Introduction to CRA for Product and Cybersecurity Teams
For whom?
For teams responsible for product design, development, cybersecurity and compliance
Course content
Morning:
- Introduction and overview
- Regulatory landscape overview: CRA, CER, NIS2, AI Act, Data Act, Machinery Regulation, ...
- Scope Check: which legislation applies to my product?
Afternoon:
- Deep Dive into CRA and product compliance requirements
- Gap Check: where do we stand today
- Roadmap best practices, frameworks, insights, external information sources
Objectives
TEST
After this training:
- You know the scope and obligations of the Cyber Resilience Act, and you understand which role your organisation takes on: manufacturer, importer or distributor
- You can determine whether your product with digital elements falls under the CRA, and in which risk class
- You know the phased timeline: incident reporting obligation and actively exploited vulnerabilities from 11 September 2026, full compliance requirements from December 2027
- You know what you can already use IEC 62443 for today
- You can position the CRA within the related legislation (NIS2, CER, AI Act, Data Act, Machinery Regulation 2023/1230) and you recognise where they overlap or cross-reference each other
- You know the basics of security by design and by default, the requirements for technical documentation and your support obligations
- You have conducted an initial gap check: where your organisation stands today against the CRA requirements
- You leave with a roadmap in outline, plus frameworks and external information sources to continue working with on your own
Practical information
Take no safety risk
Prices excluding VAT