EU Product Cybersecurity Regulations Walkthrough: CRA & RED Compliance in Practice

Master Cyber Resilience Act (CRA) and RED requirements for secure, compliant products

1 Tag In-person / Virtual Class Next: 1 Jan 2099 German / English Identifier: 194233626
EU Product Cybersecurity Regulations Walkthrough: CRA & RED Compliance in Practice

Course Overview

What you'll learn

  • Overview of the Cyber Resilience Act (EU) 2024/2847 and RED Article 3.3(d) requirements
  • Scope and applicability of products with digital elements
  • Cybersecurity risk assessment and threat modeling (CRA Annex I)
  • Secure development lifecycle and secure-by-design principles
  • Handling of open-source (FOSS) components in compliance context
  • Conformity assessment procedures and CE marking process
  • Technical documentation requirements (e.g. SBOM, risk assessment reports)
  • Vulnerability management and coordinated disclosure obligations
  • Post-market surveillance and incident response requirements
  • Testing strategies, penetration testing alignment and cybersecurity audits

Who This Course Is For

This training is designed for:

  • Technical product managers responsible for products with digital elements sold in the EU
  • Product security engineers and security architects
  • IoT and embedded systems engineers
  • Compliance, risk and governance specialists

Prerequisites:

Basic understanding of cybersecurity principles and software or product development processes is recommended. Prior experience with regulatory frameworks is beneficial but not required.

Completion:
Upon completion of the training, participants receive an SGS Certificate of Attendance.

Contact:
Tel.: 040 30101-314
E-Mail: de.academy@sgs.com

About this course

The Cyber Resilience Act (CRA) (EU) 2024/2847 and the cybersecurity requirements of the Radio Equipment Directive (RED Article 3.3(d)) are redefining product compliance for connected and software-based products in the EU.

This intensive one‑day training provides a practical, hands‑on understanding of EU product cybersecurity regulations. You will learn how to identify applicable requirements, assess product scope, and implement secure-by-design principles across the product lifecycle.

The course focuses on real-world implementation, enabling you to translate legal requirements into actionable engineering and compliance workflows. You will gain concrete guidance on documentation, risk assessment and vulnerability management to avoid compliance gaps, reduce risks and ensure market access in the EU.

Not sure if this is right?

Let us help you find the perfect match.

Course Finder