Home / Courses / EU Product Compliance / EU Cyber Resilience Act: Compliance for Manufacturers
EU Product Compliance

EU Cyber Resilience Act: Compliance for Manufacturers

Most manufacturers believe the Cyber Resilience Act starts in December 2027. It does not. From…

Code BII-CRA 4-Day Almaty, Dubai, London, Online Online + Classroom
Overview

Course Description

Most manufacturers believe the Cyber Resilience Act starts in December 2027. It does not. From 11 September 2026, any manufacturer of a product with digital elements available on the EU market must report actively exploited vulnerabilities within 24 hours and severe incidents within 72 — and that obligation applies to legacy products placed on the market years ago, not just new launches.

The trap is dependency. To report, a manufacturer must know which components sit inside its products; to know that, it needs a software bill of materials and continuous vulnerability monitoring. SBOM obligations are not formally enforceable until December 2027 — but without one, the September 2026 reporting duty cannot be met at all. Penalties reach EUR 15 million or 2.5% of worldwide turnover.

This course prepares manufacturers. Participants learn the CRA's scope and the meaning of products with digital elements, economic operator roles, the reporting regime and its 24/72-hour clocks, the ENISA Single Reporting Platform, SBOM and vulnerability management, secure-by-design essential requirements, conformity assessment and CE marking, and support lifecycle obligations.

Objectives

What you will achieve

By the end of this training course, participants will be able to:

  • Determine whether a product falls within CRA scope
  • Distinguish manufacturer, importer and distributor obligations
  • Apply the reporting regime and its 24 and 72-hour deadlines
  • Use the ENISA Single Reporting Platform
  • Build SBOM capability and vulnerability monitoring
  • Apply secure-by-design and secure-by-default requirements
  • Navigate conformity assessment, technical documentation and CE marking
  • Manage support period and lifecycle obligations
Training methodology

How the course is delivered

The course combines the CRA framework with practical scoping, SBOM and reporting workflow exercises using realistic connected products. Participants classify products, map obligations and build reporting procedures.

The programme prioritises the September 2026 reporting deadline and its SBOM dependency, because that is the obligation manufacturers most commonly overlook and cannot meet retroactively.

Who should attend

Designed for

This training course is ideal for:

  • Product and engineering leaders in hardware and software
  • Manufacturers of IoT, OT and embedded systems
  • Cybersecurity and compliance professionals
  • Quality and regulatory affairs staff
  • Anyone placing products with digital elements on the EU market
Course outline

Daily programme

DAY 01Scope and Roles
  • Why the CRA exists and what it covers
  • Products with digital elements defined
  • Exclusions and sector overlaps
  • Manufacturer, importer, distributor obligations
DAY 02The Reporting Regime
  • Actively exploited vulnerabilities and severe incidents
  • The 24-hour early warning and 72-hour notification
  • Final reports and timelines
  • The ENISA Single Reporting Platform and CSIRT routing
DAY 03SBOM and Vulnerability Management
  • Software bill of materials
  • Component inventory and legacy products
  • Continuous vulnerability monitoring
  • Coordinated vulnerability disclosure
DAY 04Essential Requirements and Conformity
  • Secure by design and secure by default
  • Essential cybersecurity requirements
  • Conformity assessment routes and CE marking
  • Support lifecycle, penalties, roadmap workshop
Certificate

Certification & accreditation

BII Certificate of Completion

BII Certificate of Completion Upon successful completion, participants receive a BII Development Institute Certificate of Completion with a unique reference code that is independently verifiable. Our certificates are recognised internationally and reflect successful completion of your chosen programme.

Schedule

Upcoming sessions

DatesVenueFormatFee
19 - 22 Apr 2027 Almaty Classroom US$ 4950 Register
21 - 24 Sep 2026 Online Online US$ 4950 Register
25 - 28 Jan 2027 Dubai Classroom US$ 4950 Register
26 - 29 Oct 2026 London Classroom US$ 4950 Register
Enrolment

Register, request in-house, or download the agenda

Choose an action and share your details — our team responds within one business day with dates, fees and the full programme.

Poster