Online training course: CRA Foundation - Fundamentals of the Cyber Resilience Act
| 💡 This program is part of CRA Academy – Cyber Resilience Act |
The CRA Foundation program is intended for individuals who wish to gain a fundamental understanding of the requirements of the Cyber Resilience Act (CRA) and its impact on the development, placing on the market and maintenance of products with digital elements. The training enables participants to understand the European Union regulatory framework, the key concepts and terminology introduced by the CRA, and the basic obligations of economic operators involved in the product life cycle. The program explains the fundamental cybersecurity requirements, the roles and responsibilities of manufacturers, authorized representatives, importers, distributors and other economic operators, and requirements related to vulnerability management, incident reporting and conformity assessment. An important part of the program covers understanding of the product life cycle and the regulatory activities that organizations must carry out to ensure compliance with the Regulation.
The training is delivered in the form of expert lectures, guided discussions and practical examples that enable participants to understand the requirements of the Cyber Resilience Act. The training focuses on explaining key regulatory concepts, understanding the roles of individual economic operators and linking the requirements of the Regulation with practical examples of products with digital elements. Through the training, participants gain an overview of the entire product life cycle and the key obligations related to its compliance.
This module provides a fundamental understanding of the Cyber Resilience Act (CRA) and its role in strengthening the cybersecurity of products with digital elements on the European Union market. Participants will gain an understanding of the reasons for adopting the Regulation, the regulatory objectives that the European Union seeks to achieve, and the cybersecurity challenges that led to the establishment of a single legislative framework for digital products. Special attention is given to the scope of application of the Regulation, including the types of products covered by CRA requirements, the boundaries of application and links with other important European regulations. The module explains the relationship between the CRA, the NIS2 Directive, the RED Directive and the Artificial Intelligence Act (AI Act), so that participants understand the position of the CRA in the broader regulatory environment of the European Union.
The module presents the key terms and definitions needed for a proper understanding of the requirements of the Regulation, including products with digital elements, economic operators and basic cybersecurity concepts. Upon completion of the module, participants will gain a comprehensive overview of the product life cycle in accordance with the Cyber Resilience Act, from planning and development to placing on the market, maintenance, security updates and the end of the support period, which forms the basis for understanding the content of the remaining program modules.
This module describes the roles, responsibilities and regulatory obligations of economic operators involved in placing products with digital elements on the European Union market in accordance with the requirements of the Cyber Resilience Act (CRA). Participants will learn about the different categories of operators defined by the Regulation and understand how their responsibilities differ depending on their role in the supply and distribution chain.
The module specifically addresses manufacturers, authorized representatives, importers and distributors and their tasks in ensuring product compliance with CRA requirements. The module also explains the concept of economic operators and the requirements concerning identification, traceability and availability of information that enable effective market surveillance.
The role of Open Source Software Stewards is also addressed as a special category of operators formally introduced for the first time by the CRA. Participants will understand their obligations in the field of vulnerability management, cooperation with competent authorities and support for the security of open-source solutions.
At the conclusion of the module, participants will be able to identify the responsibilities of individual economic operators, understand their role in ensuring product compliance and explain the requirements for cooperation with market surveillance authorities and other competent institutions.
This module presents the fundamental cybersecurity requirements that the Cyber Resilience Act (CRA) establishes for products with digital elements. Participants will become familiar with the Essential Cybersecurity Requirements, which represent the central part of the Regulation and define the minimum level of security that products must provide throughout the entire life cycle.
Special attention is given to the principles of Security by Design and Security by Default, which require manufacturers to incorporate security measures already in the planning, development and configuration phases of products. The module also explains the importance of risk management as an ongoing activity that enables the identification, assessment and treatment of cyber risks associated with the product.
The module presents requirements concerning secure configuration, data protection, access control and user authentication. Measures to ensure product resilience against cyberattacks are also addressed, as well as manufacturers' obligations regarding the provision of security updates and remediation of identified vulnerabilities. The conclusion of the module enables participants to understand the key security requirements of the Cyber Resilience Act and their role in ensuring product compliance and cybersecurity on the European market.
This module introduces the activities that manufacturers and other economic operators must carry out after product development in order to ensure compliance with the requirements of the Cyber Resilience Act (CRA). Participants will become familiar with obligations in the field of vulnerability management, including their identification, assessment, remediation and reporting to competent authorities where required by the Regulation.
A key part of the module focuses on procedures for reporting security incidents and actively exploited vulnerabilities, the role of ENISA and CSIRT bodies, and the deadlines that manufacturers must observe when reporting. The module also explains requirements related to product conformity assessment, including various assessment procedures, the role of Notified Bodies and the criteria for demonstrating product compliance with the requirements of the Regulation.
Technical documentation, records and logs that serve as evidence of compliance are also addressed, as well as the procedure for preparing the EU Declaration of Conformity and using the CE marking. At the conclusion of the module, participants will understand the conditions for placing products on the European Union market, obligations after placing a product on the market and the activities required to maintain compliance throughout the entire product life cycle.
Upon completion of the training, participants will:
- understand the purpose and objectives of the Cyber Resilience Act,
- identify the products and services covered by the CRA,
- distinguish the roles and responsibilities of individual economic operators,
- understand the fundamental cybersecurity requirements for products,
- explain the requirements concerning vulnerability management and incident reporting,
- understand the basic conformity assessment procedures,
- explain the conditions for placing products on the European Union market.
- product managers,
- software developers,
- information and cybersecurity professionals,
- business compliance professionals,
- quality professionals,
- employees of manufacturers, importers and distributors of digital products,
- anyone who wishes to gain a fundamental understanding of CRA requirements
No special prerequisites are prescribed for participation in the CRA Foundation program. The program is designed as an entry-level training program and is suitable for all individuals who wish to gain a fundamental understanding of the requirements of the Cyber Resilience Act (CRA) and its impact on products with digital elements.
Basic knowledge of information or cybersecurity is recommended, as this facilitates understanding of the security concepts, terminology and regulatory requirements addressed by the program. Prior experience in software development, compliance management or cybersecurity is not mandatory.
- Regulation (EU) 2024/2847 - Cyber Resilience Act
- European Commission Guidance Documents
- ENISA Publications related to CRA
- Relevant European Harmonised Standards
- Training materials
Additional information: Bojan Varga, phone: (01) 4778 108, e-mail: bojan.varga@siq.si
-
Please inform me of the next dateDates: 16.09.2026ID: 20062Please choose a dateRegistration
-
Duration:
1 Day (09:00 - 16:00)
8 school hours - Lecturer: Davorin Kacian, MSc
- Number of vacancies:
- Registration fee: 405,00 EUR (does not include VAT) Early Bird until 26. 08. 2026 0 EUR (does not include VAT)
We value and reward your loyalty
That is why we are introducing the Loyalty Bonus to reward our loyal participants.
More about loyalty bonus