CRA-ready IoT products will require security to be treated as part of product engineering rather than a final compliance exercise. With the first Cyber Resilience Act deadlines arriving in September 2026, connected-device teams need development processes that can produce security evidence, track vulnerabilities, and support products after release. On Thursday, September 10, 2026, Elektor and Lemberg Solutions will present a free webinar explaining how that work can be built into an existing software development lifecycle.

REGISTER HERE


What CRA-Ready IoT Products Require

The webinar, Building CRA-Ready IoT Products: The Practical Side of Compliance, begins at 16:00 CEST (14:00 UTC / 10:00 EDT). Speaker Nazar Kohut, Program Manager at Lemberg Solutions, will examine how the EU Cyber Resilience Act changes the way embedded and IoT products are planned, developed, released, and maintained.

The European Commission says the CRA introduces mandatory cybersecurity requirements covering product planning, design, development, and maintenance. Reporting obligations apply from September 11, 2026, while the main requirements apply from December 11, 2027. That makes the timing rather less comfortable than a quick glance at “2027” might suggest.

From Regulation to Engineering Workflow

The session will focus on what a CRA-compliant secure SDLC looks like in practice. Topics include risk assessment, threat modeling, development phases and gates, required documentation, release preparation, vulnerability handling, and post-release activities. The aim is to show where compliance work belongs in the development process, rather than treating it as a separate pile of paperwork assembled after the product is finished.

This matters particularly for small and midsize embedded teams. A connected product may combine firmware, an operating system, third-party libraries, cloud services, mobile applications, and update infrastructure. CRA readiness therefore depends on knowing what is inside the product, who is responsible for each part, how security decisions are recorded, and how vulnerabilities will be handled throughout the support period.

For engineers, the practical questions are familiar even when the regulation is not: How are security requirements translated into design decisions? Where should reviews and approval gates occur? What evidence must be retained? How should software components and dependencies be tracked? And what happens when a vulnerability appears after thousands of devices have already been deployed?

Meet Nazar Kohut

Nazar Kohut manages embedded and IoT projects in regulated fields including automotive, energy, and medical technology. His work includes establishing and maintaining software and hardware development lifecycle processes, with an emphasis on predictable delivery, regulatory requirements, and product security.

Kohut’s online session will give product managers, firmware developers, system architects, QA engineers, and technical decision-makers an opportunity to examine the approach and put questions directly to the speaker.

Register for the Free Webinar

The live webinar takes place on Thursday, September 10, 2026, at 16:00 CEST (14:00 UTC / 10:00 EDT). Attendance is free, but registration is required. Engineers working on connected products should find it useful whether their organization is beginning its CRA planning or trying to turn an existing security program into a defensible product-development process.
 

REGISTER HERE