Back to the list of services

Online training course: CRA Implementer - Implementing the requirements of the cyber resilience act

17.09.2026
💡 This program is part of  CRA Academy – Cyber Resilience Act
Purpose

The CRA Implementer program is intended for professionals who will be responsible within the organization for implementing and demonstrating compliance with the requirements of the Cyber Resilience Act. The program describes in detail the implementation of security requirements, vulnerability management, preparation of technical documentation, demonstration of compliance and operational activities required to maintain compliance throughout the entire product life cycle. The program links regulatory requirements with practical activities for the development, maintenance and management of products.

Training Delivery Method

The training combines expert lectures, analysis of regulatory requirements, case studies and practical workshops. Through practical examples, participants will learn about methods for implementing security requirements, preparing documentation, managing vulnerabilities and conformity assessment processes. The training also includes preparing the organization to implement CRA requirements in day-to-day operations.

Course Content
1. Implementation of Product Security Requirements

This module is intended for the practical implementation of the security requirements that the Cyber Resilience Act (CRA) establishes for products with digital elements. Participants will gain an understanding of how to translate regulatory requirements into concrete activities during the planning, development and maintenance of products, with the aim of achieving compliance and an appropriate level of cybersecurity. The focus is on the role of security throughout the entire product life cycle and on incorporating security requirements into development processes from the very beginning.
The module addresses the application of the principles of Security by Design and Security by Default and their connection with the concept of the Secure Development Lifecycle. Participants will become familiar with threat modeling methods, secure programming and the implementation of security controls that enable the reduction of security risks before a product is placed on the market. Requirements concerning secure configuration, identity management, protection of communications and the use of cryptographic mechanisms are also presented.
At the conclusion of the module, participants will understand how to incorporate CRA requirements into product development processes and how to ensure that security becomes an integral part of the technical and organizational activities required to achieve compliance with the Regulation.

2. Vulnerability Management, Reporting and Corrective Measures

This module describes the requirements of the Cyber Resilience Act (CRA) related to vulnerability management, reporting of security events and implementation of corrective measures. The module presents participants with processes that enable the timely identification, assessment and handling of vulnerabilities throughout the entire product life cycle, and with the regulatory obligations arising from the discovery of security deficiencies or security incidents.

A key part of the module introduces requirements for Vulnerability Disclosure, Coordinated Vulnerability Disclosure Policy and reporting of actively exploited vulnerabilities. The module explains in detail the obligations concerning reporting to ENISA, the content of reports, regulatory deadlines and the responsibilities of the organization during the reporting process. Activities related to root-cause analysis of security events, planning corrective measures and monitoring their effectiveness are also addressed.

Participants will also understand the importance of continuous vulnerability monitoring, management of security updates and patches, and maintenance of processes that enable rapid response to new threats. At the conclusion of the module, they will be able to establish activities that support compliance with CRA requirements and contribute to the long-term security of products.

3. Documentation, Evidence and Preparation for Compliance

This module is intended for establishing and maintaining the documentation required to demonstrate product compliance with the requirements of the Cyber Resilience Act (CRA). Because compliance cannot be demonstrated without appropriate records and documented activities, the module provides a detailed overview of the documentation that organizations must prepare, maintain and make available during conformity assessment procedures and market surveillance activities.
Participants will become familiar with product technical documentation, risk assessment documentation, records of vulnerabilities and incidents, and requirements for collecting and managing evidence confirming the implementation of security activities. An important part of the module addresses the establishment of a Software Bill of Materials (SBOM), the keeping of records on security measures and the documentation of activities related to vulnerability management and security updates. The module also presents the content and importance of the EU Declaration of Conformity as one of the key documents in the process of demonstrating compliance. The module also covers requirements concerning document retention, availability of records to competent authorities and preparation of the organization for conformity assessment procedures and regulatory oversight. At the conclusion of the module, participants will understand how to establish a structured documentation system that enables effective demonstration of product compliance throughout the entire life cycle.

4. Conformity Assessment and Operational Maintenance of CRA Requirements

This module connects conformity assessment procedures with the activities required to maintain product compliance throughout the entire life cycle. Participants will gain an overview of the different conformity assessment procedures envisaged by the Cyber Resilience Act (CRA) and understand how to select an appropriate approach depending on the type of product and its classification. The module specifically explains the differences between self-assessment of conformity, procedures carried out by third parties and procedures involving Notified Bodies.
The module provides a detailed explanation of the classification of Important Products and Critical Products and its impact on conformity assessment requirements. Participants will understand conformity assessment procedures, preparation for audits and regulatory reviews, and the activities required to demonstrate ongoing product compliance. Corrective measures that the organization must implement in the event of identified nonconformities or deviations are also addressed.
The second part of the module is dedicated to security throughout the product life cycle, including deployment, maintenance, management of security updates, the support period and the end of the product life cycle. The module then introduces incorporating CRA requirements into organizational processes, allocation of responsibilities, coordination with suppliers and continuous improvement of compliance activities. At the conclusion of the module, participants will understand how to maintain product compliance from the initial conformity assessment to final withdrawal from the market.

Learning Outcomes

Upon completion of the training, participants will:

  • implement CRA requirements in development and operational processes,
  • apply the principles of Security by Design and Security by Default,
  • establish vulnerability management and reporting processes
  • prepare technical documentation and evidence of compliance,
  • understand the requirements concerning SBOM and documentation of security activities,
  • perform conformity assessment activities for products,
  • support the maintenance of compliance throughout the entire product life cycle.
Recommended Participants
  • software developers,
  • information systems architects,
  • cybersecurity professionals,
  • quality professionals,
  • vulnerability management professionals,
  • members of development and technical teams responsible for implementing CRA requirements.
Prerequisites for Participation

The CRA Implementer program is intended for participants who already understand the fundamental requirements of the Cyber Resilience Act (CRA) and wish to acquire knowledge for their practical implementation in the organization.

A prerequisite for participation is prior successful completion of the CRA Foundation program or demonstrably comparable knowledge of the content covered by the Foundation program. Participants must understand the basic concepts of the CRA, the roles of economic operators, the fundamental cybersecurity requirements and the basic conformity assessment procedures. Prior experience in software development, information security, compliance or product management is desirable but not mandatory.

Literature
  • Regulation (EU) 2024/2847 - Cyber Resilience Act
  • European Commission Guidance Documents
  • ENISA Publications related to CRA
  • Relevant European Harmonised Standards
  • Training materials

Additional information: Bojan Varga, phone: (01) 4778 108, e-mail: bojan.varga@siq.si 

We value and reward your loyalty

That is why we are introducing the Loyalty Bonus to reward our loyal participants.

More about loyalty bonus