×
1 Choose EITC/EITCA Certificates
2 Learn and take online exams
3 Get your IT skills certified

Confirm your IT skills and competencies under the European IT Certification framework from anywhere in the world fully online.

EITCA Academy

Digital skills attestation standard by the European IT Certification Institute aiming to support Digital Society development

LOG IN TO YOUR ACCOUNT

CREATE AN ACCOUNT FORGOT YOUR PASSWORD?

FORGOT YOUR PASSWORD?

AAH, WAIT, I REMEMBER NOW!

CREATE AN ACCOUNT

ALREADY HAVE AN ACCOUNT?
EUROPEAN INFORMATION TECHNOLOGIES CERTIFICATION ACADEMY - ATTESTING YOUR PROFESSIONAL DIGITAL SKILLS
  • SIGN UP
  • LOGIN
  • INFO

EITCA Academy

EITCA Academy

The European Information Technologies Certification Institute - EITCI ASBL

Certification Provider

EITCI Institute ASBL

Brussels, European Union

Governing European IT Certification (EITC) framework in support of the IT professionalism and Digital Society

  • CERTIFICATES
    • EITCA ACADEMIES
      • EITCA ACADEMIES CATALOGUE<
      • EITCA/CG COMPUTER GRAPHICS
      • EITCA/IS INFORMATION SECURITY
      • EITCA/BI BUSINESS INFORMATION
      • EITCA/KC KEY COMPETENCIES
      • EITCA/EG E-GOVERNMENT
      • EITCA/WD WEB DEVELOPMENT
      • EITCA/AI ARTIFICIAL INTELLIGENCE
    • EITC CERTIFICATES
      • EITC CERTIFICATES CATALOGUE<
      • COMPUTER GRAPHICS CERTIFICATES
      • WEB DESIGN CERTIFICATES
      • 3D DESIGN CERTIFICATES
      • OFFICE IT CERTIFICATES
      • BITCOIN BLOCKCHAIN CERTIFICATE
      • WORDPRESS CERTIFICATE
      • CLOUD PLATFORM CERTIFICATENEW
    • EITC CERTIFICATES
      • INTERNET CERTIFICATES
      • CRYPTOGRAPHY CERTIFICATES
      • BUSINESS IT CERTIFICATES
      • TELEWORK CERTIFICATES
      • PROGRAMMING CERTIFICATES
      • DIGITAL PORTRAIT CERTIFICATE
      • WEB DEVELOPMENT CERTIFICATES
      • DEEP LEARNING CERTIFICATESNEW
    • CERTIFICATES FOR
      • EU PUBLIC ADMINISTRATION
      • TEACHERS AND EDUCATORS
      • IT SECURITY PROFESSIONALS
      • GRAPHICS DESIGNERS & ARTISTS
      • BUSINESSMEN AND MANAGERS
      • BLOCKCHAIN DEVELOPERS
      • WEB DEVELOPERS
      • CLOUD AI EXPERTSNEW
  • TRENDING
  • SUBSIDY
  • HOW IT WORKS
  •   IT ID
  • ABOUT
  • CONTACT
  • MY ORDER
    Your current order is empty.
EITCIINSTITUTE
CERTIFIED

EITC/IS/CRA Cyber Resilience Act

by EITCA Academy / Sunday, 28 June 2026 / Published in

Current Status

Not Enrolled
Enroll in this programme to get access

Price

€110.00

Get Started

Enrol for this Certification

EITC/IS/CRA Cyber Resilience Act is the European IT Certification programme on applied implementation and operation of Regulation (EU) 2024/2847 for product-security, engineering, assurance, governance, legal, conformity and market professionals.

The curriculum develops practical competence in turning the Cyber Resilience Act into a controlled product-security operating system: determining scope and product boundaries, classifying products and roles, engineering secure-by-design and secure-by-default properties, managing lifecycle and software-supply-chain evidence, handling vulnerabilities and reporting, selecting conformity routes, maintaining technical documentation, supporting market assurance and keeping controls effective through change.

EITC/IS/CRA Cyber Resilience Act complements the full EITCA/IS IT Security Academy and extends EITC/IS/CSF CyberSecurity Fundamentals from general security concepts into regulated product-security decisions, technical implementation and auditable evidence. The programme is designed for cybersecurity experts as well as product managers, software and systems engineers, PSIRT and vulnerability teams, compliance and legal specialists, quality and assurance professionals, importers, distributors, notified-body and market-surveillance stakeholders, and managers responsible for digital products.

The complete learning path comprises six lessons and 30 topics. Learners work with a recurring EuroEdge Systems product portfolio and progressively construct a CRA Product Compliance and Cybersecurity Assurance Dossier that can support release, third-party assessment, authority response, field action and lifecycle reassessment.

The programme uses a recurring professional loop: scope → assess → engineer → verify → release → monitor → respond → assure → reassess. Legal text is translated into product-specific decisions, controls and evidence without reducing cybersecurity to legal memorisation or a checklist exercise.

  • Product and legal-factual model: identify the exact product, version, intended purpose, digital and remote-processing boundary, economic operators, open-source relationships, applicable exclusions, classification and adjacent regulatory interfaces.
  • Risk and architecture: connect threat actors, weaknesses, trust boundaries and attack paths to Annex I requirements, security invariants, secure defaults, resilience behaviour, logging, recovery and verification.
  • Lifecycle and supply chain: operate a Product Security Management System, control suppliers and open-source dependencies, create useful SBOM and VEX evidence, protect builds and signing, deliver secure updates and plan support and end-of-support transitions.
  • Vulnerability and field operation: run coordinated vulnerability disclosure and PSIRT case management, assess Article 14 thresholds and deadlines, coordinate multi-regime facts, communicate with users and measure corrective-action effectiveness across the installed base.
  • Conformity and market assurance: map requirements to standards and evidence, choose a justified conformity route, maintain Annex VII technical documentation, control declarations and CE marking, support importers and distributors, and respond to authorities.
  • Continuous assurance and AI-era change: define evidence freshness, management review and reopen triggers; govern substantial-modification candidates; automate repeatable facts without automating accountability; and constrain and evaluate AI-enabled product functions.

The learning activities produce practical artefacts rather than only notes: product-boundary and role records, classification and route memoranda, Annex I applicability and risk registers, threat models and security invariants, secure-default specifications, release gates, supplier and dependency records, SBOM/VEX decisions, provenance and update controls, support-period plans, CVD and PSIRT workflows, Article 14 timelines, field-action dashboards, standards crosswalks, technical-file indexes, declaration and marking controls, market-surveillance response packs, continuous-control registers, change passports, evidence-pipeline records and AI security annexes.

  • Lesson 1: CRA operating model, scope, roles, product classification and governance.
  • Lesson 2: Risk-based secure-by-design engineering and essential product properties.
  • Lesson 3: Secure product lifecycle, supply chain, SBOM and update operations.
  • Lesson 4: Vulnerability handling, Article 14 reporting, post-market monitoring and crisis operation.
  • Lesson 5: Standards, conformity assessment, technical documentation and market assurance.
  • Lesson 6: Continuous CRA control operation, secure change, assurance automation and AI-era products.

EITC/IS/CRA assumes the general security literacy developed by EITC/IS/CSF and complements specialist EITCA/IS programmes in technical security, governance and operations. It is product-centred: EITC/IS/NIS2 remains the dedicated programme for entity scope, management accountability, national supervision and NIS2 incident duties, while GDPR, DORA, the AI Act and sectoral product rules may require separate applicability and reporting determinations. Shared facts and evidence should be reused where valid, but legal conclusions should not be merged without analysis.

The programme supports professional competence and implementation planning. It does not replace product-specific legal advice, the manufacturer’s accountable conformity decision, notified-body assessment, instructions of competent authorities or verification of the current legal and standards status. The content baseline is 23 June 2026; learners are repeatedly taught to preserve source status and review triggers as implementation acts, guidance, harmonised standards, reporting-platform instructions and national procedures evolve.

To acquaint yourself in detail with the certification curriculum, expand and analyse the lesson and topic structure below.

The EITC/IS/CRA Cyber Resilience Act Certification Curriculum references authoritative open-access materials from EUR-Lex, the European Commission, ENISA, NIST, CISA, FIRST, OASIS, OWASP, ETSI and other public professional sources. Learning is organised in a step-by-step programme → lesson → topic structure, with explanatory materials, practical scenarios, interactive studios, professional worksheets, self-checks and further-reading sections. Participants can ask curriculum questions through the Questions and answers section and use the platform’s expert-consultancy channels.
For details on the Certification procedure check How it Works.

EITC/IS/CRA authoritative open-access reference resources — complete six-lesson programme

Regulation (EU) 2024/2847 and applicable published delegated or implementing acts are the controlling legal sources. Official guidance, standards and professional frameworks support interpretation and implementation but do not replace product-specific legal, technical, reporting and conformity decisions. Harmonised standards create a presumption of conformity only after their references are published in the Official Journal and only for the requirements and scope covered. Source status should be rechecked after the programme baseline of 23 June 2026.

Core Cyber Resilience Act sources and implementation status

  • Regulation (EU) 2024/2847 — Cyber Resilience Act
  • Implementing Regulation (EU) 2025/2392 — technical descriptions of important and critical products
  • Delegated Regulation (EU) 2026/881 — conditions for delaying dissemination of certain Article 14 notifications
  • European Commission — Cyber Resilience Act overview
  • European Commission — CRA implementation tracker
  • European Commission — CRA implementation frequently asked questions
  • European Commission — CRA obligations for manufacturers

Lesson 1 — scope, roles, classification and governance

  • European Commission — CRA summary and essential cybersecurity requirements
  • European Commission — Blue Guide 2022 on EU product rules
  • Directive (EU) 2022/2555 — NIS2
  • Regulation (EU) 2016/679 — GDPR
  • Regulation (EU) 2022/2554 — DORA

Lesson 2 — secure-by-design engineering and verification

  • NIST SP 800-218 — Secure Software Development Framework
  • OWASP — Threat Modeling Cheat Sheet
  • OWASP ASVS — application-security requirements and verification
  • ETSI EN 303 645 — consumer IoT cybersecurity baseline

Lesson 3 — lifecycle, supply chain, SBOM and secure updates

  • ENISA — SBOM Adoption State of Play 2026
  • ENISA — Technical Advisory for Secure Use of Package Managers
  • NIST SP 800-161 Rev. 1 — Cybersecurity Supply Chain Risk Management
  • SPDX — software bill of materials specification and resources
  • CycloneDX — SBOM and security transparency specification
  • SLSA specification 1.2 — build and provenance assurance
  • in-toto — software supply-chain attestations
  • Sigstore/cosign — artifact signing and verification
  • The Update Framework — compromise-resilient update design

Lesson 4 — vulnerability handling, reporting and field assurance

  • European Commission — CRA reporting obligations
  • ENISA — CRA Single Reporting Platform information
  • ENISA — coordinated vulnerability disclosure resources
  • RFC 9116 — security.txt
  • FIRST — PSIRT Services Framework 1.1
  • FIRST — Common Vulnerability Scoring System
  • FIRST — Exploit Prediction Scoring System
  • CISA — Known Exploited Vulnerabilities Catalog
  • OASIS CSAF 2.1 — Common Security Advisory Framework
  • NIST SP 800-61 Rev. 3 — incident response

Lesson 5 — standards, conformity, documentation and market assurance

  • European Commission — CRA conformity assessment
  • European Commission — CRA harmonised standards and standardisation request
  • European Commission — NANDO notified-body information system
  • ENISA — technical competence requirements for CRA notified bodies
  • ENISA/JRC — CRA requirements and standards mapping
  • Regulation (EU) 2019/1020 — market surveillance and compliance of products
  • European Commission — market surveillance

Lesson 6 — continuous assurance, secure change, automation and AI-enabled products

  • European Commission — 2026 draft CRA guidance consultation notice
  • NIST OSCAL — machine-readable control and assessment information
  • Regulation (EU) 2024/1689 — Artificial Intelligence Act
  • European Commission — AI Act regulatory framework
  • NIST AI Risk Management Framework
  • NIST AI RMF Generative AI Profile
  • OWASP GenAI Security Project — LLM Top 10
  • ENISA — Cybersecurity Exercise Methodology

These references support learning and implementation. No individual framework, score, certificate, tool, data format or automated result is sufficient by itself to establish CRA applicability, conformity, reportability or acceptable residual risk.

Certification Programme Curriculum

CRA operating model, scope, roles and classification 5 Topics
You don't currently have access to this content
Lesson Content
0% Complete 0/5 Steps
From legal text to a product-security operating model
Scope, product boundary and applicability analysis
Economic operators, open source and substantial modification
Product classification and regulatory risk tiering
CRA governance and interfaces with adjacent EU regimes
Risk-based secure-by-design engineering and essential product properties 5 Topics
You don't currently have access to this content
Lesson Content
0% Complete 0/5 Steps
CRA cybersecurity risk assessment and Annex I applicability
Threat modelling and attack-surface engineering
Secure-by-design and secure-by-default product controls
Resilience, exploit mitigation, logging and safe lifecycle transitions
Security verification and the product release gate
Secure product lifecycle, supply chain, SBOM and update operations 5 Topics
You don't currently have access to this content
Lesson Content
0% Complete 0/5 Steps
Product Security Management System and secure lifecycle
Third-party, open-source and platform supply-chain assurance
SBOM engineering, vulnerability intelligence and VEX
Trusted builds, provenance, signing and secure updates
Support periods, version policy, end of support and user information
Vulnerability handling, reporting, post-market monitoring and crisis operation 5 Topics
You don't currently have access to this content
Lesson Content
0% Complete 0/5 Steps
Coordinated vulnerability disclosure and product-security intake
PSIRT triage, remediation, advisories and component coordination
Article 14 reporting for actively exploited vulnerabilities
Severe incidents and multi-regime notification coordination
Post-market monitoring, corrective action and field assurance
Standards, conformity assessment, technical documentation and market assurance 5 Topics
You don't currently have access to this content
Lesson Content
0% Complete 0/5 Steps
Standards strategy, presumption of conformity and evidence mapping
Conformity assessment strategy and notified-body engagement
Technical documentation, traceability, EU declaration and CE marking
Importer, distributor and market-surveillance readiness
Integrated capstone: the CRA-ready product assurance dossier
Operationalising CRA assurance: continuous control, secure change, automation and AI-era products 5 Topics
You don't currently have access to this content
Lesson Content
0% Complete 0/5 Steps
Keeping CRA controls alive: operating cadence, evidence freshness and management review
Secure change and substantial modification: the CRA change gate
Continuous evidence and assurance automation
AI-enabled products under the CRA: boundary, threats, evaluation and regulatory interfaces
CRA operational tabletop: 90-day readiness and executive handover
EITC/IS/CRA Cyber Resilience Act
You don't currently have access to this content
Home » My Account

Certification Center

Programme Home
CRA operating model, scope, roles and classification
From legal text to a product-security operating model
Scope, product boundary and applicability analysis
Economic operators, open source and substantial modification
Product classification and regulatory risk tiering
CRA governance and interfaces with adjacent EU regimes
Risk-based secure-by-design engineering and essential product properties
CRA cybersecurity risk assessment and Annex I applicability
Threat modelling and attack-surface engineering
Secure-by-design and secure-by-default product controls
Resilience, exploit mitigation, logging and safe lifecycle transitions
Security verification and the product release gate
Secure product lifecycle, supply chain, SBOM and update operations
Product Security Management System and secure lifecycle
Third-party, open-source and platform supply-chain assurance
SBOM engineering, vulnerability intelligence and VEX
Trusted builds, provenance, signing and secure updates
Support periods, version policy, end of support and user information
Vulnerability handling, reporting, post-market monitoring and crisis operation
Coordinated vulnerability disclosure and product-security intake
PSIRT triage, remediation, advisories and component coordination
Article 14 reporting for actively exploited vulnerabilities
Severe incidents and multi-regime notification coordination
Post-market monitoring, corrective action and field assurance
Standards, conformity assessment, technical documentation and market assurance
Standards strategy, presumption of conformity and evidence mapping
Conformity assessment strategy and notified-body engagement
Technical documentation, traceability, EU declaration and CE marking
Importer, distributor and market-surveillance readiness
Integrated capstone: the CRA-ready product assurance dossier
Operationalising CRA assurance: continuous control, secure change, automation and AI-era products
Keeping CRA controls alive: operating cadence, evidence freshness and management review
Secure change and substantial modification: the CRA change gate
Continuous evidence and assurance automation
AI-enabled products under the CRA: boundary, threats, evaluation and regulatory interfaces
CRA operational tabletop: 90-day readiness and executive handover
EITC/IS/CRA Cyber Resilience Act

USER MENU

  • My Account

CERTIFICATE CATEGORY

  • EITC Certification (117)
  • EITCA Certification (9)

What are you looking for?

  • Introduction
  • How it works?
  • EITCA Academies
  • EITCI DSJC Subsidy
  • Full EITC catalogue
  • Your order
  • Featured
  •   IT ID
  • EITCA reviews (Medium publ.)
  • About
  • Contact

EITCA Academy is a part of the European IT Certification framework

The European IT Certification framework has been established in 2008 as a Europe based and vendor independent standard in widely accessible online certification of digital skills and competencies in many areas of professional digital specializations. The EITC framework is governed by the European IT Certification Institute (EITCI), a non-profit certification authority supporting information society growth and bridging the digital skills gap in the EU.
Eligibility for EITCA Academy 90% EITCI DSJC Subsidy support
90% of EITCA Academy fees subsidized in enrolment

    EITCA Academy Secretary Office

    European IT Certification Institute ASBL
    Brussels, Belgium, European Union

    EITC / EITCA Certification Framework Operator
    Governing European IT Certification Standard
    Access contact form or call +32 25887351

    Follow EITCI on X
    Visit EITCA Academy on Facebook
    Engage with EITCA Academy on LinkedIn
    Check out EITCI and EITCA videos on YouTube

    Funded by the European Union

    Funded by the European Regional Development Fund (ERDF) and the European Social Fund (ESF) in series of projects since 2007, currently governed by the European IT Certification Institute (EITCI) since 2008

    Information Security Policy | DSRRM and GDPR Policy | Data Protection Policy | Record of Processing Activities | HSE Policy | Anti-Corruption Policy | Modern Slavery Policy

    Automatically translate to your language

    Terms and Conditions | Privacy Policy
    EITCA Academy
    • EITCA Academy on social media
    EITCA Academy


    © 2008-2026  European IT Certification Institute
    Brussels, Belgium, European Union

    TOP

    We care about your privacy

    EITCI uses cookies and similar technologies to keep this site secure, remember your choices, provide personalized experience, measure the traffic, serve more relevant content and certification programmes. You can accept all cookies or customize your preferences. Cookies are variables used to store website specific information on your device to facilitate processing of data for personalized website visit, such as login to your account, accessing the programmes, placing enrolment orders in chosen programmes and improving your EITC certification journey. You can change or withdraw your consent at any time by clicking the Consent Preferences button at the left-bottom of your screen. We respect your choices and are committed to providing you with a transparent and secure browsing experience, which may be limited when cookies aren't accepted. For more details refer to the Privacy Policy
    Customize Consent Preferences
    We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.
    The cookies categorized as Necessary are stored on your browser as they are essential for enabling the basic functionalities of the site.
    To learn more about how Google processes personal information, visit: Google privacy policy

    Necessary

    Always Active

    Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

    Functional

    Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

    Preferences

    Stores personalization choices such as interface preferences.

    External media and social features

    Allows embedded video, social, chat, and external interactive services that may set their own cookies. Keep off until the user chooses these features.

    Analytics

    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

    Marketing and conversions

    Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

    CHAT WITH SUPPORT
    Do you have any questions?
    Attach files with the paperclip or paste screenshots into the message box (Ctrl+V). Max 5 file(s), 10 MB each.
    We will reply here and by email. Your conversation is tracked with a support token.