The Canonical
CRA Connect Tour
How device makers are preparing for the Cyber Resilience Act
Get clarity on Cyber Resilience Act compliance from Canonical’s experts at the CRA Connect Tour. This series of
in-person events is designed for device makers who want to understand the new regulations and build for compliance.
You’ll walk away with actionable insights on SBOMs, vulnerability reporting, and long-term security maintenance. Join
us on the tour, with upcoming stops in Amsterdam, Munich, Toronto, and more.
Join us on the tour
Ready for the CRA? Let’s get compliant together. Spend time with the experts, demystify the latest regulations, and walk away with a clear, actionable roadmap for preparing your devices for the Cyber Resilience Act.
See our demos and map your path to compliance
See live demos of the open source tooling that gets your devices CRA-ready. We will show you how to harden devices, generate an SBOM, and manage security updates across your fleet.
Meet security and compliance experts and ask your questions
Get direct access to security and compliance experts. Bring your toughest questions to the CRA Connect Tour and engage with our experts through insightful talks, hands-on workshops, and interactive Q&A sessions designed to help you master CRA compliance.
Ship and maintain compliant devices in production
Learn what your options are and what the market offers for keeping devices compliant in production. Talk to our team about support and managed services, and how to run your devices in the EU market without worrying about upgrades, patching, or vulnerability reporting.
Where to find us
The EU Cyber Resilience Act reaches its first milestone on 11 September 2026, when manufacturers must begin reporting exploited vulnerabilities within 24 hours, including for legacy products already on the market. Canonical helps device makers build compliance in with secure-by-design development, long-term maintenance, SBOMs, and vulnerability management. Come find us across Europe and North America this autumn to talk through what the CRA means for your fleet.
Europe
22-23 September 2026, Amsterdam, Netherlands
Keynote:
Open source, open liability? How the Cyber Resilience Act changes the rules for IoT device makers with Jean-Charles Verdié and Ondrej Kubik, Canonical on Wednesday, 23rd September at 9.30 AM CET.
5 November, Manchester, England
Talk:
Bridge the IT/OT Divide with Ondrej Kubik, Canonical.
24-26 November 2026, Nuremberg, Germany
Find us inside Advantech’s booth, Hall 7, #380.
16-18 March 2027, Nuremberg, Germany
North America
22-24 September 2026, Toronto, Canada
Find us inside on booth 46-47.
22-24 September 2026, Anaheim, CA
Talk:
Surviving the CRA: Architecting Zephyr for 15-year lifecycles and long-term compliance with Jonathan Beri, Canonical.
For future CRA events, contact pr@canonical.com.
Get CRA-compliant with Canonical
A device subscription with security maintenance and compliance tooling to help you meet the CRA.
An immutable operating system for embedded devices, built on snaps with security features out of the box.
Distribute updates, patch at scale, and enforce compliance policies across your fleet from one place.
Long-term security updates for the operating system and the open source packages your devices depend on.
Get to market on certified hardware, backed by Canonical's commitment to certify its products for the CRA.
Work with our experts to plan your compliance roadmap and bring your devices to market.
CRA Resources
Blog and whitepapers
CRA compliance: Things IoT manufacturers can no longer do under the CRA (and what to do instead)
Get a thorough overview of common IoT manufacturer and PDE developer practices that need immediate attention in order to meet full CRA compliance.
The EU Cyber Resilience Act checklist
Download your practical, step-by-step guide to meeting the CRA’s requirements.
Cyber Resilience Act: Yocto or Ubuntu Core for embedded devices?
Explore the critical considerations for device manufacturers, developers, and relevant stakeholders when choosing between custom-built Linux distributions using the Yocto Project and commercially supported solutions like Ubuntu Core.
Webinars
Introduction to the EU Cyber Resilience Act
Watch our experts break down what the Cyber Resilience Act means for device manufacturers, from vulnerability reporting to lifecycle security, and see how Ubuntu Pro for Devices helps you harden your attack surface and simplify compliance.
Ubuntu and the EU Cyber Resilience Act: Building compliant, secure devices
As the Cyber Resilience Act introduces new security requirements for OEMs and ODMs, how do device makers stay compliant? Watch how Ubuntu helps you build secure devices, manage vulnerabilities, and maintain compliance across the full product lifecycle.