ONEKEY invites you to their event

PSIRT – Start Small, but Start | CRA Implications on Notification Obligations

About this event

The Cyber Resilience Act (CRA) is entering its next critical phase: from 11 September 2026, the CRA’s mandatory reporting obligations for actively exploited vulnerabilities and severe security incidents will apply.

With the reporting deadline approaching, organizations need more than an understanding of what and when to report. They need clear structures and processes to identify, assess, escalate, document, and communicate relevant vulnerabilities and incidents within the required timelines.

This is where a Product Security Incident Response Team (PSIRT) becomes essential.

A PSIRT provides the organizational framework for managing product security vulnerabilities and incidents — from initial assessment and remediation to communication and, where necessary, regulatory notification.

But organizations don’t need a fully mature PSIRT from day one. Start small — but start.

In this 45-minute webinar, taking place just two weeks before the CRA reporting obligations become applicable, we explain how PSIRTs are structured, which responsibilities they typically assume, and how vulnerability handling, PSIRT processes, and CRA notification obligations interact. We will also introduce the PSIRT maturity levels according to FIRST and show how organizations can systematically develop their capabilities over time.

You will learn:

  • What a Product Security Incident Response Team (PSIRT) is and why organizations need one
  • How vulnerability handling, PSIRT processes, and CRA notification obligations interact
  • What can trigger a notification obligation under the CRA
  • Which CRA reporting timelines organizations need to consider
  • How a PSIRT can be structured within an organization
  • Which roles, responsibilities, and tasks typically belong to a PSIRT
  • How potentially reportable vulnerabilities and incidents should be assessed and verified
  • How PSIRTs support escalation, documentation, communication, and regulatory notification
  • How a PSIRT should interact with Security Management and other relevant functions during incident and vulnerability handling
  • What the PSIRT maturity levels according to FIRST look like
  • How organizations can start small and systematically mature their PSIRT capabilities
  • What benefits a structured PSIRT provides beyond regulatory compliance

Key Takeaways

After the webinar, you will have a clearer understanding of:

  • The interplay between vulnerability handling, PSIRT, and CRA notification obligations
  • How a PSIRT enables organizations to respond to CRA-relevant vulnerabilities and incidents within the required processes and timelines
  • The organizational and operational benefits of implementing a PSIRT
  • How to take the first practical steps toward establishing and maturing your own PSIRT

This webinar is designed for professionals working in product cybersecurity, PSIRT/PIRT operations, compliance, product security governance, vulnerability management, and organizational risk management who want to understand how a PSIRT supports effective vulnerability handling and CRA readiness.

With the CRA reporting obligations taking effect on 11 September 2026, now is the time to ensure that the necessary responsibilities and processes are in place. Whether your organization already has established product security processes or is only beginning to formalize them, this session provides a practical starting point.

Start small — but start.

Can’t join live? No problem — register now, and you’ll receive the on-demand recording after the webinar.

Hosted by

  • Team member
    T
    Alexander Hentschke Sales Manager @ ONEKEY GmbH

    Alexander specializes in IoT, Cybersecurity, CRA, SBOM, SaaS, and PaaS. He drives innovation and tech integration, ensuring secure and efficient environments. His expertise supports dynamic scaling and cyber resilience in digital transformation.

  • Team member
    T
    Alexander Neiken Consultant Cybersecurity @ ONEKEY

    Alexander advises companies on cybersecurity regulations and helps them to comply with these regulations. From impact analysis and risk management to tailor-made guidelines and management systems, he takes care of all aspects of GRC.

ONEKEY

We automate software security & compliance of connected products at scale.

ONEKEY is a specialist for Product Cybersecurity for IoT & OT. Using automatically generated "Digital Twins" and "Software Bill of Materials" of devices, ONEKEY analyzes firmware for security vulnerabilities & compliance violations, without source code, device, or network access.