Understand Your Obligations
The CRA introduces far-reaching legal requirements for software and hardware manufacturers. Your team maps the obligations that apply to your products, from notification timelines to conformity assessment.
Training
The first CRA deadline is 11 September 2026. Is your team ready?
Intensive 1-day workshop for up to 25 people, available onsite and remote. Your team maps CRA obligations to the products, processes, and documents they already own.
Why
The EU Cyber Resilience Act is coming. Make sure your team is ready before the deadline hits.
The CRA introduces far-reaching legal requirements for software and hardware manufacturers. Your team maps the obligations that apply to your products, from notification timelines to conformity assessment.
Notification obligations under the CRA take effect on 11 September 2026. Your vulnerability handling processes, incident detection, and reporting workflows need to be in place before that date. This training shows which workflows, roles, and evidence your team needs.
The CRA mandates secure-by-design and secure-by-default for all products with digital elements. Your team will learn the ENISA-endorsed principles and how to apply them to your existing architecture and development processes.
Some products can use the CRA self-assessment route. This training walks your team through that process, including how to write a valid Declaration of Conformity and which technical documentation you must maintain.
Noncompliance can result in fines of up to €15 million or 2.5% of global annual turnover. Beyond fines, a poorly handled incident or missing documentation can lead to product withdrawal from the EU market. Build the reporting, documentation, and secure development processes before the deadlines force the issue.
CRA compliance crosses product, engineering, security, compliance, and legal work. The workshop has those teams agree on ownership, timelines, and evidence.
Price
Full-day workshop for up to 25 attendees.
€5700 +VAT
Full-day CRA Practitioner workshop covering all obligations, secure-by-design principles, and self-assessment process.
€6900 +VAT
Workshop plus follow-up calls and a focused review of your product documentation.
Let's talk
Training adapted to your product class, regulatory context, and team structure.
Schedule a callAgenda
Public sessions
17 July 2026
09:00 - 17:00 CET
🎫 €1000 (per person, excl. VAT)
A full-day onsite workshop. You will map the EU Cyber Resilience Act to concrete processes, documents, and ownership decisions.
KASerne, Willemspoort 1, 5223WV, 's-Hertogenbosch, Netherlands
Reserve a spot21 August 2026
09:00 - 17:00 CET
🎫 €800 (per person, excl. VAT)
A full-day remote workshop. You will map the EU Cyber Resilience Act to concrete processes, documents, and ownership decisions.
Online teleconference
Reserve a spotDetails
Product Security Architect
Nariman Aga-Tagiyev is an Application Security Architect with more than 20 years of experience in software development. He has worked as a full-stack web application developer, backend developer, DevOps engineer, and cloud developer. Since 2016, he has focused fully on application security work.
CEO, Senior Information / Application Security & Trustworthiness Advisor at Cogentas inc.
Luc Poulin is a veteran application security expert with a doctorate in software engineering and over four decades of experience in IT. He specializes in integrating and auditing security throughout the application lifecycle and contributes internationally to ISO/IEC standards, including as lead editor of ISO/IEC 27034.
Consultant, Auditor and Lecturer
Dagmar Stefanie Moser is a seasoned IT security expert and founder of blueheads GmbH, with over 25 years of experience in IT architecture, secure software engineering, and information security. She is a certified ISO/IEC 27001 Lead Auditor and guest lecturer at the Hochschule der Bayerischen Wirtschaft (HDBW).
Details
It works best as a cross-functional session. Bring the people who own the product, security, compliance, and release process.
No prior CRA knowledge is required.
Participants don't need to bring laptops. All exercises use printed materials.
Watch online
Make it happen
We’ll prepare a quote for your purchasing team within 24 hours. No spam afterward.
Prefer email? Write to us and we'll get back within one business day.
Email training@securehabits.nl