CRA — Cyber Resilience Act: Manufacturer Obligations (CE)
A two-day training on the Cyber Resilience Act (CRA): obligations for manufacturers of products with digital elements placed on the EU market, security by design, the duty to report actively exploited vulnerabilities within 24 hours, and CE marking.
The CRA turns product security into a market-entry requirement
The Cyber Resilience Act introduces what EU product law had been missing — mandatory cybersecurity requirements for products with digital elements, conditioning the CE marking. A manufacturer who fails to meet these requirements will not be able to legally place a product on the EU market. The training starts by clearly establishing which of the organization’s products are in scope and which risk category they fall into.
Security across the whole lifecycle, not just at launch
The CRA requires vulnerability management and the issuing of security updates throughout the product’s support period, not only at the point of placing it on the market. The workshop walks through building a vulnerability-handling process capable of meeting the 24-hour deadline for reporting actively exploited vulnerabilities — one of the most demanding elements of the regulation.
From technical documentation to CE marking
The final module translates the requirements into a concrete compliance path: the contents of the technical documentation, the choice between self-assessment and involving a notified body, and the EU declaration of conformity leading to CE marking. We also show how to use an existing AppSec/DevSecOps programme as a starting point instead of building compliance from scratch.
Benefits
- Understand the scope of the CRA and which of the organization's products fall under it
- Implement security-by-design and security-by-default requirements across the product lifecycle
- Build a process for reporting actively exploited vulnerabilities within 24 hours
- Prepare technical documentation and a CE marking procedure for a product with digital elements
Who is this training for?
Prerequisites
- Basic familiarity with a product or software development process
Training program
CRA scope and product categories
- Regulation (EU) 2024/2847 — its purpose and place in EU product law
- Products with digital elements covered by the regulation (hardware and software)
- Product categories: default, important (class I and II), and critical
- Timeline: main manufacturer obligations from December 2027, reporting obligation earlier
Security by design and essential requirements
- Essential cybersecurity requirements from Annex I
- Secure by default and minimizing the attack surface
- Vulnerability management throughout the product's support period
- Product cybersecurity risk assessment and its documentation
The obligation to report vulnerabilities and incidents
- Reporting actively exploited vulnerabilities within 24 hours to ENISA/CSIRT
- Reporting severe incidents affecting product security
- The vulnerability handling process and issuing security updates
- Coordinated vulnerability disclosure
Technical documentation and CE marking
- The contents of the technical documentation required by the CRA
- Conformity assessment: self-assessment vs involvement of a notified body (important/critical products)
- The EU declaration of conformity and CE marking for a product with digital elements
- Mapping an existing product security programme onto CRA requirements
Delivery Methods
Online
- Convenience of participating from anywhere
- Interactive live sessions with trainer
- Materials available for 30 days
- No travel costs
On-site
- Direct contact with trainer and group
- Intensive hands-on workshops
- Networking with other participants
- Full focus on learning
Frequently asked questions
Which products are subject to the Cyber Resilience Act?
The CRA covers products with digital elements placed on the EU market — both hardware (such as IoT devices, routers) and software — whose function includes a direct or indirect connection to a network or device. The regulation divides products into default, important (class I and II), and critical, with increasing conformity assessment requirements. In the training we determine which category your organization's products fall into.
When do the CRA requirements apply?
Regulation (EU) 2024/2847 has entered into force, but its obligations apply in stages: the obligation to report actively exploited vulnerabilities and severe incidents starts earlier, while the main manufacturer obligations (security by design, documentation, CE marking) apply from December 2027. In the training we cover this timeline and show how to use the time to prepare.
What does the 24-hour vulnerability reporting obligation mean?
The CRA requires manufacturers to report an actively exploited vulnerability (one already being used in attacks) within 24 hours of discovering it — an early warning to the relevant CSIRT and ENISA, followed by more detailed reports later. In the workshop we build a vulnerability-handling process capable of meeting this deadline.
Does every product require a notified body in the conformity assessment?
No — for default products, the CRA allows self-assessment of conformity by the manufacturer, whereas for important class II and critical products, involvement of a notified body or use of appropriate certification schemes is required. In the training we help classify the product and select the right conformity assessment path.
How does the CRA relate to an AppSec/DevSecOps programme we already have?
An existing application security programme (SAST/DAST/SCA, vulnerability management) provides a solid foundation for CRA requirements, but the CRA goes further — adding formal obligations for technical documentation, conformity assessment, and CE marking, plus a hard vulnerability reporting deadline. In the training we show how to map an existing programme onto CRA requirements and fill the missing pieces.
Request a quote
Funding Options
Check funding options for your company
Development Services Database
Up to 80% funding for SMEs from EU funds
Check availabilityNational Training Fund
Up to 100% funding for employers
Learn moreTrusted by
We train teams at Poland's largest companies
Interested in this training?
Contact us - we'll prepare an offer tailored to your organization's needs.