Cybersecurity & Product Security: EU Cyber Resilience Act (CRA) – Implementation and Compliance - Training
The Cybersecurity & Product Security: EU Cyber Resilience Act (CRA) – Implementation & Compliance course provides a comprehensive introduction to the EU Cyber Resilience Act and guides participants on how to implement its requirements effectively within their organizations.
-
After completing this course, you will be able to:
-
Understand the objectives and key requirements of the Cyber Resilience Act
-
Identify which products and organizations are affected by the CRA
-
Recognize the obligations for manufacturers, importers, and distributors
-
Apply risk-based approaches to cybersecurity
-
Conduct practical risk analyses for products containing digital elements
-
Design efficient processes for incident management and vulnerability handling
-
Ensure timely and compliant reporting of cybersecurity incidents
-
Integrate cybersecurity requirements across the entire product lifecycle
-
Understand the interconnections between CRA, NIS2, and existing standards
-
All content aligns with the latest requirements of the EU Cyber Resilience Act (CRA)
Course Content
This hands-on course covers:
-
1 | Introduction
-
- Motivation
- Definitions of terms with examples
- Explanation of intended use, foreseeable use, and foreseeable misuse
- Basic cybersecurity requirements
- Categorization of products
- Technical cybersecurity requirements in practice
- Implementation of process requirements
- Obligations of manufacturers and producers
- Reporting obligations
- Technical and user documentation
- Risk assessment
- Methodology of a risk assessment process, from core functions through risk identification and the specification of CS objectives to the derivation of cybersecurity requirements
- Exceptions and relevance
- Timeline
- Assessment framework
- Interfaces
- NIS2, ISO 27001, Machinery Directive, …
- Motivation
-
2 | Overview
-
- CRA Overview
- Basic Requirements
-
3 | Specialized Knowledge
-
- Definitions and Context
- Structures in the EU
- Checklists for Implementing CRAs
-
4 | Deep Dive
-
- Key Articles in Detail
- Deep Dive: Requirements for Manufacturers and Producers
- Deep Dive: Technical and Procedural Requirements (Annex)
- Clarification of Definitions
- Definition Chains
-
5 | Summary
Target Audience
-
Product Managers
-
Project Leaders
-
Quality and Compliance Officers
-
IT Security Officers and Risk Managers
-
Manufacturers, Importers, and Distributors
-
Also suitable for: Legal professionals, Auditors, Consultants
Additional Information

Dr. Thomas Liedtke
An experienced cybersecurity and compliance expert with a strong focus on regulatory-driven security engineering approaches. Proven expertise in translating complex cybersecurity standards and regulatory requirements into practical implementation models for OEMs and suppliers. Active in consulting, training, and strategic support with a focus on cybersecurity governance, risk management, and compliance in highly regulated industries.
→ Certificate
2-day training course: Optional opportunity to take the EuroSPI certification exam
-
2 days
-
Optional: EuroSPI Certificate Examination
-
German or English
-
On-site or remote
-
CHF 1'700.- + VAT (remote)

-
Michelle-Dominique Fees
-
This email address is being protected from spambots. You need JavaScript enabled to view it.