Training

EU CRA Practitioner Training

The first CRA deadline is 11 September 2026. Is your team ready?
Intensive 1-day workshop for up to 25 people, available onsite and remote. Your team maps CRA obligations to the products, processes, and documents they already own.

Why

Benefits

The EU Cyber Resilience Act is coming. Make sure your team is ready before the deadline hits.

Understand Your Obligations

The CRA introduces far-reaching legal requirements for software and hardware manufacturers. Your team maps the obligations that apply to your products, from notification timelines to conformity assessment.

Be Ready for the September 2026 Deadline

Notification obligations under the CRA take effect on 11 September 2026. Your vulnerability handling processes, incident detection, and reporting workflows need to be in place before that date. This training shows which workflows, roles, and evidence your team needs.

Implement Secure-by-Design from Day One

The CRA mandates secure-by-design and secure-by-default for all products with digital elements. Your team will learn the ENISA-endorsed principles and how to apply them to your existing architecture and development processes.

Conduct Your Own Self-Assessment

Some products can use the CRA self-assessment route. This training walks your team through that process, including how to write a valid Declaration of Conformity and which technical documentation you must maintain.

Reduce Legal and Financial Risk

Noncompliance can result in fines of up to €15 million or 2.5% of global annual turnover. Beyond fines, a poorly handled incident or missing documentation can lead to product withdrawal from the EU market. Build the reporting, documentation, and secure development processes before the deadlines force the issue.

Align Product, Legal, and Engineering

CRA compliance crosses product, engineering, security, compliance, and legal work. The workshop has those teams agree on ownership, timelines, and evidence.

Price

In-Company Practitioner Training

Full-day workshop for up to 25 attendees.

Essentials

€5700 +VAT

Full-day CRA Practitioner workshop covering all obligations, secure-by-design principles, and self-assessment process.

  • Onsite / remote options
  • Printed materials
  • CRA obligations deep dive
  • Notification & incident handling
  • Secure-by-design & secure-by-default
  • SBOM & supply chain obligations
  • CRA self-assessment process
  • Declaration of Conformity walkthrough
Request a quote

Complete

€6900 +VAT

Workshop plus follow-up calls and a focused review of your product documentation.

  • Essentials training, plus:
  • 2 CRA gap assessment follow-up calls (1 hour each)
  • 1 CRA readiness review of your product documentation (2 hours)
Request a quote

Customized

Let's talk

Training adapted to your product class, regulatory context, and team structure.

Schedule a call

Agenda

Topic outline

The EU Cyber Resilience Act at a Glance

  • What is the CRA?
  • Timeline and implementation phases
  • Who is affected: classification of software manufacturers
  • High-level obligations overview
  • Expected fines and enforcement
  • Effects on the open-source software ecosystem

Notification Obligations (11 September 2026)

  • Legal obligations overview
  • Incident detection: sources and triggers
  • Upstream supply chain advisories
  • Internal cybersecurity engagements (pen testing, bug bounty, threat modeling, secure architecture reviews)
  • Public vulnerability databases
  • Incident response fundamentals

Bill of Materials & Vulnerability Management

  • Software Bill of Materials (SBOM)
  • Hardware Bill of Materials (HBOM)
  • Package managers overview
  • Triaging incoming advisories
  • Prioritization
  • Security hotfix and update delivery

External Communication & Reporting

  • Delivering advisories to users
  • Notification to national CERT and ENISA
  • Formal reporting timelines
  • Hotfixes for physical, software, and industrial products

CRA Essential Requirements Deep Dive

  • CRA requirements readout
  • Requirement coverage per security principle
  • CRA self-assessment process

Secure Product Development Lifecycle (11 December 2027)

  • Architecture discovery and risk profiling
  • Threat modeling in the CRA context
  • Security requirements: product and process
  • Baseline assessment with OWASP SAMM
  • Secure-by-design principles from the ENISA Playbook: trust boundaries and least privilege, strong identity and authentication architecture, attack surface minimization, defense in depth, open design, logging, monitoring, alerting, vulnerability management, patch management, and supply chain controls
  • Secure-by-default principles: default hardening, minimization of default services, restrictive initial access, secure communication by default, and unique device identity and secrets by default

Conformity, Documentation & Post-Release

  • Declaration of Conformity: how to write and deliver it
  • Technical Documentation requirements (10-year obligation)
  • User Documentation requirements
  • Staying in touch with your users: communication channels, languages, and timelines
  • 5-year security fixes and hotfixes obligation

What's Next?

  • Team skills and roles needed for CRA compliance
  • Action planning: your organization's next steps
  • Follow-up deep-dive courses available: Threat Modeling Practitioner, Security Architecture, OWASP SAMM Practitioner, Secure Coding / OWASP Top 10, DevSecOps & CI/CD Pipeline Security, SBOM & Supply Chain Security

Public sessions

For Individuals

17 July 2026

09:00 - 17:00 CET

Classroom CRA Practitioner Workshop

🎫 €1000 (per person, excl. VAT)

A full-day onsite workshop. You will map the EU Cyber Resilience Act to concrete processes, documents, and ownership decisions.

KASerne, Willemspoort 1, 5223WV, 's-Hertogenbosch, Netherlands

Reserve a spot

21 August 2026

09:00 - 17:00 CET

Remote CRA Practitioner Workshop

🎫 €800 (per person, excl. VAT)

A full-day remote workshop. You will map the EU Cyber Resilience Act to concrete processes, documents, and ownership decisions.

Online teleconference

Reserve a spot

Details

Trainers

Nariman Aga-Tagiyev

Nariman Aga-Tagiyev

Product Security Architect

Nariman Aga-Tagiyev is an Application Security Architect with more than 20 years of experience in software development. He has worked as a full-stack web application developer, backend developer, DevOps engineer, and cloud developer. Since 2016, he has focused fully on application security work.

Luc Poulin

Luc Poulin

CEO, Senior Information / Application Security & Trustworthiness Advisor at Cogentas inc.

Luc Poulin is a veteran application security expert with a doctorate in software engineering and over four decades of experience in IT. He specializes in integrating and auditing security throughout the application lifecycle and contributes internationally to ISO/IEC standards, including as lead editor of ISO/IEC 27034.

Dagmar Moser

Dagmar Moser

Consultant, Auditor and Lecturer

Dagmar Stefanie Moser is a seasoned IT security expert and founder of blueheads GmbH, with over 25 years of experience in IT architecture, secure software engineering, and information security. She is a certified ISO/IEC 27001 Lead Auditor and guest lecturer at the Hochschule der Bayerischen Wirtschaft (HDBW).

Details

FAQ

1. Why does my team need CRA training now?
The CRA has a phased rollout. The first operational deadline, notification obligations for actively exploited vulnerabilities and severe incidents, lands on 11 September 2026. The Secure Product Development Lifecycle requirements follow on 11 December 2027. Neither timeline leaves much room to build processes from scratch. Teams that start preparing 12 to 18 months before the deadlines will be in a better position than teams starting in the final quarter.
2. Who is this training for?

It works best as a cross-functional session. Bring the people who own the product, security, compliance, and release process.

  • CISOs and Information Security Officers map legal obligations to the controls, evidence, and operating model they need.
  • Compliance Officers, Legal, and Risk Managers come away with a solid grasp of the regulatory framework, the timelines, and what documentation needs to exist.
  • Software Architects and Tech Leads learn how secure-by-design and secure-by-default principles translate into real architectural decisions.
  • Product and Application Managers understand where CRA obligations intersect with product roadmaps, release cycles, and post-release support.
  • Developers and DevOps Engineers see what changes day to day: SBOM generation, vulnerability triaging, and patch delivery timelines.
  • Software Testers understand what CRA-relevant security verification looks like in practice.

No prior CRA knowledge is required.

3. What is the course approach?
The course mixes presentation, discussion, and applied exercises. Participants work through CRA requirements and map them to scenarios from their own products. The day ends with an action-planning session that assigns next steps, owners, and follow-up questions.
4. Does our product fall under the CRA?
The CRA covers all products with digital elements placed on the EU market where there is a reasonably foreseeable consumer or business use. That includes most software products. The main exclusions are products already regulated under sector-specific legislation, such as the Medical Device Regulation, and certain categories of open-source software. The training includes a product classification module so your team can determine which obligations apply to what you ship.
5. What facilities do you need for onsite delivery?
  1. A projector and power outlet for the trainer
  2. Enough space for participants to work in small groups of 3 to 5
  3. A whiteboard or flip chart per group

Participants don't need to bring laptops. All exercises use printed materials.

6. Can the training be delivered remotely?
Yes, for up to 25 participants. Groups work in virtual breakout rooms with trainer support, and reconvene for discussion after each exercise block.

Watch online

EU Cyber Resilience Act in Practice

Make it happen

Request a quote

We’ll prepare a quote for your purchasing team within 24 hours. No spam afterward.

Prefer email? Write to us and we'll get back within one business day.

Email training@securehabits.nl