Cryptography for Product Security: Meeting Cybersecurity CRA and EU AI Act Requirements – Training
The course Cryptography for Product Security: Meeting Cybersecurity CRA and EU AI Act Requirements covers the fundamentals of modern cryptographic methods and their practical application in meeting regulatory requirements under the Cyber Resilience Act (CRA), the EU AI Act, and other security standards.
-
After completing this course, you will be able to:
-
Identify and apply appropriate methods for implementing regulations, such as product security under the Cyber Resilience Act (CRA)
-
Evaluate the advantages and disadvantages of individual methods based on their application (e.g., integrity versus confidentiality)
-
Gain an overview of cryptographic methods and algorithms
-
Understand when to use which methods
-
Identify vulnerabilities and potential attack vectors when evaluating cryptography
Course Content – Practical Implementation & Compliance Strategy
This hands-on course covers:
-
1 | Fundamentals of Cybersecurity & Cryptography
-
- CIA Triad
- Safety vs. Cybersecurity
- Threats and Attacks (Ransomware, Vishing, CEO Fraud, MITM)
- History of Cryptography
- Kerckhoffs' Principle
- Overview of Modern Cryptography
-
2 | Symmetric Encryption
-
- Fundamentals and How It Works
- Block and Stream Ciphers
- AES and Operating Modes (ECB, CBC, CTR)
- One-Time Pad
- Typical Attacks and Vulnerabilities
- Selecting Suitable Methods
-
3 | Hash Functions & Password Security
-
- Properties of Hash Functions
- Collision & Preimage Resistance
- Password Security
- Salt & Pepper
- Rainbow Tables
- Multi-Factor Authentication and TOTP
-
4 | Integrity & Authenticity
-
- Message Authentication Codes (MAC)
- HMAC and CMAC
- Replay Attacks
- Authenticated Encryption
- Encrypt-then-MAC as Best Practice
-
5 | Asymmetric Cryptography & Key Management
-
- Public-Key Cryptography
- RSA and Diffie-Hellman
- Key Exchange
- Digital Signatures
- Cryptography in Modern Products
-
6 | PKI & Certificate Management
-
- Public Key Infrastructure (PKI)
- Certificates and Certificate Authorities
- Chain of Trust
- CRL and OCSP
- Practical Examples from Industry and the Automotive Sector
-
7 | Cryptography in Product Security
-
- Requirements from the CRA and EU AI Act
- Cryptography in the Secure Product Development Lifecycle
- Secure Boot, Firmware Signing, and OTA Updates
- Selecting Suitable Methods for Different Use Cases
- Advantages and Disadvantages of Current Methods
-
8 | The Future of Cryptography
Target Audience
-
Product Security Managers
-
Security Architects and Software/System Architects
-
Cybersecurity Engineers and Software Developers
-
Technical Project Managers and Product Owners with security responsibilities
-
Also suitable for: Compliance and CRA/EU AI Act officers, Risk Managers, IT Security Officers, Auditors, and Cybersecurity Consultants
Additional Information

Dr. Thomas Liedtke
An experienced cybersecurity and compliance expert with a strong focus on regulatory-driven security engineering approaches. Proven expertise in translating complex cybersecurity standards and regulatory requirements into practical implementation models for OEMs and suppliers. Active in consulting, training, and strategic support with a focus on cybersecurity governance, risk management, and compliance in highly regulated industries.
→ Certificate
-
2 days
-
Certificate of completion included
-
German or English
-
On-site or remote
-
CHF 1'700.- + VAT (remote)

-
Michelle-Dominique Fees
-
This email address is being protected from spambots. You need JavaScript enabled to view it.