Start Date
28 September, 2026
End Date
1 October, 2026
Location
Rome, Italy
Date
28 September - 1 October, 2026
Location
Rome, Italy
Meet Brightsight at the International Common Criteria Conference 2026
We are pleased to be a silver sponsor of the 25th edition of the International Common Criteria Conference (ICCC),
the leading global forum for professionals involved in cybersecurity certification and assurance. With a strong focus on Common Criteria (CC), the conference brings together certification bodies, evaluation laboratories, industry representatives, regulators, and technology providers to discuss the evolving cybersecurity certification landscape, including developments in EUCC and other emerging frameworks.Explore Brightsight's Conference Sessions
28 September, Monday
11:30 | W01A

Fabrice Heiser
COO Asia, Brightsight
About the session
Explore the points where real projects go off the rails: bad TOE scope, unrealistic timelines, poor ownership of evidence, misunderstandings with labs, and failure to account for country-specific or scheme-specific constraints.
Keep the Certificate Alive: Assurance Continuity, Delta Evaluation, and Patch Decisions in Fast Release Cycles
14:00 | W02B

Augusto Velasco
Fellow CC Evaluator, Brightsight
About the session
Discover what can change without breaking the certification strategy; when to use assurance continuity, when delta evaluation makes sense; and how to plan patch handling without creating a compliance freeze.
29 September, Tuesday
11:45 | P11C

Rob Kemper
Director of the Certification Body, Brightsight
About the session
Explore lessons learned from the transition to EUCC, how certification bodies, ITSEFs and vendors are building predictability in a changing environment, and where further alignment may be needed to support a consistent and workable scheme.
14:15 | B12B

Bill Yang
Fellow Security Evaluator, Brightsight
About the session
How can CRA risk assessment requirements be aligned with EUCC certification? This session explores a practical approach to linking product risk management with ASE_SPD, helping bridge CRA obligations and EUCC requirements.
14:45 | B12C

Enea Zhulati
Fellow CC Evaluator, Brightsight
About the session
This presentation shares lessons learned from a CRA-EUCC pilot project, identifying gaps for Important Class I and II products and proposing an approach to bridge EUCC certification and CRA requirements.
Interested in our cybersecurity evaluation services for the Cyber Resilience Act (CRA)?
Complete the form below and one of our experts will contact you to discuss your needs.

