Meet CRACoWi at CRA Standards Unlocked in Bonn

📅7 October 2026 | 9:00 – 17:00 CEST | CITYHUB, Am Hauptbahnhof 6, Bonn| Hybrid | English & Germany | Free

The CRACoWi team is heading to Bonn!

On 7 October 2026, CRACoWi will join fellow European projects, cybersecurity experts, standardisation specialists and companies at CRA Standards Unlocked – EU Tour in Bonn, part of a European workshop series dedicated to helping organisations understand and prepare for the Cyber Resilience Act (CRA).

CRACoWi partners Bureau Veritas, SevenShift, ONEKEY and Erminas will be there, and we invite companies, SMEs and other stakeholders working on CRA compliance to join us and meet the team.

From CRA Requirements to Standards and Practical Compliance

As companies move from understanding the Cyber Resilience Act towards its practical implementation, questions around standards are becoming increasingly important.

Which standards will support CRA compliance? How are harmonised standards being developed? What will they mean for product development and conformity assessment? And what practical tools are already available to help companies prepare?

CRA Standards Unlocked will bring these discussions together in one place.

The programme will cover the CRA standardisation process and the roles of European and national standardisation organisations, followed by presentations on horizontal and product-specific standards currently under development.

Participants will also hear about CRA market surveillance, implementation from a manufacturer’s perspective and how CRA compliance could influence the European digital single market and cybersecurity landscape.

Discover CRA Compliance Tools and Support

Understanding the standards is only one part of preparing for the CRA. Companies also need practical ways to translate regulatory requirements into their own processes and products.

Dedicated sessions at the event will therefore introduce compliance tools and funding opportunities being developed through Digital Europe Programme projects.

This is also where collaboration between projects working within the wider CRA ecosystem becomes particularly valuable. By bringing together different expertise, tools and approaches, CRA Cluster initiatives can help companies find the support that best responds to their specific compliance challenges.

CRACoWi is contributing to this effort by developing practical support for organisations navigating the CRA, including the CRACoWi Wizard, CRAcademy resources and the free CRA Scope Assessment.

Meet the CRACoWi Team in Bonn

For CRACoWi, events such as CRA Standards Unlocked are an important opportunity not only to share what we are developing, but also to meet companies directly, hear about their challenges and exchange knowledge with other projects working towards practical CRA implementation.

Representatives from Bureau Veritas, SevenShift, ONEKEY and OIXIO Erminas will represent CRACoWi in Bonn.

If you are preparing for the CRA, working with products with digital elements or simply want to understand how standards and practical compliance tools can support your organisation, come and meet the CRACoWi team.

📅 7 October 2026 | 09:00–17:00
📍 CITYHUB, Am Hauptbahnhof 6, 53111 Bonn, Germany
💻 Hybrid event – onsite and online participation

Onsite participation is limited, so make sure to register in advance.

Join us in Bonn and be part of the conversation on turning CRA requirements and standards into practical compliance.

CRACoWi Featured by Frank Bold in Its CRA Support Series for SMEs

CRACoWi has been featured in a new article by Frank Bold, introducing the project and the support it offers to small and medium-sized enterprises preparing for the Cyber Resilience Act (CRA).

The article, published on 17 September, is part of a series aimed at helping Czech companies navigate CRA implementation by introducing European projects, resources and tools that can support them in this process. In the latest interview, Kristína Šabová from Frank Bold speaks with Sandra Bortek, representing the CRACoWi project, about the practical support CRACoWi can provide to SMEs and how Czech companies can benefit from the project’s activities.

Bringing CRACoWi closer to Czech SMEs

The interview introduces CRACoWi’s overall objective and the tools and resources being developed to make CRA compliance more manageable, particularly for SMEs, manufacturers, importers and distributors of products with digital elements.

One of the resources highlighted is the CRA Scope Check, already freely available through the CRACoWi website. The tool helps companies make an initial assessment of whether their product or service falls within the scope of the CRA. The interview also introduces the project’s CRAcademy, which provides webinars, workshops, FAQs, expert articles and other practical resources related to CRA implementation.

The discussion also covers the types of SMEs that can benefit from CRACoWi, the project’s ongoing use cases and pilots, and practical first steps for companies beginning their CRA compliance journey. Importantly, CRACoWi resources are available to SMEs across the EU, including companies based in the Czech Republic.

Extending CRACoWi’s reach through collaboration

Collaboration with organisations such as Frank Bold helps CRACoWi bring project knowledge and resources closer to companies in different European countries and connect with national SME communities.

We would like to thank Frank Bold and Kristína Šabová for the opportunity to introduce CRACoWi to their Czech audience and for supporting the dissemination of information about the tools and resources available to companies preparing for the CRA.

The full interview is available in Czech on the Frank Bold website: Read the full CRACoWi interview on Frank Bold

CRACoWi will continue developing and sharing practical resources through the CRAcademy and its other project activities to support companies in understanding and preparing for CRA requirements.

CRA Update After the Summer Break

The Cyber Resilience Act landscape continues to move quickly and after the summer break, there is quite a lot to catch up on.

Our CRACoWi partner and CRA expert Michael Beine from Bureau Veritas has put together a practical overview of some of the latest developments, from the European Commission’s CRA Guidance and ENISA’s SME maturity assessment tool to the Single Reporting Platform, Notified Bodies and ongoing standardisation work.

If you lost track of some of the developments over the summer, this is a good place to catch up. Michael’s overview provides a quick read, together with links for those who want to explore individual topics in more detail.

CRA Guidance

The European Commission released the official CRA Guidance at the end of July.

This is a must-read for organisations preparing for CRA implementation. After the legal text itself, the Guidance provides an important source for interpreting the Regulation and brings additional clarity to many, although not all, questions surrounding CRA implementation.

Read more: European Commission – Commission publishes new guidance to support timely Cyber Resilience Act implementation

SME maturity model and tool

ENISA has published a guided self-assessment for CRA readiness, particularly intended to support small and medium-sized enterprises (SMEs).

The SME Cyber Resilience Maturity Assessment Model can help organisations assess their current level of preparedness and identify areas requiring further attention.

Read more:ENISA – SME Cyber Resilience Maturity Assessment Model

Single Reporting Platform (SRP)

ENISA continues to update its FAQs and guidance related to the Single Reporting Platform.

Among the relevant information currently available are the required datasets for the different types of reports.

To avoid unnecessary overload, the current recommendation is not to register in advance, but only when a report needs to be submitted.

Another small but practically relevant detail has recently been updated: up to 21 representatives can now be registered for one manufacturer, compared with two previously.

Read more:ENISA – Single Reporting Platform

CRA Notified Body

The nomination process for CRA Notified Bodies has started in several EU Member States through the relevant national authorities.

Bureau Veritas has submitted its application and is currently participating in the nomination process.

Relevant information on national processes is available from authorities including BSI, DAkkS and ANSSI, as well as through the available information on CRA notifying authorities.

Standardisation

Significant progress has also been made in the development of horizontal standards, including EN 40000-1-1, EN 40000-1-2 and EN 40000-1-3, with final versions becoming available.

Seventeen vertical standards developed by ETSI (i.e. EN 304 xxx) have reached the necessary maturity to enter Enquiry Phase.

Directory Listing /CYBER/EUSR/Open

Work is also continuing on the broad vertical standards (EN IEC 62443 prAA), with the relevant working group convening in Oslo.

Together, these developments show just how quickly the wider CRA implementation ecosystem is progressing and why keeping track of guidance, reporting mechanisms, conformity assessment and standardisation is becoming increasingly important for organisations preparing for compliance.

Meet the expert

Bureau Veritas offers a free 30-minutes “Talk to the expert”.  You are invited to book a suitable time-slot: https://www.bureauveritas.de/cyber-resilience-act-expert-talk

Meet Us at the CRA Standards Unlocked Event in Lisbon

📅17 September 2026 | 9:00 – 17:00 CEST | Venue Auditório da Sede Nacional da Ordem dos Engenheiros, Lisbon | Hybrid | English & Portuguese | Free
CRACoWi consortium partner SevenShift will be attending “CRA Standards Unlocked – EU Tour in Lisbon,” a hybrid workshop dedicated to helping SMEs understand, prepare for, and comply with the EU Cyber Resilience Act (CRA). This whole-day event is organised by the EU-funded projects CYBERSTAND.eu and STAN4CRA.eu, with the support of the Ordem dos Engenheiros.

The session brings together rapporteurs from the European Standardization Organizations (ETSI and CEN-CENELEC), who will present the latest drafts of harmonised CRA standards currently under development and gather feedback directly from attendees.

What you can expect

  • A clear breakdown of what the CRA requires and what it means in practice for SMEs
  • Direct insight into which standards matter and how they support compliance
  • Presentations from CRA standards rapporteurs on the state of ongoing standardisation work
  • An overview of compliance tools, practical guides, and funding opportunities available through CRA-related EU-funded projects
  • Practical guidance tailored to SMEs on how CRA requirements translate into product development and conformity assessment processes

Pablo Endres from SevenShift will represent CRACoWi at the event, sharing insights from the project’s work on the Compliance Wizard and present a Bunkai demo as part of the CRACOWi toolchain.

If you’re attending, we’d love the opportunity to connect – stop by and say hello.

 

CRAcademy UC Workshop: An SME’s Perspective on the CRA

CRACoWi is launching a new workshop series built directly around the project’s real-world use cases – grounding CRA compliance in the day-to-day experience of the organisations actually living it, rather than presenting the regulation in the abstract.

Cybersecurity affects us all – including small and medium-sized enterprises:

📅 2 September 2026 ⌛11:00-12:00 CEST 📍Online, free

This first session features Erminas, a software SME building solutions for industrial digitalisation and one of CRACoWi’s use case partners. Speaking from first-hand experience, Erminas shares what it actually takes to respond to a security incident without a dedicated security department and how the Cyber Resilience Act (CRA) can turn that experience from chaotic firefighting into a structured, manageable process.

Rather than a theoretical overview of the regulation, this online workshop walks through a realistic incident scenario step by step, showing how a few practical tools and habits (not a large security organisation) can meet the CRA’s core demand: traceability.

What you’ll learn:

  • Why SMEs carry the same cybersecurity responsibility as large enterprises, with far fewer resources
  • A real-world walkthrough of responding to a vulnerability: using an SBOM to scope affected products, checking patch status, applying a lightweight threat model, and communicating clearly with customers
  • Practical, low-overhead practices – Security Champions, regular awareness training, and frameworks like the NIST Cybersecurity Framework – for building traceability without building a full security department
  • Why structured processes reduce stress internally and build trust externally, especially in critical moments

Who should attend

Founders, engineering leads, and product teams at SMEs developing or maintaining software or connected products, especially those without a dedicated cybersecurity function and looking for realistic, teamwork-based ways to prepare for CRA compliance.

The presenter: Jonas Gerlach

Cybersecurity Team Lead & IIoT Developer with 8 years of hands-on experience designing, implementing, and securing industrial systems. Passionate about bridging operational technology (OT) and information technology (IT), leading technical teams, and delivering secure, scalable IIoT solutions.

Save the date and register!

📅 2 September 2026 ⌛11:00-12:00 CEST 📍Online, free

New Commission guidance on CRA implementation

Last week the European Commission has published a practical guidance to help manufacturers, developers, and businesses of all sizes meet their obligations under the Cyber Resilience Act – timely news for everyone in our community preparing for compliance.

The guidance clarifies some of the questions manufacturers ask us most often, including:

  • When products fall in scope – including remote data processing solutions and free and open source software
  • What counts as a “substantial modification”
  • How to interpret support periods
  • Reporting obligations and risk assessment requirements

Good news for SMEs in particular: the guidance includes 67 practical examples, use cases, flowcharts, and graphs to make the path to compliance clearer and more proportionate.

Good to keep in mind:

  • Reporting obligations already apply from 11 September 2026
  • Main CRA obligations apply from 11 December 2027

This is exactly the kind of regulatory clarity CRACoWi is built to help manufacturers translate into action.

Read more and download the guidance here: Commission publishes new guidance to support timely Cyber Resilience Act implementation

Event: Building Cyber Resilience in the Digital Era

A joint workshop on NIS2 compliance, CRA enforcement, and cross-border cybersecurity incident response.

📅 Friday, 2 October 2026 🕘 09:00 – 16:00 📍 Electra Palace Athens – 18-20 N. Nikodimou str, 10557 Athens, Greece 🌐 Language: English

The EU cybersecurity regulatory landscape is evolving fast – and organisations across every sector are being asked to keep pace. Building Cyber Resilience in the Digital Era is a high-impact workshop organised by the EU-funded projects CRACoWi, DETANGLE, and INCIDENTRON, bringing together policy, practice, and peer projects for a single day of focused, practical exchange.

The event centres on three interconnected themes shaping the future of digital resilience in Europe:

  • NIS2 compliance – what implementation really looks like in practice
  • Cyber Resilience Act (CRA) enforcement – what to expect as the regulation takes hold
  • Collaborative, cross-border cybersecurity incident response – how sectors and countries can work together more effectively when it matters most

This is not a theoretical policy briefing. It’s a working session designed to give attendees concrete tools, honest insights from the field, and direct access to the people building solutions to help organisations comply and stay resilient.

What You Will Gain

The workshop will provide practical guidance, real-world insights, and interactive discussions to help organisations strengthen resilience and meet evolving EU cybersecurity obligations. It moves beyond theory to deliver actionable guidance for organisations navigating the new EU cybersecurity regulatory landscape – whatever stage of the compliance journey they’re at.

What to Expect

Presentations from peer EU-funded projects See the tools and services being developed across Europe’s cybersecurity project landscape, and learn how relevant stakeholders can put them to use to strengthen readiness and achieve compliance.

Expert-led discussions A special focus on the practical challenges of NIS2 implementation, expectations around CRA enforcement, and strategies for effective cross-sector, cross-border collaboration in incident management.

Active participant engagement Ask questions, engage with experts and peers, and take part in an open survey and discussion to share your concerns, priorities, and interest in testing the projects’ solutions.

Networking lunch A valuable opportunity to continue the conversation and build lasting connections within the cybersecurity community.

Who Should Attend

This event is open to a broad audience, including:

  • SMEs, startups, and enterprises
  • Business leaders and decision-makers
  • Cybersecurity professionals
  • Legal and compliance experts

Regardless of sector, any organisation seeking to better understand and prepare for EU cybersecurity regulations will benefit from participating.

Agenda

Use the link below or the QR to download agenda.

Project that will join the event

Join Us

Whether you’re leading compliance efforts, shaping strategy, or working on the ground to strengthen your organisation’s cyber resilience, this is a chance to learn directly from the projects building Europe’s cybersecurity toolkit – and to help shape what comes next.

📅 Friday, 2 October 2026 🕘 09:00 – 16:00 📍 Electra Palace Athens – 18-20 N. Nikodimou str, 10557 Athens, Greece 🌐 Language: English

New CRAcademy Resource – The CRA Compliance Glossary

Understanding the Cyber Resilience Act (CRA) starts with understanding its language and that language isn’t always easy to navigate. Legal terminology, technical acronyms, and compliance concepts are scattered across the regulation and its supporting standards, often without a clear, accessible explanation in one place.

To close that gap, CRACoWi partners have developed the CRA Compliance Glossary, now available as a new resource on the CRAcademy hub. Built as part of CRAcademy’s mission to provide clear and practical information about the CRA (through FAQs, blogs, expert insights, and more) the glossary is designed to be your quick reference whenever CRA terminology gets in the way of getting things done.

The Glossary

The glossary brings together plain-language definitions of the terms, acronyms, and concepts that come up throughout the CRA compliance journey — from foundational security properties like confidentiality, integrity, and availability, to CRA-specific mechanisms such as the Declaration of Conformity, CE marking, and conformity assessment routes. It also covers the technical vocabulary manufacturers and product teams encounter in practice: SBOMs, SAST/DAST testing, threat modelling frameworks like STRIDE, vulnerability disclosure policies, and more.

Each entry is written to be understood without a legal or cybersecurity background, while staying precise enough to be useful for teams already deep in their compliance work.

The Cyber Resilience Act establishes uniform cybersecurity criteria for digital products placed on the EU market, covering the entire product lifecycle from design through decommissioning. For manufacturers, importers, and distributors (particularly SMEs without dedicated legal or cybersecurity teams) getting familiar with this vocabulary is often the first practical step toward compliance, well before documentation or technical measures come into play.

Available as a free PDF on Zenodo

For those who prefer to save, print, or share the glossary offline, a PDF version of the CRA Compliance Glossary has also been published as an open-access download on Zenodo, ensuring the resource remains freely and permanently available to the wider CRA compliance community.

Part of a growing CRAcademy toolkit

The glossary joins the CRAcademy webinar series and other capacity-building resources already available on the platform, reinforcing CRACoWi’s broader goal: helping SMEs, manufacturers, distributors, and importers meet new cybersecurity standards throughout the product lifecycle.

CRACoWI Partner erminas to Contribute to German Webinar on the Cyber Resilience Act on 19 June

The Cyber Resilience Act (CRA) is increasingly becoming a topic of discussion among companies across Europe. While organisations are working to understand the new requirements, many are asking a more fundamental question: how can they develop products that remain secure and trustworthy throughout their lifecycle?

To support this transition, CRACoWI consortium partner erminas GmbH will participate in the upcoming German-language webinar organised by IHK Oldenburg in cooperation with CYBERsicher – Transferstelle Cybersicherheit im Mittelstand.

📅 19 June 2026, 10:00 – 12:00 AM CEST | online

During the webinar, Dr. Yvette Teiken (erminas GmbH) and Dr. Matthias Kampmann (EASY.CRA) will provide both a regulatory overview and practical perspectives on implementing the CRA.

Participants will gain insight into:

  • what the CRA regulates and who it affects;
  • why the European Union is introducing these requirements;
  • practical challenges related to Software Bills of Materials (SBOMs), vulnerability management, and documentation obligations;
  • pragmatic approaches for integrating CRA requirements into existing processes.

The session is aimed at SMEs with digital products, machinery and plant manufacturers, IoT manufacturers, and professionals working in IT, product development, and compliance who want to prepare for the CRA in a structured and practical way.

For CRACoWI, participation in events such as this reflects the project’s commitment to sharing knowledge beyond the consortium, engaging directly with industry stakeholders, and contributing to the broader European effort to help organisations navigate the transition towards CRA readiness.

👉 Further information and registration are available via the IHK Oldenburg event page: MORE INFO & REGISTRATION