Ask Your CRA Certification Questions at the Czech Sensor to Satellite Forum, 16 September and 7 October 2026
The Electrotechnical Association of the Czech Republic is running the Sensor to Satellite Future Connectivity Forum in two halves this autumn, and both programmes include a session on certification under the Cyber Resilience Act. If you build connectivity hardware, industrial IoT or secure data infrastructure for the EU market, that is the session worth travelling for. Prague is on 16 September 2026 at the Ministry of Industry and Trade. Brno is on 7 October 2026 at the International Engineering Fair. Both run from 10:00 to 13:00, both are free, and both require registration.
Two things are worth knowing before you walk in. First, the CRA does not create a cybersecurity certification scheme of its own: it creates a conformity assessment obligation that ends in a CE marking, which is a different instrument from a certificate. Second, no CRA harmonised standard has yet been cited in the Official Journal of the EU, and that directly changes which assessment route is open to you. Both points are set out below.
Whose products this is about
Connectivity stacks are unusually rich in Annex III important products, where the CRA's heavier obligations bite. Routers, modems intended for connection to the internet and switches sit at Class I item 12. Physical and virtual network interfaces are item 10. VPN functionality is item 5. Operating systems are item 11. An industrial gateway that routes to the internet and terminates a VPN can land on three of those at once, and a satellite or private 5G terminal is a modem for these purposes. eSIM provisioning and secure storage sit alongside them, with the classification turning on what the product actually does. Our classification finder will place a specific product, and we have mapped the 17 draft ETSI product standards, two of which cover routers and network interfaces directly.
What is on the programme
The two events share a programme, with Prague leaning towards strategy and regulation and Brno towards deployment experience. Both are moderated by Petr Vítek, secretary of the 5G Alliance at the Ministry of Industry and Trade. Sessions:
- eSIM solutions in industrial applications, Physter Technology
- SpaceBox, terrestrial and satellite secure storage, i46
- Certification under the CRA
- GLIDER, an industrial IoT communicator running LTE-M and the Zephyr real-time operating system, Hardwario
- Open 5G HUB Brno, Veletrhy Brno
The questions to bring
Under Article 32, the route you take depends on where your product sits. A default-tier product can be self-assessed by the manufacturer using internal control. An Annex III Class I product can be self-assessed only where harmonised standards, common specifications or a European cybersecurity certification scheme have been applied in full. Applied in part, or not existing at all, and the product must go through EU-type examination followed by production control, or full quality assurance, both of which involve a нотифициран орган. For Class II there is no self-assessment route at any point.
Read that against the status box. With no harmonised standard yet citable, a Class I connectivity product currently has no self-assessment path. That single fact drives cost, lead time and who you need to talk to, so it is the first thing to pin down:
- Which of the Article 32 routes applies to my product as it stands today, and which would apply once the harmonised standards arrive?
- Which notified bodies are designated for this scope, and what are their lead times? The rules on notified bodies have applied since 11 June 2026.
- How long is my период на поддръжка under Article 13(8), given how long this class of hardware stays in the field?
- What does the technical documentation in Article 31 and Annex VII actually have to contain, and who assembles it?
Our Ръководство за Маркировка „СЕ“ walks the routes, the support-period planner covers the second question and the калкулатора на разходите gives a sense of what third-party assessment adds. Separately, reporting obligations begin on 11 септември 2026 г., five days before the Prague event, so anyone shipping connected hardware will have just crossed that line. Our ръководството за докладване sets out the 24 hour, 72 hour and final report deadlines.
Practical details
- Prague, 16 September 2026, 10:00 to 13:00. Ministry of Industry and Trade, Na Františku 32, Prague 1. Programme and registration.
- Brno, 7 October 2026, 10:00 to 13:00. International Engineering Fair, Pavilion P, hall P3. Programme and registration.
- Attendance is free of charge, but registration is required for both.
Disclosure: i46 s.r.o., which operates this site, will be participating at both events.
