image-hero

From Threat Modeling to Secure Silicon — How to Meet EU CRA Requirements Before the Clock Runs Out

Register or log in to watch the webinar.

The EU Cyber Resilience Act is no longer a future obligation, it is an active compliance program with hard deadlines. From 11 September 2026, manufacturers must report actively exploited vulnerabilities. Full conformity follows on 11 December 2027. This session is the practitioner chapter of Infineon's CRA webinar series. Building directly on "Get Ready for EU Cyber Resilience Act with Infineon," "Navigating the EU CRA," and "Understanding EN 50764 — The CRA Harmonized Standard for Smartcards and Secure Elements," this webinar moves from awareness to implementation, from knowing what the regulation requires to building a defensible compliance program on a real product.

Hosted by Infineon, together with our partner Brightsight,  security practitioners with deep hands-on experience across product security, standards and regulatory affairs, this session delivers what engineering teams need most right now: a live threat modeling masterclass, an insider view of what harmonized standards actually demand, and a concrete 30-60-90 day action plan. Whether you are designing connected industrial systems, EV charging infrastructure, or smart devices, you will leave with the method, the clarity, and the plan to act immediately.

WHAT YOU WILL LEARN

  1. CRA scope and classification: Determine your product's risk class and the correct conformity path with confidence
  2. Threat modeling that satisfies CRA Annex I: Apply a structured risk assessment method and produce requirements traceability that drives design decisions
  3. Security-by-default: Implement the non-negotiable minimum secure configuration requirements before your product ships
  4. The compliance boundary: Know exactly which Annex I obligations certified silicon addresses and which remain yours regardless of your silicon choice
  5. A 30-60-90 day action plan: Leave with a sequenced, specific sprint plan to launch a defensible CRA compliance program starting Monday morning
Preeti Ohri Khemani

Senior Director Partnership and Ecosystem Management

With over 30 years of leadership experience and 20 years in leading programs and teams delivering security semiconductor solutions, Preeti has expertise in developing, integrating and certifying security solutions for smart card and mobile payment, consumer and industrial IoT, wearables, identity and blockchain applications.

She holds a graduate degree in Electronics and Telecommunication Engineering, and is an active member of several key advisory and standards boards, including Austrian Standards International, Eurosmart, NFC Forum, and FIDO Alliance.

 

 

Erik Wood

Senior Director of IoT Product Security

Erik has extensive experience in wireless sensor networks, cryptographic security, and secure memory technologies. He chairs Infineon’s IOT Security Center of Excellence that drives the IoT security strategy, defines new-product security requirements, and oversees the Edge Protect brand.

Erik has chaired both the US delegation to the ISO RFID security committee and the NFC Forum security committee. He holds a bachelor’s degree in electrical engineering from UCLA and a corporate MBA from Santa Clara University.

 

 

Erik Wood
Erik Wood

Director of Strategic Developments at Brightsight

Xavi currently serves as Director of Strategic Developments at Brightsight, where he is responsible for defining and implementing the company’s strategy for compliance with the Cyber Resilience Act, with a strong focus on harmonisation, IoT security, and regulatory alignment.

With nearly 20 years of experience in embedded security, he has worked as both a security evaluator and a consultant. This professional background has given him a well‑balanced understanding of the technical challenges faced by product developers, as well as the business constraints related to certification processes and market access. This dual perspective has shaped his long‑term involvement in security assurance, certification, and standardisation activities.

Xavi represents Brightsight in SESIP and PSA working groups within GlobalPlatform and actively participates in discussions of the JHAS. He is also involved in European standardisation, contributing to ETSI and CEN/CENELEC groups, including TC 47X WG2.

 

 

Engineering CRA-Ready Products by Design
Get the engineering playbook for CRA compliance: classification, threat modeling, security by default, and a 30-60-90 day plan.
September 17, 2026 - September 17, 2026
17:00 - 18:00 ( CET )
Documents