← Back to Learning

EU Cyber Resilience Act (CRA)

A structured and practical introduction to the EU Cyber Resilience Act — from the regulatory rationale to what it means for your product development.

Modules
4
Level
Foundation to practitioner
Formats
Online package, classroom
Based on
EU Cyber Resilience Act (Regulation (EU) 2024/2847) · NIS2 Directive

The Cyber Resilience Act (CRA) represents a major shift in how the European Union regulates the security of digital products. As cyber threats become more sophisticated and interconnected systems increasingly define modern life, the CRA fundamentally changes expectations around cybersecurity, shifting responsibility towards proactive, lifecycle-based security.

This course guides you from the regulatory rationale behind the Act to its real-world implications for organisations that design, develop, and place digital products on the EU market. Rather than treating legal requirements in isolation, it connects regulatory concepts with product development realities — showing how cybersecurity, risk management, documentation, and conformity fit together as part of a single compliance framework.

The course opens with a foundations module for participants without a technical security background — those who already have one can skim it — so mixed audiences of engineers, product managers, and compliance specialists can take it together.

Who it is for

Anyone involved in placing products with digital elements on the EU market: software engineering, product management, and security governance. Module 0 provides a cybersecurity primer for participants without a technical security background.

What you will learn

Course outline

Each module is divided into short sections, and ends with a knowledge-check quiz so learners can assess their own progress. Every section also works as a standalone reference.

Module 0: Cybersecurity foundations

A primer on foundational cybersecurity concepts for participants without a technical security background. It introduces the terminology and principles used throughout the rest of the course, and can be skimmed by those who already have a security background.

Sections

  • Why cybersecurity matters
  • The CIA triad
  • Authentication, authorisation, and access control
  • Cryptographic protection basics
  • Vulnerabilities, exploits, and patches
  • Attack surface and threat landscape
  • Secure-by-design and secure-by-default
  • Software supply chain and SBOMs
  • Security testing overview
  • Incident response basics
  • CE marking and EU product regulation
  • Coordinated Vulnerability Disclosure
  • Knowledge check

Module 1: Overview of the Cyber Resilience Act

Introduces the CRA and situates it within the wider EU cybersecurity and regulatory landscape, providing the conceptual foundation needed for the rest of the course.

Sections

  • Overview of the CRA
  • Key requirements under the CRA
  • CRA and NIS2
  • Timeline
  • Products in scope
  • Products out of scope
  • Knowledge check

Module 2: Cybersecurity requirements and manufacturer obligations

Who is responsible for what under the CRA, and what concrete obligations apply when placing a product with digital elements on the EU market.

Sections

  • Economic operators under the CRA
  • When importers and distributors are treated as manufacturers
  • Open-source software and OSS stewards under the CRA
  • Risk assessment
  • Essential cybersecurity requirements
  • Vulnerability handling
  • Determining the support period
  • Vulnerability reporting
  • Information and instructions to the user
  • Technical documentation
  • Penalties for non-compliance
  • Knowledge check

Module 3: Practical insights and implementation advice

Translates legal and technical requirements into actionable implementation guidance, focusing on lifecycle-based and iterative compliance.

Sections

  • Implementation roadmap
  • Product portfolio analysis
  • Cybersecurity risk, defect, and vulnerability management
  • Product security context and asset identification
  • Security issue identification
  • Risk analysis, evaluation, and treatment
  • Security requirements
  • Secure development practices
  • Other strategic considerations
  • Knowledge check

How to take this course

Online learning package

Self-paced, taken whenever it suits the learner, with a knowledge check at the end of every module. Also available as a SCORM package for your own learning management system.

Classroom training

Delivered on site or remotely by an experienced Cyberismo consultant, with the emphasis of each module tailored to your audience, your products, and your obligations. Priced per engagement.

You can read through the complete content of this course in our online service before deciding whether to purchase it. Access to the preview service is licensed per customer — get in touch and we will set it up for your organisation.

Ask for preview access

Other Cyberismo courses