IoT TECH DAY 2026

Cybersecurity in the IoT? Methodological and Regulatory Shifts You Can’t Afford to Miss!

Wednesday, October 14, from 2:00 p.m. to 6:00 p.m.

Organized as part of a partnership between the Networks and Telecommunications (R&T) Department at the Béziers University Institute of Technology (IUT) and CAP’TRONIC, this seminar aims to raise awareness among companies about the cybersecurity challenges associated with connected devices and to introduce them to the main approaches for designing, deploying, and maintaining resilient IoT systems.

Participants will learn, in particular, about the requirements of the Cyber Resilience Act (CRA), as well as the principles of "Security by Design," which place security at the heart of the development cycle for connected products.

SPEAKERS

• Mr. Jérôme AZE – Director of the Béziers IUT
• Mr. Julien VERMILLARD of CLUNKY MACHINES: The CRA (Cyber Resilience Act)
• Mr. Jean-Christophe MARPEAU – CAP’TRONIC program: Cyber risk analysis and vulnerability management
• Mr. Grégory POHU of VIVERIS: Secure-by-design and secure boot
• Mr. Guillaume HANA of the EMITECH laboratory: The requirements of the EN 18031 standard and their impact on the development of connected devices

PROGRAM

1:30 p.m.: Welcome
2:00 p.m. Introduction by the organizers
• Background: Cybersecurity for connected devices is no longer optional. Every connected device is a potential entry point for an attacker. A tailored security strategy—combining governance, technology, and employee awareness—is essential to protect data, infrastructure, and business continuity.
• Overview of the conference’s objectives and agenda

1. Cyber Resilience Act (CRA)
Speaker: Julien VERMILLARD from CLUNKY MACHINES
Presentation of the requirements of the European Cyber Resilience Act, its objectives, its scope, and the obligations it imposes on manufacturers, integrators, and distributors of connected products.
• Why the CRA exists
• Regulation covering the entire product lifecycle.
• Scope, applicability, and classification of products
• The CRA’s requirements

2. Cybersecurity Risk Analysis—A Requirement Under the CRA
Speaker: Jean-Christophe MARPEAU – CAP’TRONIC
The CYBER RESILIENT ACT marks a turning point by imposing strict requirements on manufacturers, software publishers, and digital service providers to protect users and critical infrastructure.
Cyber risk analysis is at the heart of this approach. The CRA does not merely react to threats; it requires a proactive and structured approach to identify, assess, mitigate, and monitor risks throughout the product lifecycle. It enables:
assessing cyber threats related to their products
developing operational attack scenarios targeting their products
identifying a cyber threat management strategy, detailed in specific measures and integrated into a continuous improvement plan.

3. Secure By Design
Speaker: Grégory POHU of VIVERIS
Presentation of the Secure By Design method, or how to meet CRA requirements.

4. Vulnerability Management
Speaker: Jean-Christophe MARPEAU – CAP’TRONIC
Effective September 11, 2026, this requirement is often underestimated because it is no longer limited to a simple technical practice but has become a cornerstone of compliance and user trust. The CRA requires manufacturers and software publishers to implement robust processes to identify, assess, correct, and disclose vulnerabilities throughout the product lifecycle. This includes transparency obligations toward users, particularly through the reporting of critical vulnerabilities, as well as regular updates to mitigate risks.
This is a process requirement, and a process cannot be improvised on the day of an incident.

5. Secure Boot
Speaker: Grégory POHU from VIVERIS
Presentation of the secure boot mechanism, which ensures the software integrity of a device as soon as it is powered on and prevents the execution of malware.

6. The EN 18031 Standard
Speaker: Guillaume HANA from the EMITECH laboratory
With the launch of the CRA, what does the future hold for the European standard EN 18031, which specifies the cybersecurity requirements applicable to connected radio equipment under the RED Directive and CE marking?
How the CRA relates to other standards/directives: NIS2, IEC 62443, ETSI 303645…
Focus on the process involving a notified body and on compiling the documentation for CE marking within the framework of the CRA.

6:00 p.m. Conclusion of the day – Q&A

PRACTICAL INFORMATION

Target audience: Clients, designers of connected devices and embedded systems, quality managers, project managers, etc.

Location: IUT de Béziers – 3 Place du 14 Juillet – 34505 Béziers

Date: October 14, 2026, from 2:00 p.m. to 6:00 p.m. – Registration begins at 1:30 p.m.

Price: Free; the costs associated with organizing this seminar are covered by CAP’TRONIC and the Béziers IUT

Contact: José REBEJAC – 06 79 49 72 23 – rebejac@captronic.fr