Course Description
Most manufacturers believe the Cyber Resilience Act starts in December 2027. It does not. From 11 September 2026, any manufacturer of a product with digital elements available on the EU market must report actively exploited vulnerabilities within 24 hours and severe incidents within 72 — and that obligation applies to legacy products placed on the market years ago, not just new launches.
The trap is dependency. To report, a manufacturer must know which components sit inside its products; to know that, it needs a software bill of materials and continuous vulnerability monitoring. SBOM obligations are not formally enforceable until December 2027 — but without one, the September 2026 reporting duty cannot be met at all. Penalties reach EUR 15 million or 2.5% of worldwide turnover.
This course prepares manufacturers. Participants learn the CRA's scope and the meaning of products with digital elements, economic operator roles, the reporting regime and its 24/72-hour clocks, the ENISA Single Reporting Platform, SBOM and vulnerability management, secure-by-design essential requirements, conformity assessment and CE marking, and support lifecycle obligations.
What you will achieve
By the end of this training course, participants will be able to:
- Determine whether a product falls within CRA scope
- Distinguish manufacturer, importer and distributor obligations
- Apply the reporting regime and its 24 and 72-hour deadlines
- Use the ENISA Single Reporting Platform
- Build SBOM capability and vulnerability monitoring
- Apply secure-by-design and secure-by-default requirements
- Navigate conformity assessment, technical documentation and CE marking
- Manage support period and lifecycle obligations
How the course is delivered
The course combines the CRA framework with practical scoping, SBOM and reporting workflow exercises using realistic connected products. Participants classify products, map obligations and build reporting procedures.
The programme prioritises the September 2026 reporting deadline and its SBOM dependency, because that is the obligation manufacturers most commonly overlook and cannot meet retroactively.
Designed for
This training course is ideal for:
- Product and engineering leaders in hardware and software
- Manufacturers of IoT, OT and embedded systems
- Cybersecurity and compliance professionals
- Quality and regulatory affairs staff
- Anyone placing products with digital elements on the EU market
Daily programme
- Why the CRA exists and what it covers
- Products with digital elements defined
- Exclusions and sector overlaps
- Manufacturer, importer, distributor obligations
- Actively exploited vulnerabilities and severe incidents
- The 24-hour early warning and 72-hour notification
- Final reports and timelines
- The ENISA Single Reporting Platform and CSIRT routing
- Software bill of materials
- Component inventory and legacy products
- Continuous vulnerability monitoring
- Coordinated vulnerability disclosure
- Secure by design and secure by default
- Essential cybersecurity requirements
- Conformity assessment routes and CE marking
- Support lifecycle, penalties, roadmap workshop
Certification & accreditation
BII Certificate of Completion
BII Certificate of Completion Upon successful completion, participants receive a BII Development Institute Certificate of Completion with a unique reference code that is independently verifiable. Our certificates are recognised internationally and reflect successful completion of your chosen programme.