Skip to main content

The Canonical
CRA Connect Tour

How device makers are preparing for the Cyber Resilience Act

Get clarity on Cyber Resilience Act compliance from Canonical’s experts at the CRA Connect Tour. This series of in-person events is designed for device makers who want to understand the new regulations and build for compliance. 
You’ll walk away with actionable insights on SBOMs, vulnerability reporting, and long-term security maintenance. Join us on the tour, with upcoming stops in Amsterdam, Munich, Toronto, and more.


Join us on the tour

Ready for the CRA? Let’s get compliant together. Spend time with the experts, demystify the latest regulations, and walk away with a clear, actionable roadmap for preparing your devices for the Cyber Resilience Act.

See our demos and map your path to compliance

See live demos of the open source tooling that gets your devices CRA-ready. We will show you how to harden devices, generate an SBOM, and manage security updates across your fleet.


Meet security and compliance experts and ask your questions

Get direct access to security and compliance experts. Bring your toughest questions to the CRA Connect Tour and engage with our experts through insightful talks, hands-on workshops, and interactive Q&A sessions designed to help you master CRA compliance.


Ship and maintain compliant devices in production

Learn what your options are and what the market offers for keeping devices compliant in production. Talk to our team about support and managed services, and how to run your devices in the EU market without worrying about upgrades, patching, or vulnerability reporting.


Where to find us

The EU Cyber Resilience Act reaches its first milestone on 11 September 2026, when manufacturers must begin reporting exploited vulnerabilities within 24 hours, including for legacy products already on the market. Canonical helps device makers build compliance in with secure-by-design development, long-term maintenance, SBOMs, and vulnerability management. Come find us across Europe and North America this autumn to talk through what the CRA means for your fleet.

Book a meeting with us ›


Europe

The Things Conference

22-23 September 2026, Amsterdam, Netherlands
Keynote:
Open source, open liability? How the Cyber Resilience Act changes the rules for IoT device makers with Jean-Charles Verdié and Ondrej Kubik, Canonical on Wednesday, 23rd September at 9.30 AM CET.

Canonical Day

5 November, Manchester, England
Talk:
Bridge the IT/OT Divide with Ondrej Kubik, Canonical.

SPS 2026

24-26 November 2026, Nuremberg, Germany
Find us inside Advantech’s booth, Hall 7, #380.

Embedded World

16-18 March 2027, Nuremberg, Germany


North America

ROSCon Global

22-24 September 2026, Toronto, Canada
Find us inside on booth 46-47.

Embedded World NA

22-24 September 2026, Anaheim, CA
Talk:
Surviving the CRA: Architecting Zephyr for 15-year lifecycles and long-term compliance with Jonathan Beri, Canonical.


For future CRA events, contact pr@canonical.com.


Get CRA-compliant with Canonical

A device subscription with security maintenance and compliance tooling to help you meet the CRA.


An immutable operating system for embedded devices, built on snaps with security features out of the box.


Distribute updates, patch at scale, and enforce compliance policies across your fleet from one place.


Long-term security updates for the operating system and the open source packages your devices depend on.


Get to market on certified hardware, backed by Canonical's commitment to certify its products for the CRA.


Work with our experts to plan your compliance roadmap and bring your devices to market.


CRA Resources

Blog and whitepapers

CRA compliance: Things IoT manufacturers can no longer do under the CRA (and what to do instead)

Get a thorough overview of common IoT manufacturer and PDE developer practices that need immediate attention in order to meet full CRA compliance.

The EU Cyber Resilience Act checklist

Download your practical, step-by-step guide to meeting the CRA’s requirements.

Cyber Resilience Act: Yocto or Ubuntu Core for embedded devices?

Explore the critical considerations for device manufacturers, developers, and relevant stakeholders when choosing between custom-built Linux distributions using the Yocto Project and commercially supported solutions like Ubuntu Core.


Webinars

Introduction to the EU Cyber Resilience Act

Watch our experts break down what the Cyber Resilience Act means for device manufacturers, from vulnerability reporting to lifecycle security, and see how Ubuntu Pro for Devices helps you harden your attack surface and simplify compliance.

Ubuntu and the EU Cyber Resilience Act: Building compliant, secure devices

As the Cyber Resilience Act introduces new security requirements for OEMs and ODMs, how do device makers stay compliant? Watch how Ubuntu helps you build secure devices, manage vulnerabilities, and maintain compliance across the full product lifecycle.