<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" 
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:psc="http://podlove.org/simple-chapters"
	xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0">
    <channel>
    	<atom:link href="https://cdn.stationista.com/feeds/ode-to-resilience" rel="self" type="application/rss+xml"/>
    	<generator>https://www.stationista.com</generator>
    	<language>en-GB</language>
    	<title>Ode to Resilience</title>
        	<link>https://ode-to-resilience.stationista.com</link>
        	<pubDate>Fri, 21 Aug 2026 04:00:00 +0000</pubDate>
    	<lastBuildDate>Fri, 28 Aug 2026 16:56:30 +0000</lastBuildDate>
            <itunes:summary><![CDATA[<p>Ode to Resilience is a podcast about the EU Cyber Resilience Act, hosted by engineer Piet De Vaere and technology lawyer August Bournique. Both are closely involved in the CRA implementation work, and together they cut through the complexity of one of the most ambitious technology regulations ever passed. If you want to hear about the CRA straight from Brussels, this is the podcast for you!</p>]]></itunes:summary>
    	<description><![CDATA[<p>Ode to Resilience is a podcast about the EU Cyber Resilience Act, hosted by engineer Piet De Vaere and technology lawyer August Bournique. Both are closely involved in the CRA implementation work, and together they cut through the complexity of one of the most ambitious technology regulations ever passed. If you want to hear about the CRA straight from Brussels, this is the podcast for you!</p>]]></description>
	            	<copyright>Piet De Vaere and August Bournique</copyright>
            	<itunes:type>episodic</itunes:type>
     
    	<itunes:new-feed-url>https://cdn.stationista.com/feeds/ode-to-resilience</itunes:new-feed-url>
        		<image>
			<url>https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/images/68/6a4ea3b60ad7abf19b02db68/pc/6a5299a554cc09593505a24e_feed.jpg</url>
			<title>Ode to Resilience</title>
                	<link>https://ode-to-resilience.stationista.com</link>
        		</image>
		<itunes:image href="https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/images/68/6a4ea3b60ad7abf19b02db68/pc/6a5299a554cc09593505a24e_feed.jpg" />
			<itunes:owner>
			<itunes:name>Piet De Vaere &amp; August Bournique</itunes:name>
			<itunes:email>podcast@productsecurity.ch</itunes:email>
		</itunes:owner>
		<itunes:author>Piet De Vaere &amp; August Bournique</itunes:author>
			<itunes:category text="Technology" />
		        <itunes:keywords>CRA, Cyber Resilience Act, EU regulation, cybersecurity, product security, software compliance, EU law, digital products, manufacturer obligations, cyber law, technology regulation, Europe, cybersecurity policy, open source, product liability</itunes:keywords>
        
		<itunes:explicit>no</itunes:explicit>
            <item>
            <title>E4 - Remote Data Processing Solutions (RDPS)</title>
			<itunes:title>E4 - Remote Data Processing Solutions (RDPS)</itunes:title>
					<itunes:episodeType>full</itunes:episodeType>
							<itunes:episode>4</itunes:episode>
				                	<link>https://ode-to-resilience.stationista.com/e4-remote-data-processing-solutions-rdps_6a85a10d5eb3791d2b0a05b9</link>
                    <guid isPermaLink="false">c91b4fee065ded21084aabf9649e37f1</guid>
                	<enclosure length="53101816" type="audio/mpeg" url="https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/audio/bc/6a85a1450812c8bd560ea3bc/522f3577c144d0e067bccafb3687afb0.mp3" />
            <itunes:duration>01:13:33</itunes:duration>
                    		<image>
    			<url>https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/images/e7/6a85a41498ccab0b530633e7/ep/6a85a10d5eb3791d2b0a05b9_feed.jpg</url>
    			<title>E4 - Remote Data Processing Solutions (RDPS)</title>
                        	<link>https://ode-to-resilience.stationista.com/e4-remote-data-processing-solutions-rdps_6a85a10d5eb3791d2b0a05b9</link>
                		</image>
    		<itunes:image href="https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/images/e7/6a85a41498ccab0b530633e7/ep/6a85a10d5eb3791d2b0a05b9_feed.jpg" />
    	    	            <itunes:summary><![CDATA[<p>Piet and August take on RDPS, one of the CRA's most contested concept, pulling apart its definition almost word by word: what counts as a "function" of a product? What does "designed and developed by or on behalf of the manufacturer" mean exactly? And what exactly is "at a distance"? And does all of this really mater anyway?</p>  <p><b>Ode to Resilience </b><b>is hosted by</b></p>  <p><b></b></p>  <p><b>Piet De Vaere: </b>Electrical Engineer, CRA consultant &amp; Member of the CRA Expert Group (<a href="https://www.linkedin.com/in/devaere/">Linkedin</a> | <a href="https://devae.re">Webpage</a>)</p>  <p>and</p>  <p><b></b></p>  <p><b>August Bournique: </b>Silicon Valley technology lawyer, CRA consultant &amp; Special Rapporteur for ETSI CRA standards (<a href="https://www.linkedin.com/in/august-bournique-668b66165/">Linkedin</a> | <a href="https://bourniquelaw.com/">Webpage</a>)</p>  <p>You can reach out to us on: <a href="mailto:podcast@productsecurity.ch">podcast@productsecurity.ch</a></p>]]></itunes:summary>
        	<description><![CDATA[<p>Piet and August take on RDPS, one of the CRA's most contested concept, pulling apart its definition almost word by word: what counts as a "function" of a product? What does "designed and developed by or on behalf of the manufacturer" mean exactly? And what exactly is "at a distance"? And does all of this really mater anyway?</p>  <p><b>Ode to Resilience </b><b>is hosted by</b></p>  <p><b></b></p>  <p><b>Piet De Vaere: </b>Electrical Engineer, CRA consultant &amp; Member of the CRA Expert Group (<a href="https://www.linkedin.com/in/devaere/">Linkedin</a> | <a href="https://devae.re">Webpage</a>)</p>  <p>and</p>  <p><b></b></p>  <p><b>August Bournique: </b>Silicon Valley technology lawyer, CRA consultant &amp; Special Rapporteur for ETSI CRA standards (<a href="https://www.linkedin.com/in/august-bournique-668b66165/">Linkedin</a> | <a href="https://bourniquelaw.com/">Webpage</a>)</p>  <p>You can reach out to us on: <a href="mailto:podcast@productsecurity.ch">podcast@productsecurity.ch</a></p>]]></description>
    	            <pubDate>Fri, 21 Aug 2026 04:00:00 +0000</pubDate>
			<itunes:explicit>no</itunes:explicit>
		            <itunes:keywords>Cyber Resilience Act, CRA, RDPS, remote data processing, cloud, product security, EU regulation, Commission guidance, ETSI standards, manufacturer obligations</itunes:keywords>
            		<itunes:author>Piet De Vaere &amp; August Bournique</itunes:author>
            	        </item>
            <item>
            <title>E3 - What is the minimal CRA product?</title>
			<itunes:title>E3 - What is the minimal CRA product?</itunes:title>
					<itunes:episodeType>full</itunes:episodeType>
							<itunes:episode>3</itunes:episode>
				                	<link>https://ode-to-resilience.stationista.com/e3-what-is-the-minimal-cra-product_6a723eea6368f623e40d2eb0</link>
                    <guid isPermaLink="false">65a70353b09d600b572cc1a97f3c3706</guid>
                	<enclosure length="33974639" type="audio/mpeg" url="https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/audio/36/6a7240189d7c680eda05ea36/932aea1b4ff631ffdf7eecffe5e392dd.mp3" />
            <itunes:duration>00:46:59</itunes:duration>
                    		<image>
    			<url>https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/images/37/6a72401c9d7c680eda05ea37/ep/6a723eea6368f623e40d2eb0_feed.jpg</url>
    			<title>E3 - What is the minimal CRA product?</title>
                        	<link>https://ode-to-resilience.stationista.com/e3-what-is-the-minimal-cra-product_6a723eea6368f623e40d2eb0</link>
                		</image>
    		<itunes:image href="https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/images/37/6a72401c9d7c680eda05ea37/ep/6a723eea6368f623e40d2eb0_feed.jpg" />
    	    	            <itunes:summary><![CDATA[<p>Piet and August welcome their first guest, Götz Martinek, who brings a question he deals with regularly: what's the minimal product with digital elements, and does it really need the full CRA compliance treatment? They test the CRA's scope definitions against two real objects, a calculator with no data interface and a washing machine with a technician-only diagnostic port. From there they explore how risk assessments and compliance paperwork can scale down for genuinely low-risk products without disappearing entirely. The episode closes with a look at the baseline obligations, like documentation retention and a single point of contact, that apply no matter how trivial the product is.</p>  <p><b>Ode to Resilience </b><b>is hosted by</b></p>  <p><b></b></p>  <p><b>Piet De Vaere: </b>Electrical Engineer, CRA consultant &amp; Member of the CRA Expert Group (<a href="https://www.linkedin.com/in/devaere/">Linkedin</a> | <a href="https://devae.re">Webpage</a>)</p>  <p>and</p>  <p><b></b></p>  <p><b>August Bournique: </b>Silicon Valley technology lawyer, CRA consultant &amp; Special Rapporteur for ETSI CRA standards (<a href="https://www.linkedin.com/in/august-bournique-668b66165/">Linkedin</a> | <a href="https://bourniquelaw.com/">Webpage</a>)</p>  <p>You can reach out to us on: <a href="mailto:podcast@productsecurity.ch">podcast@productsecurity.c</a>h</p>]]></itunes:summary>
        	<description><![CDATA[<p>Piet and August welcome their first guest, Götz Martinek, who brings a question he deals with regularly: what's the minimal product with digital elements, and does it really need the full CRA compliance treatment? They test the CRA's scope definitions against two real objects, a calculator with no data interface and a washing machine with a technician-only diagnostic port. From there they explore how risk assessments and compliance paperwork can scale down for genuinely low-risk products without disappearing entirely. The episode closes with a look at the baseline obligations, like documentation retention and a single point of contact, that apply no matter how trivial the product is.</p>  <p><b>Ode to Resilience </b><b>is hosted by</b></p>  <p><b></b></p>  <p><b>Piet De Vaere: </b>Electrical Engineer, CRA consultant &amp; Member of the CRA Expert Group (<a href="https://www.linkedin.com/in/devaere/">Linkedin</a> | <a href="https://devae.re">Webpage</a>)</p>  <p>and</p>  <p><b></b></p>  <p><b>August Bournique: </b>Silicon Valley technology lawyer, CRA consultant &amp; Special Rapporteur for ETSI CRA standards (<a href="https://www.linkedin.com/in/august-bournique-668b66165/">Linkedin</a> | <a href="https://bourniquelaw.com/">Webpage</a>)</p>  <p>You can reach out to us on: <a href="mailto:podcast@productsecurity.ch">podcast@productsecurity.c</a>h</p>]]></description>
    	            <pubDate>Fri, 07 Aug 2026 04:00:00 +0000</pubDate>
			<itunes:explicit>no</itunes:explicit>
		            <itunes:keywords>Cyber Resilience Act, CRA compliance, product with digital elements, CRA scope, CRA risk assessment, essential cybersecurity requirements, vulnerability handling</itunes:keywords>
            		<itunes:author>Piet De Vaere &amp; August Bournique</itunes:author>
            	        </item>
            <item>
            <title>E2 - Supply Chain and the CRA</title>
			<itunes:title>E2 - Supply Chain and the CRA</itunes:title>
					<itunes:episodeType>full</itunes:episodeType>
							<itunes:episode>2</itunes:episode>
				                	<link>https://ode-to-resilience.stationista.com/e2-supply-chain-and-the-cra_6a53f022044da5f9a806ea34</link>
                    <guid isPermaLink="false">0ab871f21d3f11387e13a5bd9ab302e5</guid>
                	<enclosure length="36470616" type="audio/mpeg" url="https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/audio/7d/6a53f0e24abe9345aa08db7d/e721595c6c3af20b471ab577f1b9ab97.mp3" />
            <itunes:duration>00:50:27</itunes:duration>
                    		<image>
    			<url>https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/images/7e/6a53f0e74abe9345aa08db7e/ep/6a53f022044da5f9a806ea34_feed.jpg</url>
    			<title>E2 - Supply Chain and the CRA</title>
                        	<link>https://ode-to-resilience.stationista.com/e2-supply-chain-and-the-cra_6a53f022044da5f9a806ea34</link>
                		</image>
    		<itunes:image href="https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/images/7e/6a53f0e74abe9345aa08db7e/ep/6a53f022044da5f9a806ea34_feed.jpg" />
    	    	            <itunes:summary><![CDATA[<p>Piet and August dig into supply chain security as a hidden third goal of the EU Cyber Resilience Act. They break down the CRA's upstream and downstream obligations for manufacturers, tackle the tricky question of how to handle open source and first-party components, and explore the difference between proactive due diligence and reactive vulnerability monitoring. The episode closes with a thought-provoking finding: the CRA may allow authorities to deem a product non-compliant based on where it was made and who made it, raising questions about digital sovereignty that go far beyond technical security.</p>  <p><b>Ode to Resilience </b><b>is hosted by</b></p>  <p><b></b></p>  <p><b>Piet De Vaere: </b>Electrical Engineer, CRA consultant &amp; Member of the CRA Expert Group (<a href="https://www.linkedin.com/in/devaere/">Linkedin</a> | <a href="https://devae.re">Webpage</a>)</p>  <p>and</p>  <p><b></b></p>  <p><b>August Bournique: </b>Silicon Valley technology lawyer, CRA consultant &amp; Special Rapporteur for ETSI CRA standards (<a href="https://www.linkedin.com/in/august-bournique-668b66165/">Linkedin</a> | <a href="https://bourniquelaw.com/">Webpage</a>)</p>  <p>You can reach out to us on: <a href="mailto:podcast@productsecurity.ch">podcast@productsecurity.ch</a></p>]]></itunes:summary>
        	<description><![CDATA[<p>Piet and August dig into supply chain security as a hidden third goal of the EU Cyber Resilience Act. They break down the CRA's upstream and downstream obligations for manufacturers, tackle the tricky question of how to handle open source and first-party components, and explore the difference between proactive due diligence and reactive vulnerability monitoring. The episode closes with a thought-provoking finding: the CRA may allow authorities to deem a product non-compliant based on where it was made and who made it, raising questions about digital sovereignty that go far beyond technical security.</p>  <p><b>Ode to Resilience </b><b>is hosted by</b></p>  <p><b></b></p>  <p><b>Piet De Vaere: </b>Electrical Engineer, CRA consultant &amp; Member of the CRA Expert Group (<a href="https://www.linkedin.com/in/devaere/">Linkedin</a> | <a href="https://devae.re">Webpage</a>)</p>  <p>and</p>  <p><b></b></p>  <p><b>August Bournique: </b>Silicon Valley technology lawyer, CRA consultant &amp; Special Rapporteur for ETSI CRA standards (<a href="https://www.linkedin.com/in/august-bournique-668b66165/">Linkedin</a> | <a href="https://bourniquelaw.com/">Webpage</a>)</p>  <p>You can reach out to us on: <a href="mailto:podcast@productsecurity.ch">podcast@productsecurity.ch</a></p>]]></description>
    	            <pubDate>Fri, 24 Jul 2026 04:00:00 +0000</pubDate>
			<itunes:explicit>no</itunes:explicit>
		            <itunes:keywords>CRA, Cyber Resilience Act, supply chain security, component due diligence, open source, SBOM, NIS2, digital sovereignty</itunes:keywords>
            		<itunes:author>Piet De Vaere &amp; August Bournique</itunes:author>
            	        </item>
            <item>
            <title>E1 - What is the CRA?</title>
			<itunes:title>E1 - What is the CRA?</itunes:title>
					<itunes:episodeType>full</itunes:episodeType>
							<itunes:episode>1</itunes:episode>
				                	<link>https://ode-to-resilience.stationista.com/e1-what-is-the-cra_6a4e9dc861e7f07d220fff59</link>
                    <guid isPermaLink="false">1270bcf3b7d93cd7f97d2814a8e1f763</guid>
                	<enclosure length="37119159" type="audio/mpeg" url="https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/audio/c0/6a4ea1d44f971736c70e93c0/1a6ff98e57d74751824aeb22cbc5af58.mp3" />
            <itunes:duration>00:51:22</itunes:duration>
                    		<image>
    			<url>https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/images/c1/6a4ea1d94f971736c70e93c1/ep/6a4e9dc861e7f07d220fff59_feed.jpg</url>
    			<title>E1 - What is the CRA?</title>
                        	<link>https://ode-to-resilience.stationista.com/e1-what-is-the-cra_6a4e9dc861e7f07d220fff59</link>
                		</image>
    		<itunes:image href="https://cdn.stationista.com/30/6a4e9bc9be26a78c2e018f30/images/c1/6a4ea1d94f971736c70e93c1/ep/6a4e9dc861e7f07d220fff59_feed.jpg" />
    	    	            <itunes:summary><![CDATA[<p>In the debut episode of <i>Ode to Resilience</i>, Piet and August introduce themselves and lay the groundwork for the podcast by answering the most basic question: what is the EU Cyber Resilience Act? They break down what "products with digital elements" actually covers (spoiler: nearly everything digital), walk through the four main pillars of CRA requirements, from product security and secure development processes to long-term support obligations and vulnerability reporting, and demystify the compliance timeline. The episode closes with a grounded take on enforcement and the famously large fines, reassuring listeners that the CRA, while ambitious, is fundamentally reasonable and manageable for manufacturers willing to take cybersecurity seriously.</p>  <p><i></i></p>  <p><b>Ode to Resilience </b><b>is hosted by</b></p>  <p><b></b></p>  <p><b>Piet De Vaere: </b>Electrical Engineer, CRA consultant &amp; Member of the CRA Expert Group (<a href="https://www.linkedin.com/in/devaere/">Linkedin</a> | <a href="https://devae.re">Webpage</a>)</p>  <p>and</p>  <p><b></b></p>  <p><b>August Bournique: </b>Silicon Valley technology lawyer, CRA consultant &amp; Special Rapporteur for ETSI CRA standards (<a href="https://www.linkedin.com/in/august-bournique-668b66165/">Linkedin</a> | <a href="https://bourniquelaw.com/">Webpage</a>)</p>  <p>You can reach out to us on: <a href="mailto:podcast@productsecurity.ch">podcast@productsecurity.ch</a></p>]]></itunes:summary>
        	<description><![CDATA[<p>In the debut episode of <i>Ode to Resilience</i>, Piet and August introduce themselves and lay the groundwork for the podcast by answering the most basic question: what is the EU Cyber Resilience Act? They break down what "products with digital elements" actually covers (spoiler: nearly everything digital), walk through the four main pillars of CRA requirements, from product security and secure development processes to long-term support obligations and vulnerability reporting, and demystify the compliance timeline. The episode closes with a grounded take on enforcement and the famously large fines, reassuring listeners that the CRA, while ambitious, is fundamentally reasonable and manageable for manufacturers willing to take cybersecurity seriously.</p>  <p><i></i></p>  <p><b>Ode to Resilience </b><b>is hosted by</b></p>  <p><b></b></p>  <p><b>Piet De Vaere: </b>Electrical Engineer, CRA consultant &amp; Member of the CRA Expert Group (<a href="https://www.linkedin.com/in/devaere/">Linkedin</a> | <a href="https://devae.re">Webpage</a>)</p>  <p>and</p>  <p><b></b></p>  <p><b>August Bournique: </b>Silicon Valley technology lawyer, CRA consultant &amp; Special Rapporteur for ETSI CRA standards (<a href="https://www.linkedin.com/in/august-bournique-668b66165/">Linkedin</a> | <a href="https://bourniquelaw.com/">Webpage</a>)</p>  <p>You can reach out to us on: <a href="mailto:podcast@productsecurity.ch">podcast@productsecurity.ch</a></p>]]></description>
    	            <pubDate>Fri, 10 Jul 2026 04:00:00 +0000</pubDate>
			<itunes:explicit>no</itunes:explicit>
		            <itunes:keywords>CRA, Cyber Resilience Act, EU regulation, product security, cybersecurity, products with digital elements, software regulation, secure development lifecycle, vulnerability management, vulnerability reporting, support period, market surveillance, CE marking, compliance, manufacturer obligations, EU market, enforcement, fines</itunes:keywords>
            		<itunes:author>Piet De Vaere &amp; August Bournique</itunes:author>
            	        </item>
        </channel>
</rss>