Skip to content
Artwork for Ode to Resilience

Ode to Resilience

Piet De Vaere & August Bournique

Ode to Resilience is a podcast about the EU Cyber Resilience Act, hosted by engineer Piet De Vaere and technology lawyer August Bournique. Both are closely involved in the CRA implementation work, and together they cut through the complexity of one of the most ambitious technology regulations ever passed. If you want to hear about the CRA straight from Brussels, this is the podcast for you!

Play
  • 5 episodes
  • fortnightly
  • Avg 53 min
  • English
  • #5
    Friday · 46 min

    E5 - Reporting obligations (Article 14)

    Piet and August discuss the reporting obligations in CRA article 14 that will enter into effect on the 11th of September. What are they? How serious are they? And is everyone ready? Find out in this exciting new episode! Ode to Resilience is hosted by Piet De Vaere: Electrical Engineer, CRA consultant & Member of the CRA Expert Group (Linkedin | Webpage) and August Bournique: Silicon Valley technology lawyer, CRA consultant & Special Rapporteur for ETSI CRA standards (Linkedin | Webpage) You can reach out to us on: podcast@productsecurity.ch

  • #4
    August 21 · 1 hr 13 min

    E4 - Remote Data Processing Solutions (RDPS)

    Piet and August take on RDPS, one of the CRA's most contested concept, pulling apart its definition almost word by word: what counts as a "function" of a product? What does "designed and developed by or on behalf of the manufacturer" mean exactly? And what exactly is "at a distance"? And does all of this really mater anyway? Ode to Resilience is hosted by Piet De Vaere: Electrical Engineer, CRA consultant & Member of the CRA Expert Group (Linkedin | Webpage) and August Bournique: Silicon Valley technology lawyer, CRA consultant & Special Rapporteur for ETSI CRA standards (Linkedin | Webpage) You can reach out to us on: podcast@productsecurity.ch

  • #3
    August 7 · 46 min

    E3 - What is the minimal CRA product?

    Piet and August welcome their first guest, Götz Martinek, who brings a question he deals with regularly: what's the minimal product with digital elements, and does it really need the full CRA compliance treatment? They test the CRA's scope definitions against two real objects, a calculator with no data interface and a washing machine with a technician-only diagnostic port. From there they explore how risk assessments and compliance paperwork can scale down for genuinely low-risk products without disappearing entirely. The episode closes with a look at the baseline obligations, like documentation retention and a single point of contact, that apply no matter how trivial the product is. Ode to Resilience is hosted by Piet De Vaere: Electrical Engineer, CRA consultant & Member of the CRA Expert Group (Linkedin | Webpage) and August Bournique: Silicon Valley technology lawyer, CRA consultant & Special Rapporteur for ETSI CRA standards (Linkedin | Webpage) You can reach out to us on: podcast@productsecurity.ch

  • #2
    July 24 · 50 min

    E2 - Supply Chain and the CRA

    Piet and August dig into supply chain security as a hidden third goal of the EU Cyber Resilience Act. They break down the CRA's upstream and downstream obligations for manufacturers, tackle the tricky question of how to handle open source and first-party components, and explore the difference between proactive due diligence and reactive vulnerability monitoring. The episode closes with a thought-provoking finding: the CRA may allow authorities to deem a product non-compliant based on where it was made and who made it, raising questions about digital sovereignty that go far beyond technical security. Ode to Resilience is hosted by Piet De Vaere: Electrical Engineer, CRA consultant & Member of the CRA Expert Group (Linkedin | Webpage) and August Bournique: Silicon Valley technology lawyer, CRA consultant & Special Rapporteur for ETSI CRA standards (Linkedin | Webpage) You can reach out to us on: podcast@productsecurity.ch

  • #1
    July 10 · 51 min

    E1 - What is the CRA?

    In the debut episode of Ode to Resilience, Piet and August introduce themselves and lay the groundwork for the podcast by answering the most basic question: what is the EU Cyber Resilience Act? They break down what "products with digital elements" actually covers (spoiler: nearly everything digital), walk through the four main pillars of CRA requirements, from product security and secure development processes to long-term support obligations and vulnerability reporting, and demystify the compliance timeline. The episode closes with a grounded take on enforcement and the famously large fines, reassuring listeners that the CRA, while ambitious, is fundamentally reasonable and manageable for manufacturers willing to take cybersecurity seriously. Ode to Resilience is hosted by Piet De Vaere: Electrical Engineer, CRA consultant & Member of the CRA Expert Group (Linkedin | Webpage) and August Bournique: Silicon Valley technology lawyer, CRA consultant & Special Rapporteur for ETSI CRA standards (Linkedin | Webpage) You can reach out to us on: podcast@productsecurity.ch

Showing 1–5 of 5 episodes