W3C, threat modeling, and the CRA: a report from GDC 2026

Imported from official source

Announcement

Cybersecurity Classified by Officially

GDC 2026 attendees, credit: GDC

On Sep 2, 2026, I took part in the Global Digital Collaboration Conference (GDC 2026) in Geneva, contributing to the panel “Operationalizing the Cyber Resilience Act: What manufacturers, Open Source stewards and security teams need now.” together with contributors from ETSI and Red Hat.

In his earlier post about GDC, Simone Onofri described the collaboration between standards organizations, implementers, and other communities that W3C brings to the conference. At the panel, I presented my contribution to ETSI EN 304 617, the draft European harmonized standard that provides cybersecurity requirements and assessment criteria for browsers under the Cyber Resilience Act (CRA).

The ETSI rapporteur responsible for EN 304 617 contacted W3C for feedback, and Simone Onofri, Luca Lumini, and I responded as participants in the W3C Security Interest Group (SING), signing our joint comments individually. ETSI then decided to restructure the draft, and I contributed to that work, as we described at the W3C breakout session in March 2026.

Bringing threat modeling into standards early

The thesis I presented argued that threat modeling should be integrated into technical standardization from the earliest stages. In the industry, it helps bring security and privacy considerations into technology development while mitigations can still be applied. The same reasoning applies to web and ICT standards, where threat modeling allows us to examine potential problems prior to ecosystem-wide adoption.

I introduced existing W3C efforts to bring threat and harm modeling into technical standardization, including the Threat Modeling Guide, the Threat Model for the Web, and the Threat Model for Decentralized Credentials. These are W3C Group Note Drafts, developed to help examine systems, identify threats and harms, and consider responses.

From a review comment to the revised browser draft

This is an extract. The publication continues at the source.

Read the original at the source: https://www.w3.org/blog/2026/w3c-threat-modeling-and-the-cra-a-report-from-gdc-2026/

Officially imported this from World Wide Web Consortium’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
World Wide Web Consortium — imported from official source
Official source
https://www.w3.org/blog/feed/ RSS
Imported
September 18, 2026 17:30
Versions
1 recorded
Identity
https://www.w3.org/blog/2026/w3c-threat-modeling-and-the-cra-a-report-from-gdc-2026/

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.