The Cyprus Organisation for Standardisation (CYS), with the support of the Office of the Commissioner of Communications – Digital Security Authority, successfully hosted the high-level conference “Building CRA Compliance through Horizontal Cybersecurity Standards” on 21 September 2026 in Nicosia, bringing together leading experts from across Europe to discuss the implementation of the European Union’s Cyber Resilience Act (CRA).

The conference was organised within the framework of the STAN4CR initiative, funded by EISMEA, and contributed to its mission by promoting knowledge exchange, supporting the implementation of the CRA and advancing the development and uptake of harmonised European standards.

The event provided a unique platform for policymakers, regulators, industry representatives, cybersecurity professionals and standardisation experts to exchange views on the evolving cybersecurity regulatory landscape and the European standards being developed to support compliance with the CRA.

The conference was honoured by the presence of the Deputy Minister of Research, Innovation and Digital Policy, Mr Nicodemos Damianou, who welcomed the participants together with the Chairperson of CYS, Mr Demetris Vakis, the Commissioner of Communications – Digital Security Authority, Mr Marios Pieri, and Ms Camille Dornier of the European Commission’s Directorate-General for Communications Networks, Content and Technology (DG CONNECT). Their addresses set the context for the day’s discussions on European cooperation, the effective implementation of the Cyber Resilience Act, and the role of standards in strengthening cybersecurity and market trust. The conference brought together internationally recognised experts directly involved in the development of the new European cybersecurity standards, who set out the current state of the drafts and engaged directly with questions from participants throughout the day

Among the distinguished speakers was Diamandis Zafeiriadis, Head of the Digital Security Authority of Cyprus, who presented Cyprus’ digital security policy and legislative landscape and highlighted the importance of cooperation between authorities, industry, standardisation bodies and conformity assessment organisations in building cyber resilience.

Representing the European standardisation community, Yves Leboucher, Sectoral Project Manager at CEN and CENELEC, provided an overview of the extensive standardisation programme supporting the Cyber Resilience Act, explaining how European standards translate regulatory requirements into practical implementation mechanisms for manufacturers and stakeholders across Europe.

The conference also featured presentations from leading contributors to the development of the future harmonised standards under the CRA. Ben Kokx, Convenor of CEN/CLC/JTC 13 Working Groups 6, 8 and 9 and Director Standardization Product Security at Philips, shared insights into the development of the horizontal standards and reflected on the role of risk-based approaches, product lifecycle management and vulnerability handling in achieving cybersecurity compliance.

Wendy Tonks, Cybersecurity Specialist and Lead System Test Engineer at OMRON Europe, presented the latest developments of the upcoming prEN 40000-1-2 standard, focusing on cybersecurity principles, product risk management and lifecycle activities that will support manufacturers in meeting CRA requirements.

Further technical insights were provided by Angelo D’Amato, Rapporteur of CEN/CLC/JTC 13 Working Group 9, who outlined progress in the development of draft standards on vulnerability handling and generic security requirements, explaining how these standards will help translate the legal obligations of the CRA into measurable technical and organisational controls.

The practical implementation perspective was strengthened by Jesus Luna Garcia, Security Assurance Manager at Amazon Web Services, who discussed the role of cloud services, responsibility models and cybersecurity assurance mechanisms in supporting CRA compliance. His presentation explored lessons learned from ENISA pilot activities and emerging approaches for assessing cloud-hosted cybersecurity services within the CRA ecosystem.

Participants also had the opportunity to hear practical case studies from Cyprus-based organisations. Through the CYBERFORT project, representatives from Columbia Ship Management, Marios Ioannou, and Clone Systems, Nicos Kekatos, demonstrated how organisations can transform CRA obligations into practical compliance workflows, covering areas such as risk management, vulnerability assessment, software bill of materials, cybersecurity governance and technical documentation.

The afternoon programme featured two panel discussions that brought together industry, legal, conformity assessment and public authority perspectives. The “Dialogue with the Stakeholders” panel explored practical challenges and expectations surrounding CRA implementation, while the “Ask the National Authority” panel enabled direct exchange with national cybersecurity and market surveillance authorities from Cyprus, Sweden, Finland and Germany. Together with the dedicated question-and-answer sessions, the panels gave participants the opportunity to raise implementation concerns, compare national perspectives and engage directly with the experts and authorities supporting the CRA framework.

The “Dialogue with the Stakeholders” panel brought together Ben Kokx (Philips), Jesus Luna Garcia (Amazon Web Services), Nuria Carrió Misas (APPLUS+ LABORATORIES), and the Cypriot National representatives in the European Technical Committee Maria Raphael (Raphael Legal and Privacy Minders) and Constantinos Tsiourtos (KINEAS Consulting). The “Ask the National Authority” panel featured Xenia Kyriakidou (Digital Security Authority of Cyprus), James Christie (Post and Telecom Authority, Sweden), Päivi Timlin (National Cyber Security Centre Finland / Traficom) and Michael Schuster (Federal Office for Information Security – BSI, Germany), providing participants with direct insight from both industry and national authorities on the practical implementation of the CRA.

A recurring theme throughout the conference was that compliance with the Cyber Resilience Act extends far beyond technical controls. Speakers emphasised that cybersecurity must be addressed throughout the entire product lifecycle, supported by structured risk management processes, vulnerability handling procedures, secure development practices and comprehensive documentation. European standards are expected to play a central role in enabling organisations to demonstrate compliance and conformity consistently and effectively.

The conference also served as a timely precursor to the meeting of CEN/CLC/JTC 13/WG 9, the European working group responsible for developing the CRA horizontal standards, which is being hosted in Cyprus immediately following the event. This further reinforces Cyprus’ growing role in European cybersecurity standardisation and provides a valuable opportunity for engagement between local stakeholders and the experts shaping the future cybersecurity framework of the European Union.

Through initiatives such as this conference, CYS continues to support the active participation of Cyprus in European and international standardisation activities, while helping organisations prepare for emerging regulatory requirements and strengthen their cybersecurity capabilities.