Free certification programme

EU Cyber Resilience Act Certification

Regulation (EU) 2024/2847 applies to anyone placing a product with digital elements on the EU market. This course teaches what it asks of you, and the exam proves you know it: closed-book, timed, and drawn from a bank built straight from the official text. Every question cites the article or annex it comes from. Free to take, and the certificate verifies publicly.

Modules
8
Question bank
939
Final exam
60 questions
Attempts
3 maximum

Enroll — free

We email you an activation link. Attempts are limited, so quizzes and the exam only open for a verified enrollment. Your name appears on the certificate exactly as entered.

Examination rules

Module quizzes

  • 10 questions, sampled fresh from that module's bank.
  • Pass mark 70%.
  • 3 attempts per module, enforced server-side.
  • Answers and explanations are shown after each attempt.
  • All 8 modules must be passed to unlock the final.

Final examination

  • 60 questions drawn across all 8 modules.
  • 90 minutes, timed and enforced at submission.
  • Pass mark 75%.
  • 3 attempts in total; each draws a different paper.
  • Results report a score and a per-module breakdown. No answer key is released, to keep the bank intact.

Questions are single-best-answer in the style of professional security certifications: roughly a third are scenarios that test judgment rather than recall, and the correct option is deliberately not the longest one. Starting an attempt consumes it, so read the module before you begin.

Syllabus

Work through the modules in order. Each ends with a quiz you must pass before the final examination opens.

  1. Module 1
    35 min · 105 items

    CRA foundations, timeline, and scope

    The regulation's purpose and legal architecture, the staged application timeline, Article 2 scope, Article 3 definitions, and the exclusions that hand products to other regimes.

  2. Module 2
    30 min · 120 items

    Product classification: default, important, critical

    The three-tier risk model: the default category, Annex III Class I and Class II important products, Annex IV critical products, and classification by function rather than name.

  3. Module 3
    40 min · 129 items

    Annex I Part I: secure-by-design essential requirements

    The product-property requirements: risk-based design, secure defaults, update mechanisms, access control, data protection, attack-surface minimisation, and logging.

  4. Module 4
    35 min · 120 items

    Annex I Part II: vulnerability handling and the SBOM

    The post-market process requirements: SBOM, remediation without delay, free security updates, coordinated vulnerability disclosure, and secure update distribution.

  5. Module 5
    45 min · 120 items

    Article 13: the manufacturer's lifecycle obligations

    The full Article 13 duty set: risk assessment, component due diligence, the support period and its floors, technical documentation, identification details, and Annex II user information.

  6. Module 6
    40 min · 120 items

    Article 14: reporting actively exploited vulnerabilities and severe incidents

    The two triggers, the 24-hour, 72-hour and final-report clocks, the CSIRT and ENISA recipients through the single reporting platform, and user notification duties.

  7. Module 7
    40 min · 125 items

    Conformity assessment, technical documentation, and CE marking

    The Annex VIII modules, which routes each product tier may use, presumption of conformity, Annex VII technical documentation, the EU Declaration of Conformity, and CE marking rules.

  8. Module 8
    35 min · 100 items

    Economic operators, market surveillance, and penalties

    Importer and distributor duties, when a rebrander or modifier becomes the manufacturer, open-source stewards, authorised representatives, market surveillance powers, and the Article 64 penalty ladder.

Final examination

Opens once all 8 module quizzes are passed.

Official study material

Everything below is published by the EU institutions and linked in its original location. Recorded sessions are embedded from the publisher's own channel.

EUCC and CRA interplay — ENISA webinar, morning session

ENISA and the European Commission on how EUCC certification maps to CRA essential requirements. 3 June 2025, 08:00 CEST, scheduled for Asian time zones.

EUCC and CRA interplay — ENISA webinar, afternoon session

The same agenda, held later the same day at 18:00 CEST for American time zones.