The Cyber Resilience Act (CRA): Foundations
What the EU Cyber Resilience Act (Regulation 2024/2847) is and who it applies to: products with digital elements, the timeline through 2027, the roles of manufacturer, importer and distributor, and the tricky edge cases: standalone SaaS, remote data processing and open source. This basic course takes you up to and including the scope question; the essential requirements, vulnerability handling and reporting obligations, product classes, conformity assessment routes, CE marking and penalties are covered in the Advanced course. Complements NIS2 and the Dutch Cbw (Cyberbeveiligingswet, the Dutch act implementing NIS2).
What you'll work through
- What is the CRA, and why now?
This module introduces the Cyber Resilience Act: what the regulation is, the implementation timeline through 2027, which products fall within scope, and how it relates to NIS2 and the Dutch Cbw. - Who does the CRA apply to? Scope and roles
This module explains which products fall under the CRA, where the line runs for cloud services, and which obligations manufacturers, importers, distributors and open-source software stewards each carry.
Start the course (no account needed)
Content last updated: 2026-08-24.