The EUs Cybersecurity Resilience Act (CRA) has Begun – How Can Manufacturers Confidently Addres ... @FIRSTdotorg
The EUs Cybersecurity Resilience Act (CRA) has Begun – How Can Manufacturers Confidently Addres ...  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 2 hours ago
The EU's Cybersecurity Resilience Act (CRA) has Begun – How Can Manufacturers Confidently Address their Obligations and Security Requirements?

Mars Cheng (TXOne Networks Inc., TW)

The EU’s Cybersecurity Resilience Act (CRA) is a landmark regulation targeting the cybersecurity of products with digital elements within the EU market. While full mandatory enforcement is set for December 2027, manufacturers must comply with critical reporting obligations starting in September 2026. With harmonized standards and third‑party verification bodies (Notified Bodies) still pending clarity, how can manufacturers move from a reactive, rushed state to a proactive, composed compliance strategy?

This presentation will focus on the manufacturer’s reporting obligations and the cybersecurity requirements for “Important Products.” We will share our Product Security Incident Response Team (PSIRT)’s practical approach to planning and evaluating the future compliance roadmap.

---

Mars Cheng (@marscheng_) is the Head of Cyber Threat & Product Defense Center at TXOne Networks Inc., responsible for leading the three subgroups under the center, including PSIRT, Advanced Threat Research Group, and Threat Operation Group. He also serves as the Executive Director of the Association of Hackers in Taiwan (HIT/HITCON), a Review Board Member for both HITCON Conference and Training, FIRSTCON26, the General Coordinator of HITCON CISO Summit 2026, and a Cybersecurity Auditor for the Taiwan Government. In these roles, he plays a pivotal part in fostering collaboration between industry and government to strengthen national cybersecurity resilience.

Mars specializes in IoT, ICS/SCADA systems, malware analysis, threat intelligence and hunting, blue team, and enterprise security. A seasoned speaker, Mars has delivered over 60 presentationst at international cybersecurity conferences, including Black Hat USA, Europe, and MEA, RSA Conference, DEF CON, CODE BLUE, FIRST, HITB, HITCON, Troopers, NOHAT, SecTor, S4, SINCON, ROOTCON, among others. He is also an experienced cybersecurity instructor, having delivered over 35 training sessions at events such as Global Cybersecurity Camp (GCC) 2026, 2024, HITCON Training (2025, 2022, 2021, 2020, 2019), NICS Elite Practical Training Taiwan (2025–2022), and for various ministries in Taiwan, including National Defense, Economic Affairs, Education, and Finance, as well as for publicly listed companies.

He has successfully organized several notable HITCON events, such as the HITCON CISO Summit in 2025, 2024 and 2023, HITCON PEACE 2022, and HITCON 2021 and 2020.
The EUs Cybersecurity Resilience Act (CRA) has Begun – How Can Manufacturers Confidently Addres ...Chaos Stack: Designing Layered Tabletop Exercises for Complex Crisis Simulation99 Bottles of Trust on the Wall: Approaches to Building Convivial CommunitiesEverything Everywhere All at Once…in 2038Understanding Scammer Threats: Detection Strategies Aligned with Thailand’s Cybersecurity Act 2562CTI-Transmute: Harmonizing Threat Intelligence in a Multi-Standard EcosystemAccuracy Is Not Enough: Detecting Hidden Risk in CVE Impact PredictionIntroducing StealerLens: An LLM-Powered Forensics Microscope to Accelerate InfoStealer ...Itinerary to Defeat Yet Another Beacon ImplementationCVE Record Format - Purl and CPE WorkshopBeyond CVEs: Mastering the Landscape with Vulnerability-LookupFrom JSON to Clarity: Practical Tools for SBOM Interpretation
FIRST |

The EU's Cybersecurity Resilience Act (CRA) has Begun – How Can Manufacturers Confidently Addres ...

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER