iThing Academy

    Courses and training

    Practical training for product companies selling connected products in the EU. The course explains what the Cyber Resilience Act requires, when it applies and how to build the process to comply.

    CRA — Cyber Resilience Act

    The course covers which products are in scope, manufacturer obligations, risk assessment, SBOM, vulnerability handling and reporting to ENISA, and how the EN 40000 standard is used to show the product meets the requirements.

    Go to course

    Frequently asked questions

    When does the Cyber Resilience Act apply?
    The CRA entered into force on 10 December 2024. From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA. From 11 December 2027 all requirements apply, and products with digital elements must meet the CRA to carry the CE mark and be sold in the EU.
    Who is the course for?
    Product managers, developers, and quality and compliance leads at companies that make, import or sell products with software or connectivity in the EU.
    Do I need a gap analysis before the course?
    No. The course explains what a gap analysis is and how to do one. If you already have one, you can use it to prioritise your actions during the course.
    What does the CRA require of an SBOM?
    The manufacturer must produce an SBOM (Software Bill of Materials) listing at least the product's top-level dependencies, in a common machine-readable format such as SPDX or CycloneDX. The SBOM is part of the technical documentation and is used to quickly see whether a new vulnerability affects the product. It does not have to be published, but must be available to market surveillance authorities.

    Need training tailored to your company?

    We run courses and workshops on site or online, adapted to your products and needs.

    Contact us