The EU’s Digital Decade strategy is driving a significant transformation of the cybersecurity regulatory landscape. New requirements under the Cyber Resilience Act (CRA), together with developments under the NIS2 and Critical Entities Resilience (CER) Directives, are creating new compliance, governance and operational resilience obligations for organisations across sectors.
Join DLA Piper’s Data, Privacy and Cybersecurity team for a practical discussion of the latest regulatory developments and the steps organisations should be taking to prepare. The session will focus on the CRA’s far-reaching requirements for products with digital elements, alongside key updates on NIS2 implementation and the evolving CER framework.
In this session, we will:
- Examine the interplay of the CRA, NIS2 and CER regimes.
- Explore the CRA, including key implementation deadlines, why it represents a fundamental shift in EU cybersecurity regulation, and its impact across the product lifecycle.
- Examine the CRA’s scope, jurisdictional reach, entities in scope, and the key compliance and reporting obligations organisations need to prepare for.
- Discuss practical steps for CRA readiness, including governance, vulnerability management and incident reporting requirements.
- Review recent NIS2 developments relating to main establishment, management bodies and group structures, and provide an update on the scope and implementation status of the CER Directive.
John Magee, Nicholas De Lacy-Brown, Lorcan Moylan Burke, Irina Macovei