How can organisations prepare for the Cyber Resilience Act (CRA) and the requirements introduced by the NIS2 Directive for both designated entities and their suppliers? Find out on 16 October 2026 at Algebra Bernays University in Zagreb, at a conference held as part of the IQ Defence project.
The conference will bring together representatives of European and Croatian institutions, standardisation and cybersecurity experts, as well as companies already dealing with these new regulatory requirements in practice.
The focus will be on NIS2 implementation, the new requirements introduced by the CRA, supply chain security, harmonised standards, supplier accountability, and the practical challenges of implementing new rules within business environments.
If you work in cybersecurity, IT, product development, regulatory compliance, risk management, or collaborate with suppliers of digital products and services, this is where regulation meets practice.
Be prepared for the new era of cybersecurity requirements.
Fundamentals of the CRA, comparison with NIS2, ISO/IEC 27001 and DORA, differences, overlaps and implementation timeline.
The overview will cover risk assessment, secure development, vulnerability handling, updates, technical documentation, conformity assessment and CE marking.
Practical framework in action: CRA scope → product boundary → product category → conformity assessment route → first compliance actions.
This will explain how a product’s core functionality determines its category and what this means for self-assessment, harmonised standards and third-party assessment.
The presentation will focus on the obligations stemming from the CRA with regard to notification by manufacturers and open source software stewards about serious incidents and actively exploited vulnerabilities. It will be followed by a live demonstration of the functioning of the Single Reporting Platform, set up by ENISA in this context and made operational on 11 September.
Guidance to the layered approach of standardisation covering the Cyber Resilience Act (CRA) (Regulation (EU) 2024/2847), from prEN 4000-1-x series horizontal (common, product-independent framework) standards to EN 304 6xx vertical (product-specific) standards and their applicability. How to tackle normative parts and how to help yourself with informative parts. Dos, don’ts and gotchas included.
This presentation provides a practical overview of planning and conducting cybersecurity and resilience audits of critical ICT supply chains, in line with regulatory requirements and guidelines as the primary benchmark, while also highlighting the most common findings identified during such audits.
The focus is on identifying critical suppliers and business dependencies, defining the scope and audit approach, and assessing the need to amend contracts with additional security clauses. Particular emphasis is placed on supplier access management, vulnerability management, incident handling, and business continuity.
The presentation will also explore how identified findings can be addressed through risk assessments and action plans, how to understand management’s responsibility in defining the organisation’s acceptable level of risk, and the potential consequences of different decisions related to security and resilience management obligations within the critical ICT supply chain.
A company’s security increasingly depends on technology suppliers, external service providers and partners with access to its systems and data. How do Croatian companies identify critical suppliers, assess their risks and put security requirements into practice?
Representatives from banking, communications infrastructure, energy and food manufacturing, alongside a business partner assessment perspective, will share their experiences of supplier due diligence, access management and incident response. The discussion will also explore decisions companies face when a supplier is difficult to replace or falls short of security expectations, offering practical recommendations for a more resilient supply chain.
How can companies turn the requirements of the Cyber Resilience Act (CRA) into a practical action plan? This panel brings together perspectives from IT management, product development, conformity assessment, regulatory affairs and security solution providers.
The panellists will discuss defining product scope, assigning responsibilities, integrating security into development, and managing vulnerabilities and support throughout the product lifecycle. Particular attention will be given to documentation and security evidence, supplier cooperation, and the roles of manufacturers and importers. The audience will gain practical recommendations on where to start and how to integrate CRA preparation into existing business and development processes.
Michael Jesse is the founder of NexTech.Law and a specialist in EU digital regulation, cybersecurity, and technology governance. With an LL.M. in Tech Law & Digital Business and over 15 years of consulting experience, he advises organisations on the AI Act, the Cyber Resilience Act (CRA), NIS2, DORA, and digital transformation strategies.
Sławomir Górniak, CISSP, CISM, is a telecommunications engineer focused on network security. Since 2008 he has worked at ENISA (the EU Agency for Cybersecurity), where he has been involved in the areas of standardisation, certification and electronic identification. He is a coordinator and co-author of multiple ENISA reports covering various aspects of information security. He is currently responsible for the Agency’s actions in the areas of standardisation and eIDAS2, and supports the implementation of the CRA.
Bruno Banelli has more than 15 years of experience in the industry, covering cybersecurity and embedded network products. He is the rapporteur for ETSI EN 304 627 (Cybersecurity requirements for routers, modems intended for the connection to the internet and switches) and an ETSI Ambassador.
He is active in various ETSI Technical Committees, a member of CEN-CENELEC JTC 21 WG 2 supporting the implementation of the AI Act (Regulation (EU) 2024/1689) Article 9 risk-management obligations, and a member of HZN (Croatian Standards Institute) TC T4 (Standardisation in telecommunications), TC 582 (Information security and business continuity) and TC 579 (Robotics, automation and integration systems).
Vesna Gabrić Kešina is a legal expert at the Croatian Regulatory Authority for Network Industries (HAKOM), with extensive experience in the fields of electronic communications, cybersecurity, and EU digital policy.
She is an active member of national and European expert and working groups dealing with cybersecurity and digital infrastructure. Her involvement includes participation in the BEREC Cybersecurity Working Group and the interinstitutional working group responsible for the implementation of the Cyber Resilience Act (CRA). She also contributed to the work of the interinstitutional working group tasked with drafting Croatia’s Cybersecurity Act.
Through her work, she contributes to the development and implementation of regulatory frameworks, cybersecurity policies, and initiatives aimed at strengthening the resilience and security of digital infrastructure at both the national and European levels.
An expert in risk management and auditing in the fields of artificial intelligence, cybersecurity, organisational resilience, and regulatory compliance. She is an active member of the European Union Agency for Cybersecurity (ENISA) working group for the European certification scheme for managed security services (EUMSS), an expert within the European Data Protection Board (EDPB) specialist group focusing on emerging technologies and information security, and an active member of the CEN-CENELEC Strategic Advisory Group on standardisation in the areas of artificial intelligence and the EU AI Act. She is a member of the Supervisory Board of OTP Bank Croatia, where she also serves on the Remuneration Committee, Nomination Committee, Audit Committee, and Risk Committee.
She advises executive boards on matters relating to the digital economy and European digital regulations. In addition, she is an internationally accredited Lead Tutor and Senior Certification Auditor for standards governing artificial intelligence, information and cybersecurity, business continuity management, personal data protection, and conformity assessments under European digital regulations. She performs these roles for TÜV NORD CERT, Germany’s largest certification body, as well as its affiliated organisations TÜV Nederlands, TÜV UK, and TÜV NORD Adriatic.
She is the first authorised cybersecurity auditor under Croatia’s Cybersecurity Act (NIS2), certified in accordance with the national security certification framework. She holds a large number of active internationally accredited professional certifications within her areas of expertise and is the author of numerous scientific and professional publications. As the owner and managing director of several active companies, she has held executive and leadership positions for more than 15 years.
Milan Parat is the Senior Executive Director of Corporate Security and Chief Security Officer (CSO) of PBZ Group. He began his career at Privredna banka Zagreb (PBZ) in 1994. In 1997, he moved into the field of information systems security and shortly thereafter became Head of Information Security (CISO) at PBZ.
Under his leadership, the Bank implemented security systems for card operations, telephone and internet banking, payment services, PKI infrastructures, and a range of other critical security solutions.
Since 2008, Milan Parat has served as Executive Director of Corporate Security and Chief Security Officer of PBZ Group, overseeing the organisation’s overall security strategy and governance.
In addition to his role at PBZ Group, he has been Chairman of the Security Committee of the Croatian Banking Association since 2012. Since 2014, he has represented Croatia in the Cyber Security Expert Group of the European Banking Federation (EBF), contributing to the development of cybersecurity initiatives and best practices within the European banking sector.
Stjepan Jambrak is the Information and Cybersecurity Coordinator at JANAF d.d., where he is responsible for coordinating cybersecurity activities, risk management, and compliance with legal and regulatory requirements.
He has extensive experience in information security, security process management, the implementation of security standards, and the development of organisational and technical security measures. His expertise encompasses governance, risk management, and the establishment of effective security frameworks that support business resilience and regulatory compliance.
Stjepan is actively involved in initiatives aimed at strengthening cyber resilience, managing cyber risks, and aligning business operations with both national and European regulatory frameworks. His work focuses on enhancing organisations’ ability to prevent, detect, and respond to evolving cybersecurity threats while ensuring compliance with applicable legislation and industry standards.
An electrical engineering graduate from FER at heart, he has served as Chief Information Security Officer (CISO) for the past eight years and currently holds the position of Director of Information Security at Podravka Group. He is responsible for the implementation and ongoing development of the Group’s Information Security Management System (ISMS), ensuring the protection of information assets and alignment with security best practices.
Co-founder of Company Score, a platform for supplier risk management and compliance with regulatory frameworks such as NIS2 and DORA. With more than 20 years of experience across the security, intelligence, and corporate sectors, including senior leadership roles in cybersecurity, he specialises in cyber risk management, supply chain security, and the development of corporate security programmes.
Martina Dragičević is the Director of Regulatory Affairs, EU Funds and Wholesale at A1 Croatia, with more than 20 years of experience in the electronic communications sector and related industries.
She holds a law degree from the Faculty of Law, University of Zagreb, a Master’s degree in EU Competition Law from King’s College London, and an MBA in General Finance from the Swiss School of Business and Management (SSBM).
Martina leads a team responsible for:
She is actively involved in several industry and business associations, including the Croatian Employers’ Association (HUP), the Croatian Chamber of Economy (HGK), AmCham Croatia, the Foreign Investors Council (FIC), and XEnergy. Within HUP, she serves as Head of the Telecommunications and Connectivity Working Group, Vice-Chair of the HUP ICT Executive Board, and Head of the HUP Cybersecurity Coordination Group.
Maja Sarić is a Regional Accounts Manager at Fortinet, responsible for business development and managing relationships with customers and partners across the Adriatic region.
She has more than 20 years of experience in the IT industry and in working with enterprise customers. Prior to joining Fortinet, she built her career at companies including IBM, Hrvatski Telekom, and Siemens. Today, her professional focus is on cybersecurity, network security, and the development of security solutions tailored to organisations’ business needs.
Fill in the form to secure your place at the CRA & Supply Chain Security conference. We will send a registration confirmation to your email address.
"(Required)" indicates required fields
How can organisations secure increasingly complex networks, enable secure remote access, and respond effectively to emerging threats? Join our four-hour technical workshop, Deploying Security Strategies for the Modern Network, held as part of the IQ Defence Conference, and discover the capabilities of Fortinet security solutions through hands-on exercises.
The workshop is designed for network and security professionals, as well as IT teams looking to strengthen the protection of their infrastructure and simplify security management. At its core is the FortiGate Next-Generation Firewall (NGFW), which combines networking and security functions, specialised processors, and FortiGuard Labs threat intelligence to deliver effective protection with high performance.
The workshop will demonstrate how a unified security approach helps protect network traffic, cloud applications, and IoT devices, while automation reduces the operational burden on IT and security teams.
"(Required)" indicates required fields
Working in small groups, participants learn to assess in a structured way whether a product falls under the CRA.
They can use product examples of their choice, assessing whether the CRA applies and explaining their reasoning. Groups can then present their findings to everyone in the breakout session, and we will discuss results together.
Michael Jesse is the founder of NexTech.Law and a specialist in EU digital regulation, cybersecurity, and technology governance.
With an LL.M. in Tech Law & Digital Business and over 15 years of consulting experience, he advises organizations on AI Act, Cyber Resilience Act (CRA), NIS2, DORA, and digital transformation strategies.
"(Required)" indicates required fields
Ready for an evening of cyber challenges? Join us at the Hacking Night CTF competition, held as part of the IQ Defence Conference, and put your knowledge, problem-solving abilities, and security skills to the test.
The competition will run from 18:00 to 24:00, offering six hours of exploration, clue hunting, and challenge solving. Each team consists of three members working together to tackle tasks in a CTF (Capture the Flag) format, where participants must identify hidden flags and collect points by solving a variety of cybersecurity challenges.
Hacking Night is an opportunity to put theory into practice, experiment with different problem-solving approaches, and connect with fellow cybersecurity enthusiasts. Curiosity, perseverance, and teamwork will be your greatest assets.
The most successful teams will receive prizes sponsored by Aircash:
"(Required)" indicates required fields