BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//talks.osfc.io//osfc-2026//speaker//Z79TDX
BEGIN:VTIMEZONE
TZID:Europe/Berlin
BEGIN:DAYLIGHT
DTSTART:20250917T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:[Open Mic] Open Source Firmware and the Cyber Resilience Act (CRA)
  - fukami
DTSTART;TZID=Europe/Berlin:20260917T142500
DTEND;TZID=Europe/Berlin:20260917T144500
DTSTAMP:20260924T222509Z
UID:pretalx-osfc-2026-VU7WBN@talks.osfc.io
DESCRIPTION:The Cyber Resilience Act (CRA) is EU product legislation that 
 lists categories of important and critical products. Standards for these c
 ategories are being developed by ETSI and CEN-CENELEC. _Boot managers_ are
  one of them (Annex III\, Class I): a manufacturer who applies the harmoni
 sed standard can self-assess conformity\, otherwise a notified body has to
  be involved.\n\nReporting obligations have applied since 11 September 202
 6 and the product standards are entering their final stage. As rapporteur 
 of [ETSI EN 304 623](https://portal.etsi.org/webapp/workprogram/Report_Wor
 kItem.asp?WKI_ID=74414)\, I give an overview of where things stand and whi
 ch issues remain open\, including what counts as a boot manager in this co
 ntext in the first place.\n\nFirmware is often built from open-source comp
 onents that were never placed on the market on their own. The talk closes 
 with an idea for how device manufacturers and integrators can meet their d
 ue diligence obligation for such components ([CRA Art. 13(5)](https://eur-
 lex.europa.eu/eli/reg/2024/2847/oj/eng#art_13)).
LOCATION:Main Room // Grote Zaal
URL:https://talks.osfc.io/osfc-2026/talk/VU7WBN/
END:VEVENT
END:VCALENDAR
