From 11 September 2026, manufacturers of products with digital elements falling within the scope of the EU Cyber Resilience Act (CRA) will be required to report actively exploited vulnerabilities and severe incidents affecting the security of their products. These reporting obligations include an early warning within 24 hours of becoming aware of the vulnerability or incident and apply also to products already placed on the EU market.
This webinar will provide a practical introduction to these new reporting requirements through the Attestra Academy, the multilingual CRA training platform developed within the EU co-funded CRA-AI project. Using selected Academy video lessons and a live walkthrough, participants will explore what needs to be reported, the applicable reporting timeline and how the CRA Single Reporting Platform will support the notification process. The session will also demonstrate how the Academy helps product and engineering teams build their understanding of CRA requirements through structured lessons, practical case studies, quizzes and supporting resources.
Participating companies will also be offered a free CRA scope and readiness assessment. The webinar will additionally introduce funding opportunities available through the SECURE project, which provides eligible European MSMEs with 50% co-financing for CRA-related projects, up to a maximum contribution of EUR 30,000 per project.
Who should attend:
Founders, product managers, engineering leads, quality managers and other professionals involved in developing or managing hardware and software products with digital elements for the EU market, as well as advisors supporting organisations with CRA compliance.
Agenda (CEST)
12:00 – 12:05 Welcome and the CRA-AI project
12:05 – 12:10 The 11 September obligation, in brief
12:10 – 12:30 The obligation, taught by the Academy
12:30 – 12:40 See how the Academy works
12:40 – 12:45 Attestra AI Introduction
12:45 – 12:50 Free assessment, Academy offer and SECURE funding
12:50 – 13:00 Questions and closing