CRA Practitioner

Turn the EU Cyber Resilience Act into working engineering and compliance practice

CRA Practitioner - a 3-day course, hosted by MUDT, for the product, engineering, security and compliance teams responsible for implementing the CRA. Understand your obligations, work through realistic product scenarios, and leave with clear priorities for your organisation.

First cohort: 7 - 9 Sep 2026, on-site in Munich. Further dates will follow. Led by product-security and compliance practitioners, including a member of the European CEN/CENELEC working group developing CRA standards.

7 - 9 Sep 20263 daysOn-site - Siemens Campus, NeuperlachEnglish6-16 participants€ 1,950 excl. VAT
Why now

The deadlines are no longer on the horizon

The CRA's reporting obligations apply from 11 September 2026 and its essential requirements from 11 December 2027 (serious violations can attract fines of up to € 15 million or 2.5 % of global annual turnover). But the real work is operational: most organisations still need to establish ownership, product scope, vulnerability and reporting workflows, reporting evidence and secure-development practices. This course helps cross-functional teams decide what to build first.

Who it's for

The cross-functional roles that have to implement the CRA. It is relevant to anyone who touches a product that falls under the CRA, not just the security team - and no prior CRA knowledge is required. Best attended as a team - you leave with a shared vocabulary and an aligned view of who does what.

CISOs & information security officersCompliance, legal & riskAppSec & product securityProduct managersSoftware architectsDevOps engineersDevelopers & testers
Who teaches

Practitioners, including a CRA standards author

The people who teach are the people who do the work - and one of them helps write the standards you will have to meet.

CRA standards working group

Nariman Aga-Tagiyev

Product Security Architect

Application Security Architect with more than 20 years in software development - full-stack, backend, DevOps and cloud - and fully focused on application security since 2016. He is a member of CEN/CLC/JTC 13/WG9, the European working group that develops the CRA standards.

LinkedIn profile
ISO/IEC 27001 Lead Auditor

Dagmar Stefanie Moser

Consultant, Auditor and Lecturer

Seasoned IT security expert and founder of blueheads GmbH, with over 25 years in IT architecture, secure software engineering and information security; certified ISO/IEC 27001 Lead Auditor and lecturer at MUDT.

LinkedIn profile
Course approach

Expert-led and built around your products

Each day combines expert-led instruction with guided discussion and worked examples. Participants work through real CRA requirements and map them to realistic products - whether software, connected hardware or industrial systems, with practical rather than hypothetical scenarios. Because the course is designed for cross-functional groups, product, engineering, legal and security teams build a shared understanding of the law and what it means for their work. It ends with a structured action-planning session, so teams leave with concrete next steps rather than just notes.

3 days6-16 participantsOn-site in MunichDigital materials includedNo prior CRA knowledge required

What you'll be able to do

  • Assess your CRA exposure, product classification and obligations.
  • Design and assess a CRA-aligned vulnerability-handling and incident-notification process, using the CRA Single Reporting Platform (24-hour early warning, 72-hour notification, 14-day final report).
  • Apply secure-by-design and secure-by-default across architecture and code.
  • Derive and demonstrate security requirements from threat modelling.
  • Use OWASP SAMM and ENISA guidance to identify gaps and prioritise improvements.
  • Translate CRA requirements into product, process and evidence requirements, including post-release conformity, documentation and support duties.
Topics outline

What the three days cover

Day 1

The CRA & notification obligations

The CRA at a glance - scope, classification, timeline, fines and effects on open source; notification obligations (active from 11 Sep 2026); Software & Hardware Bill of Materials and vulnerability management; reporting via the CRA Single Reporting Platform (to the relevant CSIRT, with information shared with ENISA), including the 24-hour, 72-hour and 14-day deadlines.

Day 2

Secure product development lifecycle

Architecture discovery and risk profiling; threat modelling in the CRA context; product and process security requirements; baseline maturity with OWASP SAMM; and the ENISA secure-by-design and secure-by-default principles.

Day 3

Essential requirements, conformity & next steps

CRA essential requirements deep dive and self-assessment; declaration of conformity, technical and user documentation, and long-term support duties; closing with an action-planning session on the roles and next steps for your organisation.

Format, host & certificate

The course is hosted by MUDT (Munich University of Digital Technologies & Applied Sciences) at its Center for Cyber Security and AI, and taught by product-security and compliance practitioners. It is grounded in recognised frameworks - OWASP SAMM and the ENISA secure-by-design playbook - so the approach is structured and defensible. Participants receive a certificate of participation. This is professional training: MUDT acts as host; it is not an accredited or ECTS-bearing programme.

This first cohort (7 - 9 Sep 2026) runs fully on-site at MUDT on the Siemens Campus in Neuperlach, Munich. Further dates follow, and later cohorts can also be delivered fully remote.

Which option fits

Attend as an individual, a team, or in-house

Public cohort

You want to build your own CRA capability and join the next scheduled cohort.

Reserve a place

Team places

You want several roles - product, engineering, security, compliance - aligned on the same understanding.

Request a team quote

In-house course

You want the course delivered for one organisation and mapped to your own products and stack.

Discuss an in-house course

Questions

Do I need a technical background?

No - the course is designed for a mix of security, compliance, product and engineering roles.

Does our product fall under the CRA?

The CRA covers products with digital elements placed on the EU market - software, connected hardware, industrial and embedded products, and SaaS where it ships software. The course includes a product-classification step, so you can work out which obligations apply to what you ship.

Do we get a certificate?

Yes - a certificate of participation. MUDT hosts the course; it is professional training, not an accredited or ECTS-bearing programme.

Can we book it for our own team?

Yes - team places and in-house bookings for a single organisation are available on request.

On-site or remote?

The first cohort (7 - 9 Sep 2026) runs fully on-site in Munich. We run the course regularly, and later cohorts can be delivered fully remote - register your interest and we'll match you to a suitable date.

What happens after 9 September?

Further dates follow - including remote cohorts. Register your interest for a later date.

Reserve your place

Reserve a place or request a team quote

Tell us a little about you and we will come back within one working day.

By submitting this form, the details you provide are processed to handle your enquiry. See our Privacy Policy for details.

Not ready to book? Start with the webinar

The webinar explains what is changing. The three-day course helps your team turn those obligations into processes, product decisions and an implementation plan.

Free 60-minute webinar - "CRA in practice: what to do before the deadlines" - 12 August 2026, 13:00-14:00
Join the free webinar