Professional Centers › Center for Cyber Security and AI › CRA Practitioner

CRA Practitioner

The EU Cyber Resilience Act - from regulation to engineering practice. A 3-day practitioner course for the teams that have to implement it.

First cohort: 31 Aug – 2 Sep 2026 – further dates will follow. In-house courses for a single organisation are available on request.

31 Aug - 2 Sep 2026 3 days On-site · Siemens Campus, Neuperlach English Small group (6-16)
Why now

The deadlines are no longer on the horizon

Unlike earlier guidance, the CRA carries real enforcement: fines of up to €15 million or 2.5% of global annual turnover, and the authority to withdraw non-compliant products from the EU market. Its notification obligations apply from 11 September 2026 and its essential requirements from 11 December 2027. Building the vulnerability tracking, incident detection and reporting workflows the CRA requires takes months - this course gives your team the shared understanding to start building the right things straight away.

Who it's for

The cross-functional roles that have to implement the CRA. It is relevant to anyone who touches a product that falls under the CRA, not just the security team - and no prior CRA knowledge is required. Best attended as a team - you leave with a shared vocabulary and an aligned view of who does what.

CISOs & information security officers Compliance, legal & risk AppSec & product security Product managers Software architects DevOps engineers Developers & testers
Course approach

Expert-led and built around your products

Each day combines expert-led instruction with guided discussion and worked examples. Participants work through real CRA requirements and map them to realistic products - whether software, connected hardware or industrial systems, with practical rather than hypothetical scenarios. Because the course is designed for cross-functional groups, product, engineering, legal and security teams build a shared understanding of the law and what it means for their work. It ends with a structured action-planning session, so teams leave with concrete next steps rather than just notes.

3 days 6-16 participants On-site in Munich Digital materials included No prior CRA knowledge required

What you'll be able to do

  • Assess your CRA exposure, product classification and obligations.

  • Run a compliant vulnerability-handling and incident-notification process (national CERT / ENISA).

  • Apply secure-by-design and secure-by-default across architecture and code.

  • Derive and demonstrate security requirements from threat modelling.

  • Self-assess against the CRA with OWASP SAMM and the ENISA playbook.

  • Handle post-release conformity, documentation and support duties.

Topics outline

What the three days cover

Day 1

The CRA & notification obligations

The CRA at a glance - scope, classification, timeline, fines and effects on open source; notification obligations (active from 11 Sep 2026); Software & Hardware Bill of Materials and vulnerability management; external communication and regulatory reporting to national CERTs and ENISA.

Day 2

Secure product development lifecycle

Architecture discovery and risk profiling; threat modelling in the CRA context; product and process security requirements; baseline maturity with OWASP SAMM; and the ENISA secure-by-design and secure-by-default principles.

Day 3

Essential requirements, conformity & next steps

CRA essential requirements deep dive and self-assessment; declaration of conformity, technical and user documentation, and long-term support duties; closing with an action-planning session on the roles and next steps for your organisation.

Format & facilities

Delivered by the Center for Cyber Security and AI at MUDT, combining applied research with an expert partner network. Grounded in recognised frameworks - OWASP SAMM and the ENISA Secure-by-Design & Default playbook - so what you learn is repeatable and auditable.

This first cohort (31 Aug - 2 Sep 2026) runs fully on-site at MUDT on the Siemens Campus in Neuperlach, Munich. Further dates follow, and later cohorts can also be delivered fully remote.

At a glance

Dates 31 Aug - 2 Sep 2026 (first cohort)
Duration 3 days
Format On-site (first cohort)
Group size 6 - 16
Fee € 1,950 for the full course *
Language English

* Per participant for all three days, excl. VAT - request a quote.

Trainers

Who teaches

Nariman Aga-Tagiyev

Nariman Aga-Tagiyev

Product Security Architect

Application Security Architect with more than 20 years in software development - full-stack, backend, DevOps and cloud - and fully focused on application security since 2016. He is a member of the CEN/CLC/JTC 13/WG9 that develops the CRA standards.

LinkedIn profile
Dagmar Stefanie Moser

Dagmar Stefanie Moser

Consultant, Auditor and Lecturer

Seasoned IT security expert and founder of blueheads GmbH, with over 25 years in IT architecture, secure software engineering and information security; certified ISO/IEC 27001 Lead Auditor and lecturer at MUDT.

LinkedIn profile

Questions

Do I need a technical background?

No - the course is designed for a mix of security, compliance, product and engineering roles.

Can we book it for our own team?

Yes - in-house and team bookings are available on request.

On-site or remote?

The first cohort (31 Aug - 2 Sep 2026) runs fully on-site in Munich. We run the course regularly, and later cohorts can be delivered fully remote - register your interest and we'll match you to a suitable date.

What happens after 2 September?

Further dates follow - including remote cohorts. Register your interest for a later date.

Get CRA-ready

Register or request a quote

Tell us a little about you and we'll come back within one working day.

















    Free 60-minute webinar – “CRA in practice: what to do before the deadlines” · 12 August 2026, 13:00-14:00

    Register for the webinar

    Dates, figures and fees are indicative and to be confirmed.