Meet CRACoWi at CRA Standards Unlocked in Bonn

📅7 October 2026 | 9:00 – 17:00 CEST | CITYHUB, Am Hauptbahnhof 6, Bonn| Hybrid | English & Germany | Free

The CRACoWi team is heading to Bonn!

On 7 October 2026, CRACoWi will join fellow European projects, cybersecurity experts, standardisation specialists and companies at CRA Standards Unlocked – EU Tour in Bonn, part of a European workshop series dedicated to helping organisations understand and prepare for the Cyber Resilience Act (CRA).

CRACoWi partners Bureau Veritas, SevenShift, ONEKEY and Erminas will be there, and we invite companies, SMEs and other stakeholders working on CRA compliance to join us and meet the team.

From CRA Requirements to Standards and Practical Compliance

As companies move from understanding the Cyber Resilience Act towards its practical implementation, questions around standards are becoming increasingly important.

Which standards will support CRA compliance? How are harmonised standards being developed? What will they mean for product development and conformity assessment? And what practical tools are already available to help companies prepare?

CRA Standards Unlocked will bring these discussions together in one place.

The programme will cover the CRA standardisation process and the roles of European and national standardisation organisations, followed by presentations on horizontal and product-specific standards currently under development.

Participants will also hear about CRA market surveillance, implementation from a manufacturer’s perspective and how CRA compliance could influence the European digital single market and cybersecurity landscape.

Discover CRA Compliance Tools and Support

Understanding the standards is only one part of preparing for the CRA. Companies also need practical ways to translate regulatory requirements into their own processes and products.

Dedicated sessions at the event will therefore introduce compliance tools and funding opportunities being developed through Digital Europe Programme projects.

This is also where collaboration between projects working within the wider CRA ecosystem becomes particularly valuable. By bringing together different expertise, tools and approaches, CRA Cluster initiatives can help companies find the support that best responds to their specific compliance challenges.

CRACoWi is contributing to this effort by developing practical support for organisations navigating the CRA, including the CRACoWi Wizard, CRAcademy resources and the free CRA Scope Assessment.

Meet the CRACoWi Team in Bonn

For CRACoWi, events such as CRA Standards Unlocked are an important opportunity not only to share what we are developing, but also to meet companies directly, hear about their challenges and exchange knowledge with other projects working towards practical CRA implementation.

Representatives from Bureau Veritas, SevenShift, ONEKEY and OIXIO Erminas will represent CRACoWi in Bonn.

If you are preparing for the CRA, working with products with digital elements or simply want to understand how standards and practical compliance tools can support your organisation, come and meet the CRACoWi team.

📅 7 October 2026 | 09:00–17:00
📍 CITYHUB, Am Hauptbahnhof 6, 53111 Bonn, Germany
💻 Hybrid event – onsite and online participation

Onsite participation is limited, so make sure to register in advance.

Join us in Bonn and be part of the conversation on turning CRA requirements and standards into practical compliance.

Join CRACoWi at Cyber Day 2026 in Ljubljana

📅15 October 2026 | 9:00 – 15:00 CEST | Ljubljana.tech, BTC Ljubljana | English | Free

How can companies move from understanding cybersecurity requirements to actually implementing them?

On 15 October 2026, CRACoWi will join cybersecurity experts, companies and European initiatives at Cyber Day 2026 in Ljubljana, an event dedicated to turning cybersecurity requirements into practical action and strengthening the cyber resilience of European companies.

As a partner of the event, CRACoWi will contribute its expertise on the Cyber Resilience Act (CRA) and present some of the practical support being developed to help companies navigate the path towards compliance.

Cyber Day will take place from 09:00 to 15:00 at Ljubljana.tech, Trg mladih 9, Ljubljana.

From CRA Requirements to Practical Action

The Cyber Resilience Act introduces new cybersecurity requirements for products with digital elements, creating new responsibilities for companies across the product lifecycle. For many SMEs, the challenge is not only understanding these requirements but also knowing how to approach them in practice. This will be one of the key topics addressed at Cyber Day.

Michael Beine from Bureau Veritas, CRACoWi partner and cybersecurity and regulatory compliance expert, will present “CRA Explained for SMEs”, looking at what the regulation means specifically for smaller companies.

This will be followed by a CRACoWi tools demonstration by Jacek Trossen from ONEKEY, giving participants an opportunity to learn more about the practical support being developed within the project.

The programme will continue by moving from compliance to action, including a panel discussion dedicated to the question “How can SMEs become cyber resilient?”

Meet the Wider Cybersecurity Ecosystem

Cyber Day is not only about understanding regulation. It is also an opportunity to discover the organisations, projects, tools and funding opportunities available to companies working to strengthen their cybersecurity.

The programme will bring together representatives of the CRA Cluster and several Digital Europe projects, including CyberSynchrony, ALiEnS-SOC and INTERCEPT.

Participants will also hear about the wider cybersecurity support ecosystem and EU funding opportunities for cyber resilience.

Alongside the conference programme, the Cybervillage will provide space to meet experts, European projects and support organisations directly, exchange experiences and explore opportunities for further cooperation.

Who Should Join?

Cyber Day is designed particularly for micro, small and medium-sized enterprises looking to strengthen their cyber resilience and better understand the regulatory requirements affecting their businesses.

The event will be especially relevant for companies preparing for the Cyber Resilience Act, organisations looking for practical cybersecurity support, and stakeholders interested in the European cybersecurity ecosystem, available tools and EU funding opportunities.

Whether you are already working on CRA compliance or are only beginning to understand what the new requirements mean for your organisation, Cyber Day provides an opportunity to ask questions, meet experts and discover the support already available.

Meet CRACoWi in Ljubljana

For CRACoWi, Cyber Day is also an opportunity to meet companies directly, better understand the challenges they face and present the practical support the project is developing for CRA implementation.

If the Cyber Resilience Act is on your agenda, come and meet the CRACoWi team in Ljubljana. Talk to our experts, learn more about the project and discover how CRACoWi can support your journey towards CRA compliance.

15 October 2026 | 09:00–15:00
Ljubljana.tech, Trg mladih 9, Ljubljana

Participation is free of charge, but registration is required.

Join us at Cyber Day 2026 and be part of the conversation on turning cybersecurity requirements into practical action.

CRACoWi Featured by Frank Bold in Its CRA Support Series for SMEs

CRACoWi has been featured in a new article by Frank Bold, introducing the project and the support it offers to small and medium-sized enterprises preparing for the Cyber Resilience Act (CRA).

The article, published on 17 September, is part of a series aimed at helping Czech companies navigate CRA implementation by introducing European projects, resources and tools that can support them in this process. In the latest interview, KristĂ­na Ĺ abová from Frank Bold speaks with Sandra Bortek, representing the CRACoWi project, about the practical support CRACoWi can provide to SMEs and how Czech companies can benefit from the project’s activities.

Bringing CRACoWi closer to Czech SMEs

The interview introduces CRACoWi’s overall objective and the tools and resources being developed to make CRA compliance more manageable, particularly for SMEs, manufacturers, importers and distributors of products with digital elements.

One of the resources highlighted is the CRA Scope Check, already freely available through the CRACoWi website. The tool helps companies make an initial assessment of whether their product or service falls within the scope of the CRA. The interview also introduces the project’s CRAcademy, which provides webinars, workshops, FAQs, expert articles and other practical resources related to CRA implementation.

The discussion also covers the types of SMEs that can benefit from CRACoWi, the project’s ongoing use cases and pilots, and practical first steps for companies beginning their CRA compliance journey. Importantly, CRACoWi resources are available to SMEs across the EU, including companies based in the Czech Republic.

Extending CRACoWi’s reach through collaboration

Collaboration with organisations such as Frank Bold helps CRACoWi bring project knowledge and resources closer to companies in different European countries and connect with national SME communities.

We would like to thank Frank Bold and Kristína Šabová for the opportunity to introduce CRACoWi to their Czech audience and for supporting the dissemination of information about the tools and resources available to companies preparing for the CRA.

The full interview is available in Czech on the Frank Bold website: Read the full CRACoWi interview on Frank Bold

CRACoWi will continue developing and sharing practical resources through the CRAcademy and its other project activities to support companies in understanding and preparing for CRA requirements.

New CRAcademy Resource – The CRA Compliance Glossary

Understanding the Cyber Resilience Act (CRA) starts with understanding its language and that language isn’t always easy to navigate. Legal terminology, technical acronyms, and compliance concepts are scattered across the regulation and its supporting standards, often without a clear, accessible explanation in one place.

To close that gap, CRACoWi partners have developed the CRA Compliance Glossary, now available as a new resource on the CRAcademy hub. Built as part of CRAcademy’s mission to provide clear and practical information about the CRA (through FAQs, blogs, expert insights, and more) the glossary is designed to be your quick reference whenever CRA terminology gets in the way of getting things done.

The Glossary

The glossary brings together plain-language definitions of the terms, acronyms, and concepts that come up throughout the CRA compliance journey — from foundational security properties like confidentiality, integrity, and availability, to CRA-specific mechanisms such as the Declaration of Conformity, CE marking, and conformity assessment routes. It also covers the technical vocabulary manufacturers and product teams encounter in practice: SBOMs, SAST/DAST testing, threat modelling frameworks like STRIDE, vulnerability disclosure policies, and more.

Each entry is written to be understood without a legal or cybersecurity background, while staying precise enough to be useful for teams already deep in their compliance work.

The Cyber Resilience Act establishes uniform cybersecurity criteria for digital products placed on the EU market, covering the entire product lifecycle from design through decommissioning. For manufacturers, importers, and distributors (particularly SMEs without dedicated legal or cybersecurity teams) getting familiar with this vocabulary is often the first practical step toward compliance, well before documentation or technical measures come into play.

Available as a free PDF on Zenodo

For those who prefer to save, print, or share the glossary offline, a PDF version of the CRA Compliance Glossary has also been published as an open-access download on Zenodo, ensuring the resource remains freely and permanently available to the wider CRA compliance community.

Part of a growing CRAcademy toolkit

The glossary joins the CRAcademy webinar series and other capacity-building resources already available on the platform, reinforcing CRACoWi’s broader goal: helping SMEs, manufacturers, distributors, and importers meet new cybersecurity standards throughout the product lifecycle.

CRACoWi Reaches Midpoint Milestone and Advances Toward Midterm Review in Athens

The CRACoWi consortium met in Athens last week for its latest plenary meeting, marking an important milestone as the project reached Month 18 of its implementation. The meeting focused on assessing progress, aligning next steps, and preparing for the upcoming midterm review.

Now halfway through its 36-month journey, CRACoWi continues to advance its core objective of supporting companies in meeting the requirements of the Cyber Resilience Act (CRA). As the regulation introduces mandatory cybersecurity obligations for products with digital elements, the project is developing a practical Compliance Wizard to help SMEs, manufacturers, distributors, and importers navigate these requirements in a structured and accessible way.

At this stage, the project has moved beyond initial setup and into tangible implementation. In parallel, partners are actively working on use cases covering critical infrastructure and market actors such as importers and distributors, ensuring that the tool reflects real-world compliance challenges.

Beyond technical development, CRACoWi has established a strong foundation for stakeholder engagement and capacity building. Through initiatives such as the CRAcademywebinar series and targeted communication activities, the project is already reaching its key audiences and building awareness around CRA requirements and practical compliance pathways.

The Athens meeting served as a key checkpoint, confirming that the project is progressing according to plan and is well-positioned for the midterm review. Partners aligned on the consolidation of results, upcoming deliverables, and the next phase of development, which will focus on further validation, stakeholder uptake, and scaling of the solution.

As Europe moves closer to the implementation of the Cyber Resilience Act, initiatives like CRACoWi are becoming increasingly important. The project plays a critical role in translating complex regulatory requirements into practical tools that businesses can actually use, reducing the compliance burden and supporting a more secure and resilient digital market.

CRACoWi project at the CRA Webinar for Dutch SMEs

We are delighted that CRACoWi projectwas invited to participate in the Cyber Resilience Act (CRA) Webinar on 11 November, organized by the Dutch Ministry of Economic Affairs and the National Cybersecurity Center of the Netherlands (NCC NL).

The webinar aimed to help Dutch SMEs understand the Cyber Resilience Act and prepare for compliance with the upcoming regulation. Two EU-funded projects, CRACoWi and SECURE, were featured during the session,

Eleftheria Marini (ITML) as Project Coordinator of CRACoWi, provided an overview of the the project’s goals and impact in supporting European SMEs toward CRA compliance, with a special focus on how CRACoWi can benefit end users, particularly SMEs developing or deploying digital products.

Pablo Endres (SevenShift) presented the technical perspective, offering a high-level overview of the technologies and tools being developed, including the Cyber Resilience Act Compliance Wizard, an AI-supported framework for automated cybersecurity assessment, documentation and certification support.

The event was an important step in raising awareness and enhancing collaboration around CRA implementation across Europe, showcasing how initiatives like CRACoWi and SECURE contribute to empowering SMEs toward a more secure digital future.

CRACoWi Consortium Meets in Maribor to Accelerate Cybersecurity Compliance for European SMEs

The city of Maribor recently hosted the 2nd Plenary Consortium Meeting of the CRACoWi project, bringing together 14 expert partners from across Europe to align on progress and define the next strategic steps toward simplifying cybersecurity compliance for businesses across the EU.

Over two days of in-depth collaboration (30 September – 1 October 2025), the CRACoWi consortium advanced its mission of supporting small and medium-sized enterprises (SMEs), manufacturers, importers, and distributors in complying with the EU Cyber Resilience Act (CRA) – a new legislative milestone aimed at improving the security of digital products throughout their lifecycle.

The CRACoWi (Cyber Resilience Act Compliance Wizard) project, funded under the Digital Europe Programme and supported by the European Cybersecurity Competence Centre (ECCC), is developing a user-friendly Compliance Wizard – a step-by-step digital tool that helps businesses understand and fulfil their CRA obligations.

As the CRA imposes strict new requirements for placing connected products on the EU market, CRACoWi fills a crucial gap by offering practical, hands-on support tailored to the needs of companies that may lack dedicated cybersecurity or legal teams.

The plenary meeting featured updates on all technical and strategic work packages, combined with hands-on workshops and valuable peer-to-peer learning. Partners engaged in a live walkthrough of CRACoWi in a Use Case Workshop where they identified documentation gaps, and performed tailored threat modelling for OT and IoT devices. The consortium worked in focused groups covering critical infrastructure, importers/distributors, and compliance documentation, fostering a strong foundation for the next project phases.

This plenary also included a dedicated CRAcademy session focused on certification and standardisation processes and vulnerability handling obligations for manufacturers, distributors and importers of the digital products. Not less important was a session for  communication, dissemination and KPI tracking to ensure that CRACoWi’s message and resources reach the right stakeholders.

“This meeting proved once again that strong collaboration and a shared mission can turn complex legislation into practical solutions. CRACoWi is not just about compliance – it’s about empowering the European ecosystem to thrive securely,” said coordinator George Bravos, ITML.

As Europe prepares for the full enforcement of the Cyber Resilience Act, CRACoWi stands out as a pioneering project that transforms regulation into action. By helping SMEs and other economic operators navigate the complexities of the CRA, the project contributes directly to the EU’s goal of a digitally secure, innovation-driven internal market.

This time, the plenary meeting was organised by Tiko Pro, a consortium partner leading the work package for communication and dissemination. Tiko Pro ensured everything ran smoothly while also offering partners the chance to enjoy true Slovenian hospitality.

CRACoWi`s 2nd Plenary Meeting

On February 12–13, 2025, the CRACoWi consortium convened in DĂĽsseldorf, Germany, for its second Plenary Meeting – a key milestone in the project’s first year of implementation. The event brought together all 14 partners to evaluate progress, exchange insights, and align efforts in delivering on CRACoWi’s mission: helping SMEs and manufacturers navigate the new Cyber Resilience Act (CRA) requirements with ease.

The two-day meeting was hosted by ONEKEY, one of the consortium partners and a leading force in embedded cybersecurity. The gathering was a timely opportunity to reflect on achievements so far and to strategically plan for the next phases of development.

The first day was dedicated to Work Package (WP) updates, providing a comprehensive overview of each technical, legal, dissemination, and capacity-building activity currently underway. Partners shared developments in the creation of the Compliance Wizard, stakeholder engagement, and the integration of regulatory frameworks (CRA, RED, NIS2). The session ensured that the project remains on track across all its pillars: compliance automation, stakeholder support, and cybersecurity awareness. The second day zoomed in on the use cases, offering a hands-on perspective into how CRACoWi technologies will be tested and validated in real-world environments and what challenges are in front of the consortium.

Beyond the formal agenda, the plenary was marked by genuine collaboration, problem-solving, and open dialogue. The evening social dinner provided an informal space for further exchange, reinforcing the strong consortium ties and mutual commitment to the project’s success.

As the CRACoWi project gains momentum, the consortium remains focused on delivering tangible, user-friendly tools to empower European companies – especially SMEs – in meeting the cybersecurity requirements of the Cyber Resilience Act.

A special thank you goes to ONEKEY for hosting us in DĂĽsseldorf and to ITML, the project coordinator, for guiding the process with clarity and dedication.

CRACoWi White Paper

The digitalization of the global economy is driving a massive shift in consumer and business behaviors, creating an interconnected ecosystem of billions of devices and millions of applications. This exponential growth amplifies the importance of robust cybersecurity measures, especially as critical infrastructures like energy, healthcare, and financial services become increasingly reliant on digital technologies.

Recognizing these challenges, the EU has introduced the Cyber Resilience Act (CRA) to establish mandatory cybersecurity requirements for products with digital elements. To support organizations in meeting these stringent standards, the CRACoWi project has developed an innovative solution – the Cyber Resilience Act Compliance Wizard. This white paper explores the critical role of CRACoWi in helping SMEs navigate the complexities of CRA compliance.

A few topics from the document:

  • The emerging cybersecurity risks for critical infrastructures and IoT ecosystems.How the CRA establishes a secure framework for digital products through lifecycle management and vulnerability reduction.
  • The role of the CRACoWi Compliance Wizard in automating compliance, documentation, and certification processes for SMEs.
  • Real-world applications of CRACoWi tools, showcasing their adaptability across industries and product categories.
  • The strategic importance of collaboration between regulatory bodies, industry leaders, and innovative SMEs to ensure a resilient digital future.

SMEs play a vital role in the EU’s digital economy but often face challenges in meeting complex regulatory requirements. This white paper outlines practical solutions provided by CRACoWi, including automated compliance assessments, AI-powered self-assessment tools, and lifecycle security management methodologies. It highlights how CRACoWi enables SMEs to strengthen product security, reduce compliance burdens, and maintain a competitive edge in a rapidly evolving market.

Gain comprehensive insights about CRACoWi: