Back to the list of services

Online training course: CRA Manager - Managing compliance with the cyber resilience act

18.09.2026
💡 This program is part of CRA Academy – Cyber Resilience Act
Purpose

The CRA Manager program is intended for managers and responsible persons who manage the organization's compliance with the requirements of the Cyber Resilience Act. The program addresses management responsibilities, risk management, compliance strategies, oversight of the product life cycle and cooperation with regulatory authorities. Special emphasis is placed on designing an effective management system that enables the long-term compliance of products and the organization.

Training Delivery Method

The training is delivered through expert lectures, analysis of practical examples, discussions and management workshops. Participants will address strategic aspects of compliance, risk management, management decision-making and organizational mechanisms for ensuring compliance with CRA requirements. Special attention is given to linking regulatory requirements with the organization's business objectives.

Course Content
1. CRA Governance and Management Responsibility

This module is intended for the management and organizational responsibilities associated with implementing the Cyber Resilience Act (CRA). Participants will become familiar with the principles of product cybersecurity governance and understand the role of management in establishing a framework that enables achievement and maintenance of compliance with regulatory requirements. The module links business objectives, regulatory obligations and security activities through a structured CRA governance framework.
The module introduces management responsibilities, responsibility for product compliance, risk management and product security management throughout the entire life cycle. The obligations of economic operators and Open Source Software Stewards are also presented, together with their role in ensuring product compliance with regulatory requirements. Participants will understand the importance of establishing policies, procedures and responsibilities that enable effective management of security and regulatory requirements.
The content covers resource allocation, management oversight of the implementation of CRA requirements, integration of management activities into the organization's existing processes and the development of a security culture that supports continuous compliance. At the conclusion of the module, participants will understand how the organization's governance structure can effectively support the implementation of CRA requirements and ensure the long-term resilience of products and business operations.

2. Product Life-Cycle Management and Continuous Compliance

This module is intended for managing the security and compliance of products throughout the entire life cycle, from initial development to the end of the support period and withdrawal of the product from the market. Participants will address management activities that enable the maintenance of compliance with the requirements of the Cyber Resilience Act (CRA) after placing a product on the market, with emphasis on continuous monitoring of security and the effectiveness of established controls.

The module focuses on oversight of vulnerability management, planning and implementation of security updates, management of the support period and activities related to monitoring products after they have been placed on the market. An important part of the module describes decision-making procedures concerning corrective measures, communication with users, management of security events and product withdrawal strategies when security risks require additional organizational activities.

The concept of continuous compliance is also presented as an ongoing management activity that requires regular monitoring of regulatory requirements, assessment of the effectiveness of security processes and continual improvement of organizational capabilities. At the conclusion of the module, participants will understand how to establish a management approach that enables the maintenance of security, regulatory compliance and user trust throughout the entire product life cycle.

3. Risk Management, Suppliers and Compliance Strategy

This module is intended for strategic risk and compliance management within the framework of the Cyber Resilience Act (CRA). Participants will gain an understanding of how to identify, assess and control risks that may affect product security, regulatory compliance and the organization's ability to fulfil obligations throughout the entire product life cycle. The module emphasizes linking risk management processes with business objectives and regulatory requirements.
The module explains different categories of risks, including risks related to products, vulnerabilities, suppliers, third parties and regulatory requirements. Participants will become familiar with risk assessment methods, planning of risk treatment and establishing activities for continuous monitoring and reporting on risk status. An important part of the content also provides an overview of the management of suppliers and partners as an important element of product security and maintenance of compliance in the supply chain. The content includes the development of a compliance strategy, preparation of an alignment plan, coordination of different organizational functions and the use of performance indicators to monitor progress. At the conclusion of the module, participants will understand how to manage risks and compliance in a way that enables long-term stability, regulatory compliance and organizational resilience.

4. Market Surveillance, Regulatory Requirements and Organizational Readiness

This module is intended for regulatory oversight and the activities that organizations must carry out to demonstrate and maintain compliance with the Cyber Resilience Act (CRA) after products have been placed on the market. Participants will become familiar with the role of market surveillance authorities, their powers and the ways of cooperating with competent institutions during regulatory reviews and investigations.
The module provides an overview of market surveillance procedures, regulatory oversight and communication with competent authorities, including requirements for submitting documentation, providing evidence of compliance and cooperating in product verification procedures. A key part of the module explains the activities that the organization must carry out in the event of identified nonconformities, including corrective measures, product recall, product withdrawal from the market and the execution of regulatory notifications and other mandatory activities.
The following topics are addressed: sanctions, enforcement measures and the consequences of non-compliance, as well as activities required to prepare the organization for regulatory audits, inspections and other forms of oversight. The module also presents the importance of continuous monitoring of the regulatory environment and maintaining organizational readiness for new requirements and changes in legislation. At the conclusion of the module, participants will understand how to manage relations with regulators effectively and how to ensure the long-term compliance of products and the organization.

Learning Outcomes

Upon completion of the training, participants will:

  • establish a governance framework for compliance with CRA requirements,
  • understand the responsibilities of management and economic operators,
  • manage risks related to products and regulatory requirements,
  • design a compliance strategy and alignment plan,
  • oversee compliance throughout the entire product life cycle,
  • cooperate effectively with regulatory authorities and market surveillance authorities,
  • guide the organization in ensuring long-term compliance and resilience.
Recommended Participants
  • members of the management board,
  • directors,
  • heads of development and quality,
  • heads of information and cybersecurity,
  • heads of business compliance,
  • persons responsible for managing regulatory requirements and compliance.
Prerequisites for Participation

The CRA Manager program is intended for managers, persons responsible for compliance, heads of development, heads of information and cybersecurity and other individuals who assume management responsibilities in ensuring compliance with the Cyber Resilience Act (CRA).

A prerequisite for participation is prior successful completion of the CRA Foundation and CRA Implementer programs or demonstrably comparable knowledge in the area of CRA requirements, their implementation and conformity assessment procedures. Participants are expected to understand regulatory requirements, vulnerability management processes, compliance documentation and basic conformity assessment procedures, as the program focuses primarily on the management, strategic and organizational aspects of implementing the Cyber Resilience Act.

Literature
  • Regulation (EU) 2024/2847 - Cyber Resilience Act
  • European Commission Guidance Documents
  • ENISA Publications related to CRA
  • Relevant European Harmonised Standards
  • Training materials

Additional information: Bojan Varga, phone: (01) 4778 108, e-mail: bojan.varga@siq.si 

We value and reward your loyalty

That is why we are introducing the Loyalty Bonus to reward our loyal participants.

More about loyalty bonus