CRA Practitioner
The EU Cyber Resilience Act - from regulation to engineering practice. A 3-day practitioner course for the teams that have to implement it.
First cohort: 31 Aug – 2 Sep 2026 – further dates will follow. In-house courses for a single organisation are available on request.
The deadlines are no longer on the horizon
Unlike earlier guidance, the CRA carries real enforcement: fines of up to €15 million or 2.5% of global annual turnover, and the authority to withdraw non-compliant products from the EU market. Its notification obligations apply from 11 September 2026 and its essential requirements from 11 December 2027. Building the vulnerability tracking, incident detection and reporting workflows the CRA requires takes months - this course gives your team the shared understanding to start building the right things straight away.
Who it's for
The cross-functional roles that have to implement the CRA. It is relevant to anyone who touches a product that falls under the CRA, not just the security team - and no prior CRA knowledge is required. Best attended as a team - you leave with a shared vocabulary and an aligned view of who does what.
Expert-led and built around your products
Each day combines expert-led instruction with guided discussion and worked examples. Participants work through real CRA requirements and map them to realistic products - whether software, connected hardware or industrial systems, with practical rather than hypothetical scenarios. Because the course is designed for cross-functional groups, product, engineering, legal and security teams build a shared understanding of the law and what it means for their work. It ends with a structured action-planning session, so teams leave with concrete next steps rather than just notes.
What you'll be able to do
Assess your CRA exposure, product classification and obligations.
Run a compliant vulnerability-handling and incident-notification process (national CERT / ENISA).
Apply secure-by-design and secure-by-default across architecture and code.
Derive and demonstrate security requirements from threat modelling.
Self-assess against the CRA with OWASP SAMM and the ENISA playbook.
Handle post-release conformity, documentation and support duties.
What the three days cover
The CRA & notification obligations
The CRA at a glance - scope, classification, timeline, fines and effects on open source; notification obligations (active from 11 Sep 2026); Software & Hardware Bill of Materials and vulnerability management; external communication and regulatory reporting to national CERTs and ENISA.
Secure product development lifecycle
Architecture discovery and risk profiling; threat modelling in the CRA context; product and process security requirements; baseline maturity with OWASP SAMM; and the ENISA secure-by-design and secure-by-default principles.
Essential requirements, conformity & next steps
CRA essential requirements deep dive and self-assessment; declaration of conformity, technical and user documentation, and long-term support duties; closing with an action-planning session on the roles and next steps for your organisation.
Format & facilities
Delivered by the Center for Cyber Security and AI at MUDT, combining applied research with an expert partner network. Grounded in recognised frameworks - OWASP SAMM and the ENISA Secure-by-Design & Default playbook - so what you learn is repeatable and auditable.
This first cohort (31 Aug - 2 Sep 2026) runs fully on-site at MUDT on the Siemens Campus in Neuperlach, Munich. Further dates follow, and later cohorts can also be delivered fully remote.
At a glance
* Per participant for all three days, excl. VAT - request a quote.
Who teaches
Nariman Aga-Tagiyev
Application Security Architect with more than 20 years in software development - full-stack, backend, DevOps and cloud - and fully focused on application security since 2016. He is a member of the CEN/CLC/JTC 13/WG9 that develops the CRA standards.
LinkedIn profile
Dagmar Stefanie Moser
Seasoned IT security expert and founder of blueheads GmbH, with over 25 years in IT architecture, secure software engineering and information security; certified ISO/IEC 27001 Lead Auditor and lecturer at MUDT.
LinkedIn profileQuestions
Do I need a technical background?
No - the course is designed for a mix of security, compliance, product and engineering roles.
Can we book it for our own team?
Yes - in-house and team bookings are available on request.
On-site or remote?
The first cohort (31 Aug - 2 Sep 2026) runs fully on-site in Munich. We run the course regularly, and later cohorts can be delivered fully remote - register your interest and we'll match you to a suitable date.
What happens after 2 September?
Further dates follow - including remote cohorts. Register your interest for a later date.
Register or request a quote
Tell us a little about you and we'll come back within one working day.
Free 60-minute webinar – “CRA in practice: what to do before the deadlines” · 12 August 2026, 13:00-14:00
Dates, figures and fees are indicative and to be confirmed.