

1.495,- (excl. btw)

Opleiding


NCOI Learning



Nieuw


The Cyber Resilience Act is getting closer and introduces clear obligations for organisations that place products with digital elements on the European market. This includes software, hardware, connected devices and digital products where cybersecurity is no longer just an added value, but a legal requirement.
In this 2-day training, you learn how to implement the CRA in practice within your organisation. You gain insight into the legal obligations and the technical measures needed to place cyber-resilient, documented and compliant products on the market.
The training does not stop at explaining the legislation. You work concretely on scope, product classification, risk assessment, secure updates, vulnerability handling, reporting obligations, SBOM, conformity assessment and technical documentation.
The training is delivered by a cyber lawyer and a product security expert. This means you approach the CRA from two essential perspectives: legally correct and technically feasible.
By the end of the training, you will have a defensible action plan that you can use immediately within your organisation or advisory practice. The training concludes with an exam. Upon passing, you receive the CRA Lead Implementer certificate.
This training is delivered in English only.
This training is delivered in collaboration with Data Protection Institute.
After completing this training:
This training is intended for professionals who need to understand, apply or implement the Cyber Resilience Act in practice.
It is relevant for CISOs, product security professionals, compliance officers, legal counsels, quality managers, product managers, IT and cybersecurity professionals, consultants and lawyers.
Do you work for a manufacturer, importer or distributor of products with digital elements? This training helps you translate CRA obligations into your products, processes and documentation.
Do you advise clients on cybersecurity, compliance, product safety or technology? This training gives you the knowledge and structure to build out a CRA service line.
No specific prior knowledge is required. If you want to prepare in advance, you can read the text of the CRA, Regulation (EU) 2024/2847, and the European Commission’s FAQ.
Before the start of the training, you will receive targeted preparatory material and a short intake quiz. You may also bring your own product list, so you can work on recognisable cases from your own practice during the training.
The first day lays the foundation and answers the central question: does a product fall within the scope of the CRA and who is responsible for what?
You start with the objectives and rationale of the CRA and its place within the broader EU legal framework. The interaction with NIS2, GDPR, the AI Act and the Radio Equipment Directive is also discussed.
You then explore European harmonisation legislation and the Blue Guide, including concepts such as making available, placing on the market, commercial activity, intended use, reasonably foreseeable use, reasonably foreseeable misuse and substantial modification.
These concepts are key to determining what a product with digital elements is, how to qualify it using the core functionality criterion and how a remote data processing solution fits into the picture.
The day also covers components, the due diligence obligation, the special position of free and open-source software and the different stakeholders involved: manufacturers, quasi-manufacturers, importers, distributors and authorised representatives. It concludes with the key dates and phased entry into force of the CRA.
The second day translates the legal framework into substantive requirements and concrete deliverables.
You start with the essential cybersecurity requirements, including risk assessment, baseline assessment of a product and drawing up an SBOM. You then address the essential vulnerability handling requirements and the design of the corresponding processes.
Reportable situations are also covered: identifying actively exploited vulnerabilities, severe incidents, reporting obligations and the applicable deadlines under the CRA.
You then look at when harmonised standards and certification can be used, what effect they have and how to determine and select the applicable conformity assessment procedure based on the product classification.
The focus then shifts to concrete deliverables: the EU declaration of conformity, technical documentation and information and instructions for the user. The training concludes with enforcement and interaction with supervisory authorities.
The training concludes with an exam. Upon passing, you receive the CRA Lead Implementer certificate. This certificate demonstrates that you have the knowledge needed to translate CRA obligations into products, processes and documentation in a practical, structured and defensible way.
Â
De opleidingen komen in aanmerking voor verschillende subsidies. Handig: zo betaal je zelf maar een deel van het inschrijvingsgeld.
This training is organised in collaboration with Data Protection Institute.
This training is delivered in English only.
Before the start of the training, you will receive targeted preparatory material and a short intake quiz. You may also bring your own product list, so you can work on recognisable cases from your own practice during the training.
Participants receive a printed syllabus and digital tools and templates that support the practical implementation of the CRA.

