Training

Cyber Resilience Act – implementation

For manufacturers of connected products: clarify applicability, understand obligations, meet deadlines.

The CRA covers every product with digital elements – and therefore far more companies than expected. The course translates the regulation into concrete tasks along the product lifecycle, drawing on experience from a group-wide CRA implementation across a complete product portfolio.

Request this course

At a glance

Level
Advanced
Duration
1 day
Audience
Product management, development, compliance and management at manufacturers
Format
In-house – on site or remote
Language
German or English

Structure

This is how the course is built up. I agree the order and focus with you in advance, based on your audience and prior knowledge.

  1. Applicability & classification

    Scope of the CRA, product classes and the conformity routes that follow from them.

  2. Obligations & deadlines

    Obligations of manufacturers, importers and distributors plus deadlines and transitional arrangements at a glance.

  3. Security by design in the process

    Threat analysis and risk assessment in development, SBOM and vulnerability management throughout the support period.

  4. Evidence & reporting duties

    Reporting duties to ENISA (24 h / 72 h / final), technical documentation, conformity assessment and CE marking.

Course content

  • Scope: which products fall under the CRA?
  • Product classes and the conformity routes that follow from them
  • Obligations of manufacturers, importers and distributors
  • Deadlines and transitional arrangements at a glance
  • Security by design as a process, not a declaration of intent
  • Threat analysis and risk assessment in the development process
  • SBOM and vulnerability management throughout the support period
  • Reporting duties to ENISA: 24 hours, 72 hours, final report
  • Technical documentation, conformity assessment and CE marking

What you take away

  • Clarity about your own applicability and the product classes
  • A prioritised task list aligned with the deadlines
  • An understanding of which processes need to be created in development

More training courses

Advanced · 1 day including a tabletop exercise

Incident response basics

What happens in the first hours of a security incident – and who makes which decision.

Workshop · 1-day workshop

Creative awareness measures

A workshop for everyone responsible for awareness – and tired of mandatory e-learning.

Interested in “Cyber Resilience Act – implementation”?

Tell me briefly about group size, prior knowledge and your preferred date – I will come back with a proposal including effort.