
CRA workshop
CRA training as a workshop: working through the Cyber Resilience Act with your own products
The Blackfort Technology CRA workshop is training for one company and its products. In four blocks your team covers what the Cyber Resilience Act requires of manufacturers and applies each point to two or three of your products. The workshop takes place on site or by video conference, as agreed.
Who the workshop is for
Manufacturers of products with digital elements, meaning hardware or software whose intended or reasonably foreseeable use includes a data connection to a device or network (Article 2(1)). The workshop is meant for teams that need to get up to speed on the CRA. Ideally one developer per reference product attends, together with someone who knows who settles and approves legal questions in-house.
The reporting obligation under Article 14 has applied since 11 September 2026, including for products placed on the market before 11 December 2027 (Art. 69(3)). The remaining manufacturer obligations apply from 11 December 2027 (Art. 71(2)). The sooner your team knows which products are affected and who is responsible for what, the more lead time remains for the risk assessment, the documentation and the conformity assessment.
The four blocks
The structure follows our working document, whose statements on the Regulation we have checked against the legal text. Every block cites the provisions of the Regulation for later reference.
Block 1: products, roles, classes
What counts as a product with digital elements, what is excluded, and how open source and cloud are treated. Manufacturer, authorised representative, importer, distributor. Important and critical products under Annexes III and IV and the conformity assessment route that follows (Art. 32).
Roles under the CRABlock 2: security requirements
The thirteen requirements of Annex I Part I, from being placed on the market without known exploitable vulnerabilities to deleting data, and the cybersecurity risk assessment under Article 13(2) to (4), which sets out whether and how each requirement applies to the product and is implemented.
Threat modelling for the CRABlock 3: vulnerabilities and reporting
Annex I Part II with the software bill of materials, security updates and coordinated vulnerability disclosure, due diligence for third-party components (Art. 13(5) and (6)) and the Article 14 reporting chain: early warning within 24 hours of becoming aware, notification, final report.
Reporting obligation since September 2026Block 4: documentation and conformity
Technical documentation under Annex VII, information and instructions to the user under Annex II, a support period of in principle at least five years (Art. 13(8)), conformity assessment, EU declaration of conformity and CE marking.
Technical documentationWhat you take away
The aim of the session is a working position your team can carry on from directly.
01
Draft product list
Which products and variants you make available on the EU market, with the details that matter for classification.
02
Roles as a working hypothesis
For which products you are likely to be manufacturer, importer or distributor, flagged for review by your legal department or counsel.
03
Initial assessments
For the two or three reference products, the topics needing most clarification, including open questions on the product class, assessed from a technical angle and flagged for review by your legal department or counsel.
04
Questions to take away
For each block, the questions your team has to answer internally.
How the workshop runs
From your enquiry to the next steps.
1
Free initial call
Your products, your team, your deadlines. You then receive a proposal with a clearly defined scope.
2
Preparation
You choose the reference products and participants and share what already exists: product list, certificates, customer requirements.
3
Workshop
The four blocks with your team, on site or by video conference, as agreed, each applied to the reference products.
4
Next steps
Your team completes the product list and answers the open questions. A gap analysis can follow if you wish.
Learning on your own products
Before the session you pick two or three reference products. We check the requirements against these products during the session and record anything that cannot be settled as an open point.
The blocks come with questions to take away, which your team answers internally after the session. For example: which models will you still ship after December 2027? Who decides at the weekend whether a vulnerability is actively exploited and has to be reported? Which end date of the support period can you commit to today for each product?
The workshop and the gap analysis
You can commission the workshop on its own. It can also be the kick-off of the CRA gap analysis: the product list and roles from the workshop become its starting point, and the gap analysis then reviews code, documents and tools and delivers a gap report per product with an action plan. Whether you take that step is your decision after the workshop.
What we do not do
So that expectations are right:
- No legal services: we give a technical assessment of role, scope and product class and flag it for review by your legal department or counsel.
- No notified body, no certification: the workshop does not replace a conformity assessment, and we issue neither notified body certificates nor cybersecurity certificates for your products.
- Penetration tests are not part of our services.
- The workshop is not a gap analysis: code, documents and tools are reviewed in the gap analysis.
The CRA obligations remain with your company. We help you meet them and document the evidence.
Frequently asked questions
Is CRA training mandatory?+
The CRA contains no express training obligation for manufacturers’ staff. Recital 23, however, states that manufacturers should ensure their staff has the necessary skills to comply with their obligations under the Regulation. Member States promote skills development (Art. 10) and, where appropriate, organise training activities for microenterprises and small enterprises (Art. 33(1)). If you demonstrate conformity through full quality assurance under module H, the quality system covers qualification reports on the personnel concerned (Annex VIII Part IV).
How does the workshop differ from an open seminar?+
The workshop is run for your company only. We work with your products, your supply relationships and your existing evidence, and your team can discuss internal processes without outside participants.
Can the workshop be held remotely?+
Yes. It takes place on site or by video conference, as agreed.
What does the CRA workshop cost?+
It depends on the scope, for instance the number of reference products and whether the workshop is held on site or by video conference. After a free initial call you receive a proposal with a clearly defined scope.
Further reading
- CRA gap analysis: the next step
- Does my product fall under the CRA?
- CRA product classes explained
- CRA checklist in nine steps
- CRA consulting: all services
This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).
Last updated: 2026-10-09
Kontakt aufnehmen
Request a CRA workshop
Tell us about your products and who from your team should take part. The initial call is free and without obligation.