Skip to main content

Cybersecurity & Product Security: EU Cyber Resilience Act (CRA) – Implementation and Compliance - Training

The Cybersecurity & Product Security: EU Cyber Resilience Act (CRA) – Implementation & Compliance course provides a comprehensive introduction to the EU Cyber Resilience Act and guides participants on how to implement its requirements effectively within their organizations.

  • After completing this course, you will be able to:
  • Understand the objectives and key requirements of the Cyber Resilience Act
  • Identify which products and organizations are affected by the CRA
  • Recognize the obligations for manufacturers, importers, and distributors
  • Apply risk-based approaches to cybersecurity
  • Conduct practical risk analyses for products containing digital elements
  • Design efficient processes for incident management and vulnerability handling
  • Ensure timely and compliant reporting of cybersecurity incidents
  • Integrate cybersecurity requirements across the entire product lifecycle
  • Understand the interconnections between CRA, NIS2, and existing standards
  • All content aligns with the latest requirements of the EU Cyber Resilience Act (CRA)


Course Content

This hands-on course covers:

  • 1 | Introduction
    • Motivation
      • Definitions of terms with examples
      • Explanation of intended use, foreseeable use, and foreseeable misuse
    • Basic cybersecurity requirements
      • Categorization of products
      • Technical cybersecurity requirements in practice
      • Implementation of process requirements
      • Obligations of manufacturers and producers
      • Reporting obligations
      • Technical and user documentation
    • Risk assessment
      • Methodology of a risk assessment process, from core functions through risk identification and the specification of CS objectives to the derivation of cybersecurity requirements
    • Exceptions and relevance
      • Timeline
      • Assessment framework
    • Interfaces
      • NIS2, ISO 27001, Machinery Directive, …
  • 2 | Overview
    • CRA Overview
    • Basic Requirements
  • 3 | Specialized Knowledge
    • Definitions and Context
    • Structures in the EU
    • Checklists for Implementing CRAs
  • 4 | Deep Dive
    • Key Articles in Detail
    • Deep Dive: Requirements for Manufacturers and Producers
    • Deep Dive: Technical and Procedural Requirements (Annex)
    • Clarification of Definitions
    • Definition Chains
  • 5 | Summary

Target Audience

This course is designed for professionals and managers responsible for products with digital components:
  • Product Managers
  • Project Leaders
  • Quality and Compliance Officers
  • IT Security Officers and Risk Managers
  • Manufacturers, Importers, and Distributors
  • Also suitable for: Legal professionals, Auditors, Consultants

Additional Information

→ Trainer

Dr. Thomas Liedtke

An experienced cybersecurity and compliance expert with a strong focus on regulatory-driven security engineering approaches. Proven expertise in translating complex cybersecurity standards and regulatory requirements into practical implementation models for OEMs and suppliers. Active in consulting, training, and strategic support with a focus on cybersecurity governance, risk management, and compliance in highly regulated industries.

→ Prerequisites
A basic understanding of IT, product development, or regulatory requirements is beneficial. No prior knowledge of the Cyber Resilience Act (CRA) is required.
→ Documentation
Participants receive comprehensive course materials, practical examples, and templates.

→ Certificate

2-day training course: Optional opportunity to take the EuroSPI certification exam

Key Facts:
  • 2 days
  • Optional: EuroSPI Certificate Examination
  • German or English
  • On-site or remote
  • CHF 1'700.- + VAT (remote)

All rights reserved
- ©SYNSPACE Switzerland GmbH