EU–Japan Cyber Resilience Act (CRA) and JC-STAR Technical Working Group (TWG)

Overview

The Cyberstand.eu and StandICT.eu 2029 EU-Japan Cyber Resilience Act (CRA) and JC-STAR Technical Working Group (TWG) brings together leading European experts to analyse, compare and map the cybersecurity requirements and conformity assessment approaches of the European Cyber Resilience Act (CRA) and Japan's JC-STAR scheme.

The group provides a structured forum for collaboration between standardisation experts and researchers. Its work focuses on identifying similarities and gaps between the two frameworks, while fully respecting the regulatory autonomy of both jurisdictions.

The TWG supports evidence-based technical cooperation by conducting detailed comparative analyses and facilitating continuous dialogue between European and Japanese stakeholders. The group contributes to strengthening international cooperation on cybersecurity standards between Europe and Japan.

 

Objectives

The Technical Working Group aims to support closer cooperation between the European Union and Japan by delivering robust technical analyses that can inform future policy discussions on the similarities and gaps between the CRA and JC-STAR frameworks.

Its objectives are to:

  • Compare and map cybersecurity requirements across the two frameworks for relevant product categories, including smart home devices, communication equipment, routers, modems and network devices.

  • Analyse and compare Conformity Assessment Procedures (CAPs) to identify common approaches an, differences.

  • Identify regulatory gaps, implementation differences and areas of alignment that may facilitate future cooperation.

  • Foster continuous knowledge exchange between European and Japanese experts from government, industry, academia and standardisation organisations.

  • Provide technical evidence that supports the European Commission's ongoing work on EU-Japan cooperation on cybersecurity standardisation.

By reducing technical complexity and improving transparency between the two schemes, the group's work contributes to facilitating market access, supporting manufacturers operating across both regions and promoting greater global convergence on cybersecurity practices.

 

Task Force results

The Technical Working Group is expected to deliver a series of practical outputs that support both technical collaboration and future policy development, including:

  • Comprehensive technical mapping reports comparing the cybersecurity requirements of the CRA and JC-STAR across selected product categories.
  • A detailed comparative analysis of the Conformity Assessment Procedures (CAPs) adopted by both frameworks.
  • Executive summaries highlighting the main findings, levels of alignment and policy-relevant recommendations.
  • Recommendations identifying areas where additional technical work or policy dialogue may strengthen cooperation between Europe and Japan.

Collectively, these outputs will provide a solid technical foundation for future discussions on regulatory cooperation, and strengthen long-term EU-Japan collaboration in cybersecurity standardisation.

 

TWG Leader

Anna Maria Mandalari

Secretary
Cyberstand.eu Strategy Board member and ETSI TC CYBER-EUSR
Luigi Colucci
Luigi Colucci

Project Manager
Trust-IT Services
XiaoRui Zhang
XiaoRui Zhang

Project Manager
Dublin City University

The Cyber Resilience Act is a major step towards improving the security of connected products in Europe. Through the EU-Japan CRA and JC-STAR Technical Working Group, we have the opportunity to discuss how these requirements can be understood, implemented and assessed in practice, while strengthening cooperation between European and Japanese experts.
 

Anna Maria Mandalari

University College London

From the Common Criteria onward, experience shows that durable recognition between assurance regimes is built on patient technical mapping, not diplomatic signatures alone. Mapping the CRA and JC-STAR turns duplicated conformity costs into reusable evidence, which matters most to the SMEs both economies depend on. It also raises the global security baseline, because insecure products in one market are attack infrastructure against every market. Done well, this becomes proof that like-minded economies can set product-security norms cooperatively rather than by regulatory collision.

Bruno Banelli

Sartura d.d.

The mapping between the EU Cyber Resilience Act (CRA) and Japan's JC-STAR is a critical step toward achieving global cybersecurity alignment. By bridging these two frameworks, we can significantly reduce compliance burdens for manufacturers and ensure consistent security standards across international markets.

Sara Lazzaro

University Mediterranea of Reggio Calabria

Translating the Cyber Resilience Act into clear, practical, and verifiable security requirements is essential to support effective implementation. International alignment can also help reduce duplication and simplify compliance for manufacturers operating across different markets.

Vincenzo De Angelis

Università Mediterranea di Reggio Calabria

TWG Members

Bruno Banelli
Emerging Technologies Architect
Sartura d.d.
Scott Cadzow
Consultant
Cadzow Communications Consulting Ltd
Vincenzo De Angelis
Tenure-Track Assistant Professor
Università Mediterranea di Reggio Calabria
Sara Lazzaro
Postdoctoral researcher
University Mediterranea of Reggio Calabria
Andrew Losty
PhD Student
University College London