Skip to content
Gdańsk Bay Tech Innovation ecosystem calendar · Pomerania
/
← All events

Training CRA - Gdańsk - Training in Gdańsk, 25.09.2026

When Friday, 25 September 2026
Time 09:00
City Gdańsk

FREE TRAINING

Cyber Resistance Act (CRA) in practice

Full-day practical training on Cyber Resilience Act (CRA) and preparing products and organizations for new cybersecurity requirements.

We will go through the whole process of compliance with CRA: from determining whether the regulation concerns your product, through security by design, SBOM, Threat modeling and management of susceptibility to technical documentation, conformity assessment, CE marking and post-market obligations.

WHY IS CRA TO BE PROVIDED NOW?

Report obligations of CRAs start to apply on September 11, 2026

From that day on, manufacturers have to report on m.in. actively exploited vulnerability and serious safety incidents. The full application of most CRA requirements will start on 11 December 2027, but the preparation of documentation, safety processes, SBOM and three modeling is worth starting much earlier.

Select Date

CITY

21 September 2026

University of Gdańsk Institute of Computer Science, ul. Welcome to your 57

🕘 9:00-17:00

CITY

25 September 2026

University of Gdańsk Institute of Computer Science, ul. Welcome to your 57

🕘 9:00-17:00

Free share

After acceptance of the application

Limited number of seats

Notifications shall be verified

Practical nature

Examples and exercises

No recording

Prohibition of video recording

Who is this training for?

The training is addressed to those responsible for creating, security, development and marketing software products or digital communications.

✓ Product managers and engineers

  • Specialists for cybersecurity

❌ Product Security

✓ Compliance and CE certification

Producers, importers and distributors

✓ Open-source software stewards

You don't have to know the CRA. We start training from scratch and gradually move on to practical issues.

What will you learn?

How to determine whether your product is subject to CRA and to which category of product it qualifies.

How to translate CRA requirements into concrete design decisions including secure by design, secure by default and limiting the surface of the attack.

How to create and use SBOM in formats such as CycloneDX and SPDX.

How to conduct three modeling using STRIDE, data flow diagrams and trust zones.

How to prepare the process of handling susceptibility and incidents including reporting required by the article. 14 CRAs.

How to prepare documentation and conformity assessment and when and under what conditions the CE marking shall be used.

What obligations remain after placing the product on the market, including susceptibility monitoring, support period and safe updates.

CRA + NIS2 / UoKSC

During the training we will also show where CRA as product regulation meets NIS2 and UoKSC as organization regulations. The aim is to build coherent safety processes and avoid unnecessary duplication of work.

Training programme

8 hours of practical work with Cyber Resistance Act requirements.

BLOOK A

What is CRA and who is it about?

Scope of regulation, products covered by CRA, roles of manufacturer, importer and distributor, product categories and conformity assessment basis. CRA's relationship with NIS2 and UoKSC.

BLOOK B

Product safety requirements

Annex I CRA: Secure by design, secure by default, confidentiality, integrity and availability of data, minimizing of attack surfaces, lack of universal passwords and secure coding in practice.

☕ Lunch break 12:30-13:15

BLOOK C

Sensitivity management and SBOM

Software Bill of Materials, CycloneDX/SPDX formats, component inventory, and the use of SBOM as a basis for effective vulnerability management.

BLOOK D

Threat modeling and surface attack

STRIDE, data flow diagrams, trust zones and product hazard modelling. We will show why safety should be the process of the entire product development cycle. The block contains a workshop exercise.

☕ 15:15-15:30 break

BLOOK E

Art. 14 CRA: reporting of susceptibility and incidents

Reporting obligations in force from 11 September 2026: early warning within 24 hours, subsequent reporting stages and preparation of the internal process of handling incidents and susceptibility.

BLOOK F

Documentation, conformity assessment and CE

Technical documentation in accordance with Annex VII, the conformity assessment procedures, module A, the EU declaration of conformity and the application of the CE marking.

BLOOK G

Postmarketing

Sensitivity monitoring, declared support period, safe updates, incident handling and product compliance throughout its support period.

Important

The number of seats is limited. Sending the form does not mean automatic participation in the training. Applications will be reviewed and qualified persons will receive separate confirmation of participation.

Organisational information

Place: Institute of Computer Science, University of Gdańsk, ul. Hello, 57, Gdansk

⏱️ Time: 9:00-17:00

🎟️ Cost: free

📵 Recording: training is not recorded; video recording is prohibited during the event

Organizers: CODE:ME Foundation / szkoleniazcra.com. pl / Thakaamed Poland / Andrzej Piotrowski

FAQ

Frequently asked questions.

Is participation in training free of charge?

Yeah. Participation is free, but requires prior notification and acceptance.

Does sending a form guarantee a place?

Nope. The number of seats is limited and each application will be verified. We will inform you about qualifying for training separately.

Do you need to know the CRA before?

Nope. We start the training from scratch and then move on to practical aspects of implementing CRA requirements in the organization and product.

Will the training be recorded?

Nope. The training will not be recorded or later made available online. During the event there is also a ban on video recording by participants.

Is the training technical or legal?

It combines both eyes. We focus primarily on the practical shift of CRA requirements to the process of creating, developing, securing and maintaining the product.

Machine translation. The English version was produced by machine translation. The organiser's page is authoritative.