EU Cyber Resilience Act (CRA)
A structured and practical introduction to the EU Cyber Resilience Act — from the regulatory rationale to what it means for your product development.
- Modules
- 4
- Level
- Foundation to practitioner
- Formats
- Online package, classroom
- Based on
- EU Cyber Resilience Act (Regulation (EU) 2024/2847) · NIS2 Directive
The Cyber Resilience Act (CRA) represents a major shift in how the European Union regulates the security of digital products. As cyber threats become more sophisticated and interconnected systems increasingly define modern life, the CRA fundamentally changes expectations around cybersecurity, shifting responsibility towards proactive, lifecycle-based security.
This course guides you from the regulatory rationale behind the Act to its real-world implications for organisations that design, develop, and place digital products on the EU market. Rather than treating legal requirements in isolation, it connects regulatory concepts with product development realities — showing how cybersecurity, risk management, documentation, and conformity fit together as part of a single compliance framework.
The course opens with a foundations module for participants without a technical security background — those who already have one can skim it — so mixed audiences of engineers, product managers, and compliance specialists can take it together.
Who it is for
Anyone involved in placing products with digital elements on the EU market: software engineering, product management, and security governance. Module 0 provides a cybersecurity primer for participants without a technical security background.
What you will learn
- Explain what the CRA requires, who it applies to, and how it relates to NIS2 and the wider EU product regulation landscape.
- Determine whether a product is in scope, and which product category it falls into.
- Identify which economic operator role your organisation holds — and when importers and distributors are treated as manufacturers.
- Work through the essential cybersecurity requirements of Annex I and the vulnerability handling requirements that accompany them.
- Determine a defensible support period and meet the 24-hour, 72-hour, and 14-day reporting obligations.
- Produce the user-facing documentation of Annex II and the technical documentation of Annex VII.
- Build a proportionate, iterative implementation roadmap instead of treating compliance as a one-off project.
Course outline
Each module is divided into short sections, and ends with a knowledge-check quiz so learners can assess their own progress. Every section also works as a standalone reference.
Module 0: Cybersecurity foundations
A primer on foundational cybersecurity concepts for participants without a technical security background. It introduces the terminology and principles used throughout the rest of the course, and can be skimmed by those who already have a security background.
Sections
- Why cybersecurity matters
- The CIA triad
- Authentication, authorisation, and access control
- Cryptographic protection basics
- Vulnerabilities, exploits, and patches
- Attack surface and threat landscape
- Secure-by-design and secure-by-default
- Software supply chain and SBOMs
- Security testing overview
- Incident response basics
- CE marking and EU product regulation
- Coordinated Vulnerability Disclosure
- Knowledge check
Module 1: Overview of the Cyber Resilience Act
Introduces the CRA and situates it within the wider EU cybersecurity and regulatory landscape, providing the conceptual foundation needed for the rest of the course.
Sections
- Overview of the CRA
- Key requirements under the CRA
- CRA and NIS2
- Timeline
- Products in scope
- Products out of scope
- Knowledge check
Module 2: Cybersecurity requirements and manufacturer obligations
Who is responsible for what under the CRA, and what concrete obligations apply when placing a product with digital elements on the EU market.
Sections
- Economic operators under the CRA
- When importers and distributors are treated as manufacturers
- Open-source software and OSS stewards under the CRA
- Risk assessment
- Essential cybersecurity requirements
- Vulnerability handling
- Determining the support period
- Vulnerability reporting
- Information and instructions to the user
- Technical documentation
- Penalties for non-compliance
- Knowledge check
Module 3: Practical insights and implementation advice
Translates legal and technical requirements into actionable implementation guidance, focusing on lifecycle-based and iterative compliance.
Sections
- Implementation roadmap
- Product portfolio analysis
- Cybersecurity risk, defect, and vulnerability management
- Product security context and asset identification
- Security issue identification
- Risk analysis, evaluation, and treatment
- Security requirements
- Secure development practices
- Other strategic considerations
- Knowledge check
How to take this course
Online learning package
Self-paced, taken whenever it suits the learner, with a knowledge check at the end of every module. Also available as a SCORM package for your own learning management system.
Classroom training
Delivered on site or remotely by an experienced Cyberismo consultant, with the emphasis of each module tailored to your audience, your products, and your obligations. Priced per engagement.
You can read through the complete content of this course in our online service before deciding whether to purchase it. Access to the preview service is licensed per customer — get in touch and we will set it up for your organisation.
Ask for preview accessOther Cyberismo courses
- Developing Secure Software Fundamentals — Practical fundamentals of developing secure software for developers, DevOps professionals, and software engineers.
- Vulnerability Management — Establish and operate a vulnerability management process for software products, based on IEC 62443-4-1.