[Webinaire] Mise en conformité aux réglementations cyber

[Webinaire] Mise en conformité aux réglementations cyber

🎙 Mikael Carmona, Thomas Loubier, Christophe Villemazet 👥 335 📅 September 10, 2025 ⏱ 41 min 👁 92 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

CRAcybersecurityembedded systemsside-channel attackssecure boot

Summary

This webinar, hosted by IRT Nanoelec, addresses the challenges and solutions for achieving compliance with new European cybersecurity regulations, particularly the Cyber Resilience Act (CRA). Mikael Carmona introduces the Hardware Security laboratory at CEA-Leti, highlighting its three innovation vectors: new threats (quantum computing, AI), new regulations (CRA, etc.), and technological innovations (embedded AI, RISC-V). Thomas Loubier then provides a detailed overview of the CRA, including its objectives, scope, exclusions, and timeline. He explains the obligations for manufacturers and the role of standardization bodies. He also presents the LTSO lab’s activities in security testing, including platforms like SIDE, FuzEngine, and SecBench, which are used for vulnerability assessment and side-channel analysis. Christophe Villemazet focuses on the blue team perspective, discussing security by design for IoT and edge devices. He introduces reference designs (SEC-IoT and SEW) that incorporate secure boot, secure update, and cryptographic key management. The webinar concludes with a Q&A session, emphasizing the importance of preparing for the CRA and leveraging CEA-Leti’s expertise.

162 words

Critical Evaluation

Value of the Information & Strength of the Argument

The webinar provides valuable insights into the CRA and its implications for manufacturers of digital products. The presenters effectively argue that proactive security measures are essential, and they demonstrate their expertise through concrete examples of tools and methodologies. The argumentation is solid, based on their extensive experience in hardware security and testing. However, the presentation also serves as a promotional platform for CEA-Leti’s services, which may introduce a bias in the evaluation of their solutions.

84 words

Title / Content Match

The title accurately reflects the content, which focuses on compliance with cyber regulations, particularly the CRA.

Quality & Reliability

8/10

The webinar is presented by experts from CEA-Leti, a renowned research institute, and covers the Cyber Resilience Act (CRA) and associated security practices. The content is well-structured, technical, and based on the presenters' direct experience. However, it is primarily an expert opinion and promotional presentation of their services, with limited external sources cited.

Key Moments

Cited Sources

  • Cyber Resilience Act (CRA) — Mentioned as the main regulation discussed in the webinar.
  • SecBench — Open-source platform for hardware security testing, mentioned by Thomas Loubier.

Concurring Sources

Contribution & Novelties

The webinar provides a comprehensive overview of the CRA and its practical implications for manufacturers, along with concrete tools and methodologies developed by CEA-Leti for security testing and secure design. It bridges the gap between regulatory requirements and technical implementation, offering actionable insights for the industry.

Pour aller plus loin :

  • Cyber Resilience Act — Official EU page with the regulation text and updates.
  • Side-channel attack — Wikipedia article explaining the concept of side-channel attacks, relevant to the security testing discussed.
  • Post-quantum cryptography — Wikipedia article on cryptographic algorithms designed to resist quantum attacks, a key topic in the webinar.

100 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, technical level, and global reliability, indicating a well-rounded and informative presentation. The slightly lower score in technical level suggests that while the content is technical, it is accessible to a broader audience.

Reliability 8/10