CRAcademy Webinar: How CRA Tools Simplify Compliance

Understanding the scope of the Cyber Resilience Act (CRA) is one thing; meeting its requirements in practice is another.

As the CRA prepares to replace the cybersecurity requirements under the Radio Equipment Directive from December 2027, manufacturers are entering a new phase of readiness. The challenge is no longer just understanding the regulation, but translating legal obligations into compliant products, practical processes, and demonstrable evidence.

To support organisations on this journey, the CRACoWi project invites you to join the next session of the CRAcademy webinar series From Pain Points to Market Readiness – How CRA Tools Simplify Compliance, on 25 June 2026, at 11 AM CEST.

This practical webinar focuses on the reality of CRA implementation. Drawing on experiences from the field, it explores the recurring issues that often delay manufacturers on their path to compliance and demonstrates how a new generation of CRA tools can transform slow, manual activities into structured and repeatable processes.

Participants will gain insight into some of the most common pain points organisations encounter, including incomplete interface inventories, cryptography gaps, and documentation that cannot be easily verified. The session will show how these challenges can be addressed in ways that are actionable for product teams and aligned with the expectations of the regulation.

Designed as a bridge between regulation and engineering reality, the webinar will help attendees better understand what practical CRA readiness looks like and how organisations can prepare efficiently for market placement and future certification activities.

This session is particularly relevant for:

  • Manufacturers of connected and digital products;
  • Engineers, system architects, and product security teams;
  • Product managers and compliance professionals translating requirements into implementation;
  • SMEs preparing for CRA implementation and certification.
    What will you learn?

By attending, you will:

  • Understand why security-by-design sits at the heart of the CRA;
  • See who is responsible for what across manufacturers, consultants, and notified bodies;
  • Recognise the common pain points that lead to costly delays and understand why they occur;
  • Learn how CRA tools reduce manual, error-prone work into repeatable processes;
  • Get direct answers to your questions during the live Q&A session.

📅 26 June 2026 🕚 11:00 AM CEST | ONLINE

Participation is free of charge.

👉 Register today and take the next step from compliance pain points to market readiness.

Meet the Speaker

The session will be presented by Katherine Leese from SevenShift.

Originally from New Zealand and now based in Cologne, Germany, Katherine brings a unique and practical perspective to cybersecurity. After retraining in her forties to become an IT specialist for system integration, she combines hands-on technical experience with an understanding of the real-world challenges organisations face when implementing cybersecurity requirements.

As part of the CRACoWi project, SevenShift contributes to raising awareness about the Cyber Resilience Act and developing practical tools to support compliance. Katherine’s work focuses on helping bridge the gap between regulatory expectations and engineering reality, making complex requirements more understandable and actionable for manufacturers and SMEs alike.

Outside of work, she enjoys parenting a teenager and exploring how technology connects to everyday life.

If you are looking for practical guidance on moving from understanding the CRA to implementing it, this webinar is designed for you.

Participation is free of charge.

👉 Register today and take the next step from compliance pain points to market readiness.

Cyber Resilience Act – State of Play in 2026

The implementation landscape around the Cyber Resilience Act (CRA) is evolving rapidly. While the regulation itself entered into force in 2024, the ecosystem surrounding it – including guidance documents, harmonised standards, certification schemes, and conformity assessment procedures – is now taking shape at a remarkable pace.

For companies working with products containing digital elements, 2026 has become a crucial year for understanding how CRA requirements will be interpreted and applied in practice. From draft guidance published by the European Commission to major developments in standardisation and certification, several important milestones have already been reached.

This overview is prepared based on insights and analysis provided by Michael Beine (Bureau Veritas), contributor to the CRACoWi project activities related to certification, standardisation, and CRA implementation developments.

1. Draft CRA Guidance Published by the European Commission

    In March 2026, the European Commission published the draft guidance on the Cyber Resilience Act, with the commenting period ending in April 2026. The final version is expected towards the end of 2026 or beginning of 2027:

    • It provides interpretations of CRA legal text from official source of truth.
    • A must-read for everybody seeking clarity and interpretation of CRA.
    • In some cases, the additional level of detail creates follow-up questions, which will hopefully be addressed in the final revision

    This draft guidance is particularly important because it provides interpretations of the CRA legal text directly from the official source. For many stakeholders, it is currently one of the most valuable documents available for understanding how certain provisions of the regulation may be interpreted in practice.

    The document also demonstrates the complexity of implementing the CRA. While the guidance clarifies several topics, the additional level of detail has, in some areas, also created follow-up questions from industry and standardisation groups. Many stakeholders are now expecting that some of these open points will be addressed in the final revision.

    The draft guidance can be accessed through the European Commission’s official channels under the Draft Commission guidance on the Cyber Resilience Act

    2. RED-DA Cybersecurity Requirements will be Repealed – It is Official

    Another major development became official in 2026. To avoid overlapping regulatory requirements, the cybersecurity-related provisions under Article 3.3 d/e/f of the Radio Equipment Directive (RED-DA) will be deactivated on the date the CRA becomes fully applicable: 11 December 2027.

    This confirms an important signal from the legislator: there is currently no indication that the CRA timeline will be delayed. The transition towards CRA remains firmly on track.

    The repeal was adopted through Delegated Regulation (EU) 2026/339 published on EUR-Lex: Delegated regulation – EU – 2026/339 – EN – EUR-Lex

    3. Standardisation is Moving Forward Rapidly – prEN 40000-1-2 Drafting is Completed

    Standardisation activities around the CRA are accelerating significantly.

    The drafting of the first horizontal CRA standard, prEN 40000-1-2 “Cybersecurity requirements for products with digital elements – Part 1-2: Principles for cyber resilience”, has been completed and entered final review. If the formal vote is positive, publication could follow by the end of October 2026.

    This is an important milestone because horizontal standards are expected to play a key role in supporting harmonised approaches to CRA compliance across industries.

    At the same time, discussions around sector-specific standards continue intensely.

    More info: Post | LinkedIn

    4. Debate Around “Broad Verticals” and IEC 62443 – “Broad verticals will not be cited in the OJEU“

    One statement made by the European Commission during the ENISA Conference in March 2026 created significant discussion within standardisation working groups and the OT industry.

    According to comments shared publicly after the event, the Commission stated that “broad verticals will not be cited in the Official Journal of the European Union (OJEU).”

    This has raised concerns among stakeholders working on adapting IEC 62443 standards for CRA presumption of conformity, particularly in industrial and operational technology environments.

    The standards EN IEC 62443-4-1 and EN IEC 62443-4-2 remained in public consultation (Enquiry phase) until the end of April 2026. However, discussions around how these standards may ultimately be referenced under the CRA framework are still ongoing.

    At this stage, it is clear that the final approach to sector-specific harmonisation is still evolving.

    The last word is probably not yet said about this.

    More info: Post | LinkedIn

    5. CSA2 draft regulation proposes new Certification Schemes for CRA

    The proposed update of the Cybersecurity Act (commonly referred to as CSA2) also represents an important step in aligning the EU cybersecurity certification framework with the CRA.

    The proposal aims to facilitate the creation and adaptation of certification schemes supporting CRA requirements. This is particularly relevant for products that may require third-party conformity assessment procedures.

    The proposal for the revised EU Cybersecurity Act has been published under the European Commission’s “Shaping Europe’s Digital Future” initiative.

    CSA2 aims to boost the creation and adaptation of Certification Schemes for the CRA.

    More info: Proposal for a Regulation for the EU Cybersecurity Act | Shaping Europe’s digital future

    6. EUCC Implementing Act Expected by End of 2026

    The European Commission has also indicated plans for an implementing act approving the EU Common Criteria (EUCC) scheme for CRA purposes. This would support conformity assessment procedures for critical products with digital elements, including categories such as payment terminals, smart cards, and smart meter gateways.

    While no publicly available implementing act reference has yet been identified, this would represent another major step towards operationalising CRA conformity assessment mechanisms.

    7. „fast track“ procedure for NoBo under RED-DA

    Another important discussion currently taking place involves a potential “fast-track” procedure for the nomination of Notified Bodies (NoBos) under the CRA.

    According to publicly shared information from discussions between the European Commission and ADCO CRA, the proposal would simplify nomination procedures for organisations already designated under RED-DA.

    The objective appears straightforward: ensuring that a sufficient number of Notified Bodies are available before the CRA becomes fully applicable at the end of 2027.

    More info: Post | LinkedIn

    Help Is on the Way for SMEs

    As the Cyber Resilience Act (CRA) moves closer to full implementation, many SMEs are still trying to understand what the regulation means in practice and how to prepare for compliance. The good news is that support is already taking shape across Europe.

    Several EU-funded initiatives, including CRACoWi and other projects within the CRA Cluster, are actively developing practical tools, guidance materials, and training resources designed to help organisations navigate the new cybersecurity requirements.

    Within CRACoWi, the first support resources are already becoming available. This includes tools such as the CRA Scope Assesment, helping organisations better understand whether and how the CRA applies to their products, as well as the CRAcademy initiative, offering webinars, workshops, and educational materials focused on CRA implementation and cybersecurity compliance.

    And this is only the beginning. Additional tools, guidance documents, training materials, and practical support mechanisms are currently under development and will continue to evolve over the coming months.

    If you want to stay informed about the latest developments, upcoming training sessions, and new CRA support resources, make sure to follow the CRACoWi project and subscribe to the newsletter.

    You can also explore the broader ecosystem of initiatives by visiting the CRA Cluster projects working towards practical CRA implementation across Europe: CRA Cluster

    A Regulatory Ecosystem Taking Shape

    What becomes increasingly clear is that the CRA is no longer only a legal text. The broader implementation ecosystem (guidance documents, harmonised standards, certification schemes, conformity assessment procedures, and institutional coordination) is now actively developing.

    For companies across Europe, especially SMEs, staying informed about these developments will be essential over the coming months. The pace of change is high, and many practical aspects of compliance are still being refined in parallel with the regulation’s rollout.

    Projects such as CRACoWi are therefore becoming increasingly relevant, not only because they raise awareness about the CRA, but because they help organisations translate evolving regulatory requirements into practical implementation steps.


    Michael Beine bureau veritas

    About the Author
    Michael Beine is a cybersecurity and regulatory compliance expert at Bureau Veritas Consumer Product Services Germany, with more than 20 years of experience in the testing, inspection, and certification industry. His work focuses on cybersecurity requirements for connected products, IoT security, industrial automation, and European regulatory frameworks, including the Cyber Resilience Act (CRA) and RED Delegated Act. Within the CRACoWi project, he contributes to activities related to certification schemes, standardisation, and practical implementation of cybersecurity compliance requirements.

    SevenShift Participating in Cybersecurity Competence Group Meeting in Cologne

    On 12 May 2026, the CRACoWi consortium partner SevenShift participated in the meeting of the Cybersecurity Competence Group titled “Cyber Resilience in Practice: Strategies for a Secure Digital Future”, held in Cologne, Germany.

    The event gathered cybersecurity experts, industry representatives, and practitioners to discuss current challenges related to cyber resilience, the evolving threat landscape, and the practical implementation of the Cyber Resilience Act (CRA).

    During the session “The Cyber Resilience Act: Legal Framework and Practical Experience”, Katherine Leese from SevenShift (SES) contributed to the discussion by sharing practical experiences from CRA compliance testing and presenting CRA-related tools developed through EU-funded initiatives. As part of the presentation, Katherine introduced the CRACoWi Wizard, highlighting how the project supports organisations in understanding and implementing CRA requirements in practice. Complementary tools developed within other CRA Cluster projects were also presented, underlining the importance of collaboration and alignment between related initiatives.

    The discussion addressed several important topics linked to CRA implementation, including reporting obligations and deadlines, responsibilities across the supply chain, security-by-design principles, lifecycle responsibility, and practical challenges organisations face when preparing for compliance.

    The meeting also explored broader cybersecurity resilience topics beyond regulatory compliance itself. Discussions focused on the changing threat landscape, including stolen credentials, infostealer malware, residential proxy usage, and increasingly rapid attack execution following successful infiltration. Additional presentations addressed automated vulnerability management, CSAF, and security.txt as important mechanisms for more structured and scalable vulnerability communication.

    Participation in events such as this supports CRACoWi’s ongoing efforts to exchange practical knowledge, engage with cybersecurity communities, and strengthen cooperation with related initiatives working on CRA implementation and cyber resilience across Europe.

    Katherine Leese (SevenShift)

    CRACoWi at the Cluster Synergies Webinar

    CRACoWi recently participated in the Cluster Synergies Webinar held on 22 April 2026, an event that brought together EU-funded cybersecurity projects to exchange insights, present ongoing work, and explore areas of alignment.

    While such events are often framed as dissemination activities, their real value lies in something deeper – connecting initiatives that are addressing the same regulatory and technical challenges from different angles.

    As the Cyber Resilience Act (CRA) moves closer to full implementation, the landscape of tools, methodologies, and support mechanisms across EU projects is rapidly expanding. Without active collaboration, this risks becoming fragmented. The Cluster Synergies Webinar is one of the spaces where this fragmentation can be addressed early – through open exchange, comparison of approaches, and identification of complementarities.

    During the session, Pablo Endres (Seven Shift)and Sandra Bortek (Tiko Pro) presented the CRACoWi project, focusing on three key elements:

    • The development of tools supporting CRA compliance
    • The current progress and direction of the project
    • The CRAcademy, which provides structured training and practical guidance to help organisations better understand and implement CRA requirements

    The discussion confirmed a recurring point across projects: organisations are not lacking awareness of the CRA – they are lacking clarity on how to act. This is where coordinated efforts between projects become essential. Each initiative contributes a different piece – whether technical tools, training, certification support, or implementation guidance – and together they form a more complete ecosystem.

    Engaging with other EU initiatives also opens the door to joint dissemination, shared learning, and potential integration of approaches, ultimately increasing the impact of all projects involved.

    The recording of the webinar is available here:

    CRACoWi Reaches Midpoint Milestone and Advances Toward Midterm Review in Athens

    The CRACoWi consortium met in Athens last week for its latest plenary meeting, marking an important milestone as the project reached Month 18 of its implementation. The meeting focused on assessing progress, aligning next steps, and preparing for the upcoming midterm review.

    Now halfway through its 36-month journey, CRACoWi continues to advance its core objective of supporting companies in meeting the requirements of the Cyber Resilience Act (CRA). As the regulation introduces mandatory cybersecurity obligations for products with digital elements, the project is developing a practical Compliance Wizard to help SMEs, manufacturers, distributors, and importers navigate these requirements in a structured and accessible way.

    At this stage, the project has moved beyond initial setup and into tangible implementation. In parallel, partners are actively working on use cases covering critical infrastructure and market actors such as importers and distributors, ensuring that the tool reflects real-world compliance challenges.

    Beyond technical development, CRACoWi has established a strong foundation for stakeholder engagement and capacity building. Through initiatives such as the CRAcademywebinar series and targeted communication activities, the project is already reaching its key audiences and building awareness around CRA requirements and practical compliance pathways.

    The Athens meeting served as a key checkpoint, confirming that the project is progressing according to plan and is well-positioned for the midterm review. Partners aligned on the consolidation of results, upcoming deliverables, and the next phase of development, which will focus on further validation, stakeholder uptake, and scaling of the solution.

    As Europe moves closer to the implementation of the Cyber Resilience Act, initiatives like CRACoWi are becoming increasingly important. The project plays a critical role in translating complex regulatory requirements into practical tools that businesses can actually use, reducing the compliance burden and supporting a more secure and resilient digital market.

    CRACoWi at InCyber Forum Europe 2026

    Meet the CRACoWi partners – ITML, Seven Shift and Tiko Pro – a the InCyber forum 31 March – 2 April, Pavilion Europe – booth E20-8A.

    The CRACoWi project will be showcased at the InCyber Forum Europe 2026, one of Europe’s leading events dedicated to cybersecurity and digital trust. Bringing together thousands of experts, policymakers, and industry leaders, the Forum serves as a key platform for addressing the most pressing challenges in today’s digital landscape and strengthening cooperation across the European cybersecurity ecosystem.

    CRACoWi partners ITML, SevenShift, and Tiko Pro will be present at the Pavilion Europe (Booth E20-8A), where they will introduce the project and engage with stakeholders from across the cybersecurity and innovation community.

    As the Cyber Resilience Act (CRA) introduces new mandatory cybersecurity requirements for digital products in the EU, CRACoWi plays an important role in supporting organisations, especially SMEs, in navigating compliance. Through its Compliance Wizard, the project provides a practical, step-by-step approach to understanding and implementing CRA obligations.

    The InCyber Forum offers a valuable opportunity to exchange knowledge, explore collaboration opportunities, and connect with organisations shaping the future of cyber resilience in Europe.

    We invite you to meet the CRACoWi team at the booth and learn more about how the project is contributing to a more secure and trusted digital environment.

    CRAcademy Webinar Series – A Structured Training Path for Cyber Resilience Act Compliance

    CRACoWi is launching the CRAcademy webinar series – a structured set of training sessions designed to support manufacturers, SMEs, and product teams in navigating the EU Cyber Resilience Act (CRA) from understanding to implementation and compliance.

    The CRA introduces mandatory cybersecurity requirements for products with digital elements placed on the EU market. While many organisations are aware of the regulation, uncertainty often remains around how obligations translate into practical steps, technical requirements, and demonstrable compliance.

    The CRACoWi addresses this gap through CRAcademy training series, workshops and by developing practial tools.

    1. CRA Overview, Regulatory Landscape, and Product Classification

    FEB 18, 2026 // 11:00 – 12:00 CET

    This session provides a structured, practical introduction to the CRA, focusing on how to correctly interpret the regulation, understand its scope, and position your product within the CRA classification framework. You will also gain clarity on how the CRA aligns with and differs from other relevant EU regulations, helping you avoid misinterpretation and compliance gaps.

    The webinar is designed as a foundational training session and sets the baseline for all subsequent CRA-related technical and compliance activities.

    2. CRA Standards, Risk Analysis, and Technical Requirements

    MARCH 26, 2026 // 11:00 – 12:00 CET

    This webinar focuses on the practical building blocks of CRA compliance: the current state of standardisation, how risk analysis is expected to be performed, and what the CRA requires in terms of technical cybersecurity measures. You will gain clarity on how harmonised standards support compliance, how risk analysis connects legal obligations to technical controls, and how to interpret the CRA’s technical requirements in a way that is actionable for product teams.

    This session is designed as a bridge between regulation and engineering reality.

    3. Conformity Assessment, CE Marking, and Vulnerability Management under the CRA

    APRIL 14, 2026 // 11:00 – 12:00 CET

    Understanding the Cyber Resilience Act is not enough -manufacturers must demonstrate compliance. This webinar focuses on the final and most critical phase of CRA readiness: conformity assessment procedures, the rules and logic behind CE marking, and the ongoing obligations related to vulnerability handling and reporting. You will learn how CRA compliance moves from internal preparation to formal assessment, market placement, and post-market obligations, and how vulnerability handling becomes a continuous compliance requirement rather than a one-off activity.

    The session concludes with actionable next steps, translating regulatory obligations into a realistic compliance roadmap.

    Speaker

    Michael Beine bureau veritas

    Michael Beine, Business Unit Manager – CyberSecurity, Bureau Veritas CPS Germany

    Michael Beine has over 20 years of experience in the Testing, Inspection, and Certification (TIC) industry. He has led testing and approval activities for a wide range of wireless technologies and developed testing procedures and services for connected and IoT devices.

    In recent years, his work has focused on cybersecurity. He acts as a cybersecurity auditor for industrial automation components and systems in line with the IEC 62443 standard and leads cybersecurity services at Bureau Veritas Consumer Product Services in Germany. He is a recognised expert in regulatory cybersecurity compliance for connected products, including RED-DA and the Cyber Resilience Act (CRA).

    Subscribe For Updates

    CRACoWi project at the CRA Webinar for Dutch SMEs

    We are delighted that CRACoWi projectwas invited to participate in the Cyber Resilience Act (CRA) Webinar on 11 November, organized by the Dutch Ministry of Economic Affairs and the National Cybersecurity Center of the Netherlands (NCC NL).

    The webinar aimed to help Dutch SMEs understand the Cyber Resilience Act and prepare for compliance with the upcoming regulation. Two EU-funded projects, CRACoWi and SECURE, were featured during the session,

    Eleftheria Marini (ITML) as Project Coordinator of CRACoWi, provided an overview of the the project’s goals and impact in supporting European SMEs toward CRA compliance, with a special focus on how CRACoWi can benefit end users, particularly SMEs developing or deploying digital products.

    Pablo Endres (SevenShift) presented the technical perspective, offering a high-level overview of the technologies and tools being developed, including the Cyber Resilience Act Compliance Wizard, an AI-supported framework for automated cybersecurity assessment, documentation and certification support.

    The event was an important step in raising awareness and enhancing collaboration around CRA implementation across Europe, showcasing how initiatives like CRACoWi and SECURE contribute to empowering SMEs toward a more secure digital future.

    CRACoWi Consortium Meets in Maribor to Accelerate Cybersecurity Compliance for European SMEs

    The city of Maribor recently hosted the 2nd Plenary Consortium Meeting of the CRACoWi project, bringing together 14 expert partners from across Europe to align on progress and define the next strategic steps toward simplifying cybersecurity compliance for businesses across the EU.

    Over two days of in-depth collaboration (30 September – 1 October 2025), the CRACoWi consortium advanced its mission of supporting small and medium-sized enterprises (SMEs), manufacturers, importers, and distributors in complying with the EU Cyber Resilience Act (CRA) – a new legislative milestone aimed at improving the security of digital products throughout their lifecycle.

    The CRACoWi (Cyber Resilience Act Compliance Wizard) project, funded under the Digital Europe Programme and supported by the European Cybersecurity Competence Centre (ECCC), is developing a user-friendly Compliance Wizard – a step-by-step digital tool that helps businesses understand and fulfil their CRA obligations.

    As the CRA imposes strict new requirements for placing connected products on the EU market, CRACoWi fills a crucial gap by offering practical, hands-on support tailored to the needs of companies that may lack dedicated cybersecurity or legal teams.

    The plenary meeting featured updates on all technical and strategic work packages, combined with hands-on workshops and valuable peer-to-peer learning. Partners engaged in a live walkthrough of CRACoWi in a Use Case Workshop where they identified documentation gaps, and performed tailored threat modelling for OT and IoT devices. The consortium worked in focused groups covering critical infrastructure, importers/distributors, and compliance documentation, fostering a strong foundation for the next project phases.

    This plenary also included a dedicated CRAcademy session focused on certification and standardisation processes and vulnerability handling obligations for manufacturers, distributors and importers of the digital products. Not less important was a session for  communication, dissemination and KPI tracking to ensure that CRACoWi’s message and resources reach the right stakeholders.

    “This meeting proved once again that strong collaboration and a shared mission can turn complex legislation into practical solutions. CRACoWi is not just about compliance – it’s about empowering the European ecosystem to thrive securely,” said coordinator George Bravos, ITML.

    As Europe prepares for the full enforcement of the Cyber Resilience Act, CRACoWi stands out as a pioneering project that transforms regulation into action. By helping SMEs and other economic operators navigate the complexities of the CRA, the project contributes directly to the EU’s goal of a digitally secure, innovation-driven internal market.

    This time, the plenary meeting was organised by Tiko Pro, a consortium partner leading the work package for communication and dissemination. Tiko Pro ensured everything ran smoothly while also offering partners the chance to enjoy true Slovenian hospitality.