Intermediate2h 21m

# EU Cyber Resilience Act (CRA) Compliance Course

EU Cyber Resilience Act compliance: product classes, essential requirements, SBOMs, vulnerability handling and the September 2026 reporting duty.

A smart camera manufacturer ships a hardcoded root password because nobody revisited a default set years ago. A router vendor has no way for a researcher to report a flaw, so the flaw surfaces on a security blog instead. A component supplier feeding secure elements into smart meters discovers, mid-audit, that their product needs third-party certification nobody budgeted for. None of this is exotic. It's the ordinary result of treating the EU Cyber Resilience Act as someone else's problem. This course teaches Regulation (EU) 2024/2847 — the Cyber Resilience Act — from first principles to complete practical compliance, for every manufacturer, importer, and distributor of a connected hardware or software product sold into the European Union. You'll learn exactly what counts as a "product with digital elements," how to classify it as default, important Class I, important Class II, or critical under Annex III and Annex IV, and what each classification actually means for your conformity assessment route. You'll build both halves of Annex I in depth: the secure-by-design and secure-by-default essential requirements, and the vulnerability handling obligations that run for a product's entire declared support period, including a dedicated, practical module on building a real software bill of materials your team will actually keep current. From there, the course covers every economic operator's obligations under Article 13 end to end — risk assessment, due diligence on third-party and open-source components, technical documentation under Annex VII, the EU declaration of conformity, and the conformity assessment modules that determine when self-assessment is genuinely available and when a notified body is mandatory. A full module is dedicated to the current harmonised-standards gap — no CRA harmonised standard has been published in the Official Journal yet — and exactly how to document direct Annex I compliance in the meantime. CE marking mechanics, the free and open-source software steward carve-out, and how this regulation sits next to NIS2, GDPR, the Radio Equipment Directive, the UK's PSTI Act and Cyber Security and Resilience Bill, and the US Cyber Trust Mark round out the regulatory picture. The reporting module is built around the deadline this course keeps returning to: mandatory vulnerability and incident reporting through ENISA's Single Reporting Platform, live from September 11, 2026 — the 24-hour early warning, the 72-hour full notification, and the 14-day and one-month final reports. Enforcement and Article 64's three-tier penalty structure, a full practical walkthrough of one manufacturer building a compliance program from a standing start, common mistakes and edge cases, and your own thirty, sixty, ninety-day action plan close out the course. Built on Krono's regulatory database and current 2026 guidance, covering Regulation (EU) 2024/2847 as adopted, its rollout through December 2027, and the state of harmonised standardisation, notified body designation, and delegated and implementing acts as they stood at the time of this course's production. This course contains the use of artificial intelligence for asthetic purposes.

*   Includes the ebook edition, free
*   8 downloadable resources included

## What you'll learn

*   Build and maintain a real, automated software bill of materials your team will actually keep current
*   Run every manufacturer, importer, and distributor obligation under Article 13, including technical documentation and the EU declaration of conformity
*   Choose the right conformity assessment route and work through the current harmonised-standards gap without waiting on a publication timeline
*   Meet the September 2026 vulnerability and incident reporting deadlines — 24 hours, 72 hours, 14 days, one month — through ENISA's Single Reporting Platform
*   Understand Article 64 enforcement and penalties, and how the CRA fits alongside NIS2, RED, GDPR, and the UK's and US's parallel regimes

## Requirements

*   ·No prior cybersecurity, legal, or engineering background required — the course builds every concept from first principles
*   ·A working knowledge of your own product's connectivity and update mechanism is helpful but not required
*   ·Manufacturers, importers, distributors, compliance teams, and hardware startups selling into the EU will all benefit

$199.00

One-time purchase · Lifetime access · No subscription

Less than one hour with a compliance consultant.

[First lesson free to preview: EU Cyber Resilience Act](#lesson-08f7645b-16d9-4f62-a1f1-b7b458708c6a)

*   Determine exactly which products count as "products with digital elements" under the CRA, including indirect connections and components sold separately
*   Classify any product as default, important Class I, important Class II, or critical under Annex III and Annex IV, and know what each means for assessment
*   Implement both halves of Annex I — secure by design and default, and full-lifecycle vulnerability handling — correctly

Includes the ebook edition, free — read it in your [library](/platform/books) after purchase.

Enroll — $199.00

Secure checkout via Paddle

Not what you expected? Contact us within 14 days.

Built from a regulatory graph already at work

1,599

users this week

658

guides

323

product types

9

markets

## Course content

21 modules·141 min total

The Big Picture

Preview11 min

The Regulatory Framework

10 min

Scope: What Counts as a Product With Digital Elements

8 min

Product Classification: Default, Important, and Critical

8 min

Essential Requirements — Part I: Secure by Design & Default

7 min

Essential Requirements — Part II: Vulnerability Handling

7 min

Building a Real Software Bill of Materials

6 min

Manufacturer Obligations End to End

7 min

Importer and Distributor Obligations

6 min

Technical Documentation & the EU Declaration of Conformity

6 min

Conformity Assessment Procedures

7 min

The Harmonised Standards Gap

6 min

CE Marking for Products With Digital Elements

6 min

Reporting Obligations: 24 Hours to One Month

7 min

Market Surveillance, Enforcement & Penalties

6 min

Free and Open-Source Software Under the CRA

6 min

How the CRA Fits With Other Regimes

7 min

Full Walkthrough: Building a Compliance Program

6 min

Common Mistakes & Edge Cases

5 min

Your Compliance Action Plan

9 min

What's Next

0 min

Enroll — $199.00

Need more than one? The **All-Access Krono Vault** unlocks every course and book for one payment, or put your whole team on it with **Krono Team Vault**.

[See pricing](/pricing)

Short on time?

### Rather hand it over than learn it?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

[See services](/services)