High-level CYS conference brings together European policymakers, regulators, industry leaders and cybersecurity experts, with first-hand insights into the latest developments in harmonised European cybersecurity standards.
The Cyprus Organisation for Standardisation (CYS), with the support of the Office of the Commissioner of Communications – Digital Security Authority, successfully organised the high-level international conference “Building CRA Compliance through Horizontal Cybersecurity Standards” on Monday, 21 September 2026, at the Hilton Nicosia.
Bringing together over 300 delegates from Cyprus and around the world, both in person and online, the conference served as an international platform for policymakers, regulators, European standardisation experts, cybersecurity professionals, manufacturers and industry representatives to examine the implementation of the European Union’s Cyber Resilience Act (CRA).
Organised within the framework of the STAN4CR initiative, the conference focused on the development of harmonised European standards by CEN and CENELEC, which aim to provide manufacturers and organisations with practical pathways towards demonstrating compliance with the CRA’s cybersecurity requirements.
The event took place at a significant stage in the Regulation’s implementation. With CRA reporting obligations having entered into application on 11 September 2026 and the main requirements scheduled to apply from 11 December 2027, manufacturers face an increasingly important period of preparation and adaptation.
The conference’s opening session featured addresses by Mr. Demetris Vakis, Chairperson of CYS; Dr. Nicodemos Damianou, Deputy Minister for Research, Innovation and Digital Policy of the Republic of Cyprus; Mr. Marios Pieri, Commissioner of Communications; and Mrs.Camille Dornier, representing DG CONNECT of the European Commission.
Addressing the conference, Dr. Nicodemos Damianou, Deputy Minister for Research, Innovation and Digital Policy of the Republic of Cyprus, highlighted the significance of harmonised European standards in supporting businesses, particularly small and medium-sized enterprises, in meeting the requirements of the Cyber Resilience Act. Referring specifically to SMEs, the Deputy Minister said that “For them, a practical, accessible standard is the difference between compliance as a burden and compliance as a competitive advantage.”
Mr. Marios Pieri, Commissioner of Communications, underlined the importance of cooperation between regulatory authorities, standardisation organisations and industry in strengthening Europe’s digital resilience. Mr. Pieri said that “The Cyber Resilience Act represents an important step towards strengthening cybersecurity across the European Union. Its successful implementation requires coordinated action between regulators, standardisation bodies and industry, as well as a commitment to integrating cybersecurity into digital products throughout their lifecycle. By bringing together European and national expertise, this conference contributes to a better understanding of the new regulatory framework and supports the preparations necessary to strengthen the security and resilience of our digital ecosystem.”
One of the conference’s central highlights was the keynote presentation by Mr. Angelo D’Amato, Founder of Vulnir and Rapporteur of CEN/CENELEC Joint Technical Committee 13, Working Group 9 (WG9), who provided an in-depth update on two key draft horizontal cybersecurity standards supporting implementation of the CRA: prEN 40000-1-3, addressing vulnerability handling, and prEN 40000-1-4, covering generic security requirements.
His presentation offered participants first-hand insights into the progress of these standards, their practical application and the remaining work required before their finalisation.
Regarding vulnerability handling, Mr D’Amato explained how the draft standard establishes a structured, risk-based approach to maintaining the cybersecurity of products with digital elements throughout their support period. The framework encompasses six distinct phases – preparation, receipt, verification, remediation, release and post-release – and 22 associated activities designed to help manufacturers identify, assess, address and monitor vulnerabilities systematically.
His presentation also covered important developments concerning Software Bills of Materials (SBOMs), coordinated vulnerability disclosure involving multiple parties, and requirements for regular security testing and reviews.
Turning to generic security requirements, Mr. D’Amato outlined how the draft standard translates the CRA’s essential cybersecurity requirements into a structured framework linking identified threats, security objectives and technical security controls. The framework incorporates 18 families of technical controls, addressing areas including access control, authentication, secure updates, cryptography, data protection, monitoring and resilience.
Mr. D’Amato said that “The development of horizontal cybersecurity standards is essential to translating the Cyber Resilience Act’s requirements into practical, measurable approaches that manufacturers can implement. We are making important progress, particularly with the vulnerability-handling standard, which is approaching its final stages. Our work focuses on ensuring that manufacturers have clear requirements and assessment criteria to support effective vulnerability management throughout a product’s lifecycle. The objective is to develop standards that are technically robust, risk-based and practical to implement, while providing a consistent approach to cybersecurity across the European market.”
Mr. D’Amato’s keynote also provided an update on the progress of the standards, noting that the vulnerability-handling draft was approaching its final stages, with outstanding comments being addressed, while the generic security requirements draft remained under European Commission assessment.
The presentation established an important connection with the CEN/CENELEC JTC 13 WG9 meeting taking place in Ayia Napa, Cyprus, from 22 to 25 September 2026, where European experts will continue their work on resolving outstanding comments and advancing the standards.
The conference continued with presentations and discussions addressing the European standardisation roadmap, cybersecurity principles, product risk management, lifecycle activities and the practical challenges associated with implementing the CRA.
Representatives from European standardisation organisations and industry provided insights into the work underway to develop harmonised standards, including their role in supporting manufacturers and facilitating compliance across the EU Single Market.
The programme also featured practical industry case studies, including contributions from Amazon Web Services and Cyprus-based Columbia Ship Management and Clone Systems, examining the implications of CRA requirements from the perspectives of manufacturers and businesses.
Two dedicated panel discussions, “Dialogue with the Stakeholders” and “Ask the National Authority”, provided opportunities for engagement between European experts, industry representatives and regulatory authorities from Cyprus, Sweden, Finland and Germany.
The conference highlighted the importance of international cooperation in translating European regulatory requirements into practical, consistent and effective approaches to cybersecurity. For Cyprus, hosting this international gathering provided an opportunity to bring leading European expertise directly to local businesses, manufacturers and other stakeholders, while strengthening dialogue on the implementation of the CRA.
Commenting on the significance of the conference, Mrs. Athina Panagiotou, Director General of the Cyprus Organisation for Standardisation (CYS), said that “The participation of over 300 delegates from around the world demonstrates the importance of the Cyber Resilience Act and the strong interest in the European standards that will support its implementation. For CYS, this conference represents an important opportunity to bring together the European standardisation community, regulatory authorities and industry, fostering dialogue and providing practical knowledge to organisations preparing for the new regulatory framework.
Our objective is to ensure that Cypriot businesses have access to the expertise, information and European standards they need to prepare effectively, strengthen their cybersecurity capabilities and remain competitive in an increasingly digital European market. We are particularly pleased that Cyprus has served as a meeting point for this important international exchange of knowledge and expertise.”
The conference’s international significance is further reinforced by the meeting of CEN/CENELEC JTC 13 Working Group 9, taking place in Ayia Napa from 22 to 25 September 2026, bringing together the experts responsible for advancing the development of horizontal cybersecurity standards supporting the CRA.
The Cyprus Organisation for Standardisation expressed its appreciation to the Office of the Commissioner of Communications – Digital Security Authority, European standardisation organisations, distinguished speakers, industry representatives and all delegates for their valuable contributions to the success of the conference.
Through initiatives of this nature, CYS continues to support the development and adoption of European standards, promote the participation of Cypriot stakeholders in European standardisation and contribute to the development of a more secure and resilient digital Europe.



