resilience Act→ OWASP SAMM→ BSIMM→ OWASP DevSecOps Maturity Model→ openCRE→ Linux FoundationFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Nariman Aga-Tagiyev02:48 From competitive programming to AppSec05:40 Learning security through software architecture09:21 Nariman's work with OWASP09:49 What the EU Cyber Resilience Act changes13:12 Product classes and conformity assessment16:15 Will certification work across Europe?17:17 How complicated is CRA compliance?18:49 Does the Act reference OWASP SAMM?20:49 Why should companies care?21:44 Three perspectives on the regulation25:40 Assessing readiness team by team28:20 How the CRA treats open source30:04 Commercial activity in the supply chain34:19 How enforcement may develop36:37 Start with a maturity framework38:27 Mapping requirements with openCRE39:49 Closing thoughts

Episode metadata supplied by the publisher feed · Published Aug 20, 2025

Embed this episode

The EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe. Application Security Architect and OWASP SAMM core team member Nariman Aga-Tagiyev explains what manufacturers need to know about product classes, conformity assessments, vulnerability handling, software components, and enforcement. He and the hosts explore why global software companies should care, how the rules apply to commercial uses of open ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Getting Ready for the EU CRA

0:00 40:46

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 40 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 20, 2025.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!