IQ Defence Conference

CRA & Supply Chain Security: From Regulation to True Cyber Resilience

16 October 2026Algebra Bernays University, ZagrebConference · Workshop · Hacking Night
Conference date16 October 2026Friday
Time09:00 – 16:30Registration from 09:00
VenueAlgebra Bernays UniversityGradišćanska 24, Zagreb

About the event

How can organisations prepare for the Cyber Resilience Act (CRA) and the requirements introduced by the NIS2 Directive for both designated entities and their suppliers? Find out on 16 October 2026 at Algebra Bernays University in Zagreb, at a conference held as part of the IQ Defence project.

The conference will bring together representatives of European and Croatian institutions, standardisation and cybersecurity experts, as well as companies already dealing with these new regulatory requirements in practice.

The focus will be on NIS2 implementation, the new requirements introduced by the CRA, supply chain security, harmonised standards, supplier accountability, and the practical challenges of implementing new rules within business environments.

If you work in cybersecurity, IT, product development, regulatory compliance, risk management, or collaborate with suppliers of digital products and services, this is where regulation meets practice.

Be prepared for the new era of cybersecurity requirements.

Programme

Main hall

  1. 09:00 – 09:30
    Registration
  2. 09:30 – 09:35
    Conference opening
    Zlatan Morić, Algebra Bernays University
  3. 09:35 – 09:50
    Introductory presentation
    Tomislav Dominković, Algebra Bernays University
  4. 09:50 – 10:20
    CRA in Practice: What Manufacturers Need to Do Now
    Michael Jesse, CRA expert
    MoreLess

    1. Regulatory overview, timeline and reporting

    Fundamentals of the CRA, comparison with NIS2, ISO/IEC 27001 and DORA, differences, overlaps and implementation timeline.

    2. Manufacturer responsibilities and key requirements

    The overview will cover risk assessment, secure development, vulnerability handling, updates, technical documentation, conformity assessment and CE marking.

    3. Product scope, classification and conformity route

    Practical framework in action: CRA scope → product boundary → product category → conformity assessment route → first compliance actions.

    This will explain how a product’s core functionality determines its category and what this means for self-assessment, harmonised standards and third-party assessment.

  5. 10:20 – 10:40
    CRA reporting, Single Reporting Platform Demo
    Sławomir Górniak, ENISA
    MoreLess

    The presentation will focus on the obligations stemming from the CRA with regard to notification by manufacturers and open source software stewards about serious incidents and actively exploited vulnerabilities. It will be followed by a live demonstration of the functioning of the Single Reporting Platform, set up by ENISA in this context and made operational on 11 September.

  6. 10:40 – 11:20
    Translating CRA requirements into practical and verifiable requirements
    Bruno Banelli, ETSI
    MoreLess

    Guidance to the layered approach of standardisation covering the Cyber Resilience Act (CRA) (Regulation (EU) 2024/2847), from prEN 4000-1-x series horizontal (common, product-independent framework) standards to EN 304 6xx vertical (product-specific) standards and their applicability. How to tackle normative parts and how to help yourself with informative parts. Dos, don’ts and gotchas included.

  7. 11:20 – 11:50
    Coffee break
  8. 11:50 – 12:10
    The Croatian national perspective
    NCSC-HR
  9. 12:10 – 12:30
    Regulatory and market-surveillance perspective
    Vesna Gabrić Kešina, HAKOM
  10. 12:30 – 12:50
    Supply chain cybersecurity – experience from audit
    Dr. Natalija Parlov Una
    TÜV NORD & Dr. Franjo Tudjman Defense and Security University
    MoreLess

    This presentation provides a practical overview of planning and conducting cybersecurity and resilience audits of critical ICT supply chains, in line with regulatory requirements and guidelines as the primary benchmark, while also highlighting the most common findings identified during such audits.

    The focus is on identifying critical suppliers and business dependencies, defining the scope and audit approach, and assessing the need to amend contracts with additional security clauses. Particular emphasis is placed on supplier access management, vulnerability management, incident handling, and business continuity.

    The presentation will also explore how identified findings can be addressed through risk assessments and action plans, how to understand management’s responsibility in defining the organisation’s acceptable level of risk, and the potential consequences of different decisions related to security and resilience management obligations within the critical ICT supply chain.

  11. 12:50 – 13:40
    Panel Supply Chain Security: Experiences from Croatia
    Milan Parat, Croatian Banking Association (HUB)
    Igor Videc, OIV
    Stjepan Jambrak, JANAF
    Dario Rajn, Podravka
    Bruno Pavić, ProForca
    Moderator: Ivana Ivanda Rožić, RTL
    MoreLess

    A company’s security increasingly depends on technology suppliers, external service providers and partners with access to its systems and data. How do Croatian companies identify critical suppliers, assess their risks and put security requirements into practice?

    Representatives from banking, communications infrastructure, energy and food manufacturing, alongside a business partner assessment perspective, will share their experiences of supplier due diligence, access management and incident response. The discussion will also explore decisions companies face when a supplier is difficult to replace or falls short of security expectations, offering practical recommendations for a more resilient supply chain.

  12. 13:40 – 14:40
    Lunch break
  13. 14:40 – 15:30
    Panel Preparing Companies for the CRA
    Kristina Leko Kuštrak, AKD
    Tamara Hadjina, KONČAR
    Natalija Parlov Una, TÜV NORD
    Martina Dragičević, A1
    Maja Sarić, Fortinet
    Moderator: Ivana Ivanda Rožić, RTL
    MoreLess

    How can companies turn the requirements of the Cyber Resilience Act (CRA) into a practical action plan? This panel brings together perspectives from IT management, product development, conformity assessment, regulatory affairs and security solution providers.

    The panellists will discuss defining product scope, assigning responsibilities, integrating security into development, and managing vulnerabilities and support throughout the product lifecycle. Particular attention will be given to documentation and security evidence, supplier cooperation, and the roles of manufacturers and importers. The audience will gain practical recommendations on where to start and how to integrate CRA preparation into existing business and development processes.

  14. 15:30 – 16:20
    Panel NIS2 challenges
    Representatives of national cybersecurity centres from several EU Member States
  15. 16:20 – 16:30
    Conference closure
Register

Parallel programme

  1. 10:50 – 11:20
    Coffee break
  2. 11:20 – 15:30
    NCSCs Workshop
    Closed session for national cybersecurity centres
  3. 11:20 – 16:20
    Deploying Security Strategies for the Modern Network More →
    Technical Workshop on Fortinet Equipment
  4. 12:40 – 13:40
    Workshop: Does My Product Fall under the CRA? More →
    Michael Jesse
  5. 18:00 – 24:00
    Hacking Night 2026 More →
    Evening hands-on programme, CTF competition
Conference date16 October 2026Friday
Time09:00 – 16:30Registration from 09:00
VenueAlgebra Bernays UniversityGradišćanska 24, Zagreb

Speakers

Conference date16 October 2026Friday
Time09:00 – 16:30Registration from 09:00
VenueAlgebra Bernays UniversityGradišćanska 24, Zagreb

Conference registration

Fill in the form to secure your place at the CRA & Supply Chain Security conference. We will send a registration confirmation to your email address.

"(Required)" indicates required fields

By submitting this form, you consent to the processing of your personal data for the purpose of event registration and organisation and providing information related to the IQ Defence project. Your data will be processed in accordance with applicable EU and national data protection legislation, including Regulation (EU) 2016/679 (GDPR). Personal data will not be shared with third parties outside the project consortium unless required by law. You may request access to, correction, or deletion of your data at any time by contacting the project coordinator.(Required)
Date and time16 October 202611:20 – 16:20 · 4 hours of hands-on work
Who it is forNetwork and security professionalsand IT teams
VenueAlgebra Bernays UniversityGradišćanska 24, Zagreb
Fortinet workshop

Deploying Security Strategies for the Modern Network

How can organisations secure increasingly complex networks, enable secure remote access, and respond effectively to emerging threats? Join our four-hour technical workshop, Deploying Security Strategies for the Modern Network, held as part of the IQ Defence Conference, and discover the capabilities of Fortinet security solutions through hands-on exercises.

The workshop is designed for network and security professionals, as well as IT teams looking to strengthen the protection of their infrastructure and simplify security management. At its core is the FortiGate Next-Generation Firewall (NGFW), which combines networking and security functions, specialised processors, and FortiGuard Labs threat intelligence to deliver effective protection with high performance.

The workshop will demonstrate how a unified security approach helps protect network traffic, cloud applications, and IoT devices, while automation reduces the operational burden on IT and security teams.

Through practical exercises, you will learn how to:

  • Configure essential FortiGate settings, including routing, firewall policies, and security profiles.
  • Deploy the Fortinet Security Fabric for centralised log collection, security posture visibility, and automated threat response.
  • Implement AI-powered FortiGuard security services for real-time threat detection, web filtering, application control, and malware prevention.
  • Segment and secure networks using ISFW, ZTNA, and ADVPN technologies, while enhancing remote access security and WAN connectivity.

Workshop registration

"(Required)" indicates required fields

By submitting this form, you consent to the processing of your personal data for the purpose of event registration and organisation and providing information related to the IQ Defence project. Your data will be processed in accordance with applicable EU and national data protection legislation, including Regulation (EU) 2016/679 (GDPR). Personal data will not be shared with third parties outside the project consortium unless required by law. You may request access to, correction, or deletion of your data at any time by contacting the project coordinator.(Required)
Date and time16 October 202612:40 – 13:40 · parallel to the conference
Led byMichael JesseCRA expert, NexTech.Law
VenueAlgebra Bernays UniversityGradišćanska 24, Zagreb
Workshop

Workshop: “Does My Product Fall under the CRA?”

Working in small groups, participants learn to assess in a structured way whether a product falls under the CRA.

They can use product examples of their choice, assessing whether the CRA applies and explaining their reasoning. Groups can then present their findings to everyone in the breakout session, and we will discuss results together.

About the speaker

Michael Jesse is the founder of NexTech.Law and a specialist in EU digital regulation, cybersecurity, and technology governance.

With an LL.M. in Tech Law & Digital Business and over 15 years of consulting experience, he advises organizations on AI Act, Cyber Resilience Act (CRA), NIS2, DORA, and digital transformation strategies.

Workshop registration

"(Required)" indicates required fields

By submitting this form, you consent to the processing of your personal data for the purpose of event registration and organisation and providing information related to the IQ Defence project. Your data will be processed in accordance with applicable EU and national data protection legislation, including Regulation (EU) 2016/679 (GDPR). Personal data will not be shared with third parties outside the project consortium unless required by law. You may request access to, correction, or deletion of your data at any time by contacting the project coordinator.(Required)
Time18:00 – 24:0016 October 2026
FormatCTFCapture the Flag competition
Team3 membersRegistration by team
CTF competition

Hacking Night 2026

Ready for an evening of cyber challenges? Join us at the Hacking Night CTF competition, held as part of the IQ Defence Conference, and put your knowledge, problem-solving abilities, and security skills to the test.

The competition will run from 18:00 to 24:00, offering six hours of exploration, clue hunting, and challenge solving. Each team consists of three members working together to tackle tasks in a CTF (Capture the Flag) format, where participants must identify hidden flags and collect points by solving a variety of cybersecurity challenges.

Hacking Night is an opportunity to put theory into practice, experiment with different problem-solving approaches, and connect with fellow cybersecurity enthusiasts. Curiosity, perseverance, and teamwork will be your greatest assets.

Prizes

The most successful teams will receive prizes sponsored by Aircash:

1st place
€1,500
3 Aircash cards worth €500 each
2nd place
€300
3 Aircash cards worth €100 each
3rd place
€150
3 Aircash cards worth €50 each

Team registration

"(Required)" indicates required fields

Team members(Required)
Enter all 3 members of your team in the fields below.
First name
Last name
Email
 
By submitting this form, you consent to the processing of your personal data for the purpose of event registration and organisation and providing information related to the IQ Defence project. Your data will be processed in accordance with applicable EU and national data protection legislation, including Regulation (EU) 2016/679 (GDPR). Personal data will not be shared with third parties outside the project consortium unless required by law. You may request access to, correction, or deletion of your data at any time by contacting the project coordinator.(Required)