← CVD Portal Academy

CRA Training Course

Cyber Resilience Course for EU CRA Manufacturers

Regulation (EU) 2024/2847 applies to anyone placing a product with digital elements on the EU market. This course teaches what it asks of you, and the exam proves you know it: closed-book, timed, and drawn from a bank built straight from the official text. Every question cites the article or annex it comes from. Free to take, and the certificate verifies publicly.

Modules
8
Question bank
939
Final exam
60 questions
Attempts
3 maximum
CPE credits
6

Enroll — free

We email you an activation link. Attempts are limited, so quizzes and the exam only open for a verified enrollment. Your name appears on the certificate exactly as entered.

Examination rules

Module quizzes

  • 10 questions, sampled fresh from that module's bank.
  • Pass mark 70%.
  • 3 attempts per module, enforced server-side.
  • Answers and explanations are shown after each attempt.
  • All 8 modules must be passed to unlock the final.

Final examination

  • 60 questions drawn across all 8 modules.
  • 90 minutes, timed and enforced at submission.
  • Pass mark 75%.
  • 3 attempts in total; each draws a different paper.
  • Results report a score and a per-module breakdown. No answer key is released, to keep the bank intact.

Questions are single-best-answer in the style of professional security certifications: roughly a third are scenarios that test judgment rather than recall, and the correct option is deliberately not the longest one. Starting an attempt consumes it, so read the module before you begin.

Continuing professional education

The certificate carries 6 CPE credits, one per instructional hour across the 8 modules and the examination, rounded down to the nearest half credit. The figure is printed on the certificate. These credits are self-reported by the holder to their own certifying body. We are not an (ISC)² CPE Submitter or a PMI Authorized Training Partner, so they are not officially accredited.

Syllabus

Work through the modules in order. Each ends with a quiz you must pass before the final examination opens.

  1. Module 1
    35 min · 105 items

    CRA foundations, timeline, and scope

    The regulation's purpose and legal architecture, the staged application timeline, Article 2 scope, Article 3 definitions, and the exclusions that hand products to other regimes.

  2. Module 2
    30 min · 120 items

    Product classification: default, important, critical

    The three-tier risk model: the default category, Annex III Class I and Class II important products, Annex IV critical products, and classification by function rather than name.

  3. Module 3
    40 min · 129 items

    Annex I Part I: secure-by-design essential requirements

    The product-property requirements: risk-based design, secure defaults, update mechanisms, access control, data protection, attack-surface minimisation, and logging.

  4. Module 4
    35 min · 120 items

    Annex I Part II: vulnerability handling and the SBOM

    The post-market process requirements: SBOM, remediation without delay, free security updates, coordinated vulnerability disclosure, and secure update distribution.

  5. Module 5
    45 min · 120 items

    Article 13: the manufacturer's lifecycle obligations

    The full Article 13 duty set: risk assessment, component due diligence, the support period and its floors, technical documentation, identification details, and Annex II user information.

  6. Module 6
    40 min · 120 items

    Article 14: reporting actively exploited vulnerabilities and severe incidents

    The two triggers, the 24-hour, 72-hour and final-report clocks, the CSIRT and ENISA recipients through the single reporting platform, and user notification duties.

  7. Module 7
    40 min · 125 items

    Conformity assessment, technical documentation, and CE marking

    The Annex VIII modules, which routes each product tier may use, presumption of conformity, Annex VII technical documentation, the EU Declaration of Conformity, and CE marking rules.

  8. Module 8
    35 min · 100 items

    Economic operators, market surveillance, and penalties

    Importer and distributor duties, when a rebrander or modifier becomes the manufacturer, open-source stewards, authorised representatives, market surveillance powers, and the Article 64 penalty ladder.

Final examination

Opens once all 8 module quizzes are passed.

What to do with this

Knowing the regulation is the first half. The second is producing the file it asks for: the classification, the Annex I assessment, the technical documentation, the Declaration of Conformity and the Article 14 reporting path. Start with a free assessment, then bring the result into a workspace that keeps the evidence.

Classify your product

Answer the Annex III and Annex IV questions for one product and get its class and the conformity route that follows. No account.

Classify — free

Check what you expose

The exposure scanner reads your domain for the security.txt and the coordinated disclosure policy Annex I Part II requires, and reports what is missing.

Scan — free

Build the technical file

The compliance workspace carries a product from classification through Annex I to a signed Declaration of Conformity. 14-day trial, no card.

Start a free trial

Official study material

Everything below is published by the EU institutions and linked in its original location. Recorded sessions are embedded from the publisher's own channel.

EUCC and CRA interplay — ENISA webinar, morning session

ENISA and the European Commission on how EUCC certification maps to CRA essential requirements. 3 June 2025, 08:00 CEST, scheduled for Asian time zones.

EUCC and CRA interplay — ENISA webinar, afternoon session

The same agenda, held later the same day at 18:00 CEST for American time zones.