Free certification programme
EU Cyber Resilience Act Certification
Regulation (EU) 2024/2847 applies to anyone placing a product with digital elements on the EU market. This course teaches what it asks of you, and the exam proves you know it: closed-book, timed, and drawn from a bank built straight from the official text. Every question cites the article or annex it comes from. Free to take, and the certificate verifies publicly.
- Modules
- 8
- Question bank
- 939
- Final exam
- 60 questions
- Attempts
- 3 maximum
Examination rules
Module quizzes
- 10 questions, sampled fresh from that module's bank.
- Pass mark 70%.
- 3 attempts per module, enforced server-side.
- Answers and explanations are shown after each attempt.
- All 8 modules must be passed to unlock the final.
Final examination
- 60 questions drawn across all 8 modules.
- 90 minutes, timed and enforced at submission.
- Pass mark 75%.
- 3 attempts in total; each draws a different paper.
- Results report a score and a per-module breakdown. No answer key is released, to keep the bank intact.
Questions are single-best-answer in the style of professional security certifications: roughly a third are scenarios that test judgment rather than recall, and the correct option is deliberately not the longest one. Starting an attempt consumes it, so read the module before you begin.
Syllabus
Work through the modules in order. Each ends with a quiz you must pass before the final examination opens.
- Module 135 min · 105 items
CRA foundations, timeline, and scope
The regulation's purpose and legal architecture, the staged application timeline, Article 2 scope, Article 3 definitions, and the exclusions that hand products to other regimes.
- Module 230 min · 120 items
Product classification: default, important, critical
The three-tier risk model: the default category, Annex III Class I and Class II important products, Annex IV critical products, and classification by function rather than name.
- Module 340 min · 129 items
Annex I Part I: secure-by-design essential requirements
The product-property requirements: risk-based design, secure defaults, update mechanisms, access control, data protection, attack-surface minimisation, and logging.
- Module 435 min · 120 items
Annex I Part II: vulnerability handling and the SBOM
The post-market process requirements: SBOM, remediation without delay, free security updates, coordinated vulnerability disclosure, and secure update distribution.
- Module 545 min · 120 items
Article 13: the manufacturer's lifecycle obligations
The full Article 13 duty set: risk assessment, component due diligence, the support period and its floors, technical documentation, identification details, and Annex II user information.
- Module 640 min · 120 items
Article 14: reporting actively exploited vulnerabilities and severe incidents
The two triggers, the 24-hour, 72-hour and final-report clocks, the CSIRT and ENISA recipients through the single reporting platform, and user notification duties.
- Module 740 min · 125 items
Conformity assessment, technical documentation, and CE marking
The Annex VIII modules, which routes each product tier may use, presumption of conformity, Annex VII technical documentation, the EU Declaration of Conformity, and CE marking rules.
- Module 835 min · 100 items
Economic operators, market surveillance, and penalties
Importer and distributor duties, when a rebrander or modifier becomes the manufacturer, open-source stewards, authorised representatives, market surveillance powers, and the Article 64 penalty ladder.
Final examination
Opens once all 8 module quizzes are passed.
Official study material
Everything below is published by the EU institutions and linked in its original location. Recorded sessions are embedded from the publisher's own channel.
EUCC and CRA interplay — ENISA webinar, morning session
ENISA and the European Commission on how EUCC certification maps to CRA essential requirements. 3 June 2025, 08:00 CEST, scheduled for Asian time zones.
EUCC and CRA interplay — ENISA webinar, afternoon session
The same agenda, held later the same day at 18:00 CEST for American time zones.
- Regulation (EU) 2024/2847 — full text
EUR-Lex. The authoritative source for every article and annex this course examines.
- Summary of the legislative text
European Commission. A readable orientation to the structure of the regulation.
- Cyber Resilience Act policy hub
European Commission. Implementation news, guidance and the FAQ.
- SME readiness for the CRA
ENISA. Where smaller companies actually stand, and the common gaps.