SEC10Cyber Resilience Act (CRA) for Embedded Systems
Objectives
|
- Embedded Systems Engineers building products with digital elements
- Firmware Architects designing systems for compliance
- Product Managers overseeing compliance and communicating
- Manufacturing & Supply Chain teams responsible for product security at all stages
- Basic Knowledge of Embedded Systems
- LIVE ONLINE
- Interactive virtual classroom with remote lab access, digital materials, same expertise as classroom format, available for distributed teams
- ON-SITE/PRIVATE (Your Facility)
- Customized to your products, your schedule, your team. Can be tailored to your specific industry or product type.
- Theoretical course
- PDF material in English (printed for face-to-face); online over Teams.
- Trainer assistance throughout.
- Each session starts with a trainee check-in.
- Prerequisites are checked before the training.
- Progress is assessed by quizzes at the end of sections.
- Each trainee receives a completion certificate.
- If a prerequisite gap appears, alternative or additional training is offered.
Course Outline
- Why CRA Matters Now
- CRA Scope & Applicability - Product classification
- CRA vs. Related EU Regulations
- CRA Timeline & Entry Into Force
- Secure Design & Development
- Threat modeling
- Design principles
- Vulnerability Management
- Lifecycle approach (discover -> assess -> remediate -> deploy)
- Transparency & User Information
- Required disclosures
- Communication channels
- Handling Substantial Modifications
- Decision matrix approach
- CRA Classification: Important vs. Critical
- CE Marking & Conformity Assessment
- self-cert vs. notified body
- Technical Docs.
- Case study: Applying conformity assessments to embedded systems
- Industrial IoT gateway example
- Step-by-step walkthrough
- Assessment Pathway Selection Activity
- Manufacturer Obligations
- Pre-market, post-market, end-of-life phases
- Support period expectations
- clear responsibility mapping
- Supply Chain Security
- Due diligence requirements
- Open source considerations
- Risk assessment matrix
- Risk assessment & Due diligence
- 6-step framework
- CVSS scoring explained
- Security Solutions
- Secure boot architecture
- Hardware security options (TPMs, Secure Elements)
- RTOS & OS Security Features
- Comparison table (Zephyr, Linux, FreeRTOS)
- CRA readiness scores
- Compliance Tools and Frameworks
- Vulnerability scanning tools (e.g., CVE checkers)
- Compliance management platforms
- Security testing frameworks
More
To book a training session or for more information, please contact us on info@ac6-training.com.
Registrations are accepted till one week before the start date for scheduled classes. For late registrations, please consult us.
You can also fill and send us the registration form
This course can be provided either remotely, in our Paris training center or worldwide on your premises.
Scheduled classes are confirmed as soon as there is two confirmed bookings. Bookings are accepted until 1 week before the course start.
Last update of course schedule: 27 June 2026
Booking one of our trainings is subject to our General Terms of Sales
Related Courses
C1
Effective MISRA C
C2
MISRA Compliance for Project Managers
SEC1
Developing C/C++ Secure Embedded Systems
SEC11
NIS2 for Embedded
SEC12
Comprehensive Secure Systems Programming
SEC2
Advanced Embedded Systems Security
SEC5
Embedded Security for STM32-based devices
SEC6
Embedded Security for NXP i.MX-based processors
SEC7
ARM TrustZone for Cortex-M based devices
SEC8
Secured Embedded Linux Platform Build
SEC9
Advanced Embedded Linux Security