Three days before the deadline
On 8 September we are at DIGITAL X in Cologne, all three founders. Three days later the first binding obligation of the Cyber Resilience Act takes effect. And anyone who sat at our table in July would have seen a different product.
In just over a week, on 8 September, we are at DIGITAL X in Cologne's Rheinauhafen, on Deutsche Telekom's partner floor. All three founders, each with one perspective: information security, data protection, IT management.
The calendar has built in a punchline. Three days after the fair, on 11 September, the reporting obligation of the Cyber Resilience Act takes effect. 24 hours from awareness for the early warning, simultaneously to the responsible CSIRT and to ENISA. And it applies to products that have long been in the field.
Anyone placing products with digital elements on the market therefore carries a very concrete question to 8 September, whether they want to or not.
The state of things differs from July
We announced the date at the end of July. Since then a fair amount has arrived that can actually be shown at a trade fair table.
A module for cloud misconfigurations that checks Entra ID, Azure, AWS, Google Cloud and OTC natively and covers everything else via an import. Read-only throughout, without automatic remediation.
The context for what is currently happening at the BSI: the WiBA checklists become a fixture of the Grundschutz successor, and the requirements catalogue becomes machine-readable. Anyone starting with the checklists today is not working into a dead end.
On the data centre side, measurements for power, cooling and environment, along with the question of whether cooling still holds when the largest unit fails.
Since this text was first drafted, more has arrived: success verification for rollouts that checks actual state against existing connectors rather than trusting the distribution tool, a standards cockpit whose chapter status follows the worst child instead of averaging, and the convergence of virtual machines from hypervisor, network and software scans into a single asset.
And a training player that meets WCAG 2.2 at level AA and is fully keyboard-operable. For mandatory instruction that is not a nice-to-have.
What we would like from a conversation
Product demos exist at every fair, and they are rarely what someone remembers afterwards. It gets more useful when you arrive with a task that is currently stuck.
The actual reason for three people at one table is a mundane one: a compliance tool lands on three different desks every day, and those three judge the same tool by entirely different standards. That is exactly where selection processes fail. You can probe all three perspectives in one conversation instead of needing three appointments.
If you want to be sure to meet us, arrange the appointment in advance via the contact page. 8 September will be busy.
All key dates for the coming months are in the compliance calendar.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.