EU Cyber Resilience Act Certification Course
The EU Cyber Resilience Act Certification Course is a free, exam-graded training programme covering what Regulation (EU) 2024/2847 requires of anyone placing a product with digital elements on the EU market. It is published at /academy/cra-manufacturer and requires no account: you enroll with your name and email, confirm the email through an activation link, and work through the material in the browser.
Where to find it
Academy in the main site navigation, and Free CRA training course under Free resources in the footer. The landing page states the module count, the size of the question bank, the exam format, the attempt limit and the CPE credits the certificate carries.
Curriculum
The course is eight modules, each with learning objectives, study text drawn from the official regulation, and links to the primary sources on EUR-Lex, the European Commission's Cyber Resilience Act pages, and ENISA (including recorded ENISA webinars embedded from the publisher's own channel).
- CRA foundations, timeline and scope — legal architecture, the staged application dates, Article 2 scope, Article 3 definitions, and the sectoral exclusions.
- Product classification — the default tier, Annex III Class I and Class II important products, Annex IV critical products, and why classification follows function.
- Annex I Part I: secure by design — the essential product requirements and the risk assessment that scopes them.
- Annex I Part II: vulnerability handling — SBOM, free security updates, coordinated disclosure, and secure update distribution.
- Article 13: manufacturer obligations — the lifecycle duty set, component due diligence, the support period, and Annex II user information.
- Article 14: reporting — the two triggers, the 24-hour, 72-hour, 14-day and one-month clocks, and reporting to the coordinator CSIRT and ENISA.
- Conformity assessment and CE marking — the Annex VIII routes, Annex VII technical documentation, the EU Declaration of Conformity, and CE marking rules.
- Economic operators and enforcement — importers, distributors, when a rebrander becomes the manufacturer, open-source stewards, market surveillance, and the penalty tiers.
Examination rules
Questions are single-best-answer items in the style of professional security certifications. Roughly a third are scenarios that test judgment rather than recall, and the correct option is deliberately not the longest one — an automated data-quality check enforces this across the whole bank, along with an even spread of the correct answer across all four positions.
Module quizzes. Ten questions sampled fresh from that module's bank, pass mark 70%, a maximum of three attempts per module. Answers and full explanations are shown after every attempt, with links to the source article or annex.
Final examination. Sixty questions drawn across all eight modules, ninety minutes, pass mark 75%, a maximum of three attempts in total. It unlocks only once every module quiz has been passed. Each attempt draws a different paper.
Two rules follow from keeping the examination meaningful:
- Starting an attempt consumes it. This prevents the question bank from being harvested by starting attempts, reading the questions, and abandoning them. If you close the page, reopening resumes the same paper — and for the final exam, the same clock.
- The final examination releases no answer key. You receive your score and a per-module breakdown to guide revision, but not per-question answers. Module quizzes are where explanations are given.
Attempt limits are enforced on the server and cannot be reset.
Examination text cannot be selected or copied. Question text, answer options and the module-quiz answer review suppress selection, copy, cut, drag and the right-click menu, so questions cannot be pasted into an AI chat assistant mid-exam. This is a deterrent rather than a guarantee — no web page can stop someone photographing the screen — but it removes the effortless route. The study modules and your certificate are unaffected and remain fully selectable.
Certificate
Passing the final examination issues a certificate immediately and emails you the link. The credential is the EU Cyber Resilience Act Certification — Foundational, issued by Porta Regulus B.V. (KvK 42062307, VAT NL869534208B01), the company that operates CVD Portal.
The certificate page is also the verification record: anyone holding the link — an employer, a customer, an auditor — can open it and confirm the credential is genuine. Certificate pages are excluded from search engine indexing because they carry a person's name behind an unguessable URL.
What a verifier sees, and what stays private
The link is safe to share, including on a public profile. It shows two different views depending on who opens it.
| Anyone with the link | You, the holder | |
|---|---|---|
| Name, credential, level, standing | Yes | Yes |
| Issue date | Month and year | Exact date |
| Curriculum version, certificate ID | Yes | Yes |
| Exam score and percentage | No | Yes |
| Employer | No | Yes |
Your score and employer are performance and personal data that do not help anyone answer "is this person certified", so they are never shown to a third party. You see the full record when you open the page in the browser you took the course in, where your course session identifies you.
The certificate is a formal credential document in the same style as the Partner Academy one: a double-ruled navy frame with a circular issuing seal, the holder's name as the focal point, and the credential title in letterspaced caps. It prints as a landscape A4 credential with the site navigation removed — use Print / Save PDF.
It carries CPE credits rather than an exam score, on the standard one-credit-per-instructional-hour convention. The figure is derived from the curriculum (300 instructional minutes plus an exam estimate) and rounded down to the nearest half credit, so it is never overstated and stays honest as modules change. Currently 6 credits. These credits are self-reported: CVD Portal is not an (ISC)² CPE Submitter or a PMI Authorized Training Partner, so they are not officially accredited.
Your score and employer appear beneath the certificate, in a panel visible only to you and excluded from the printed document — so the credential itself is always safe to share.
Adding it to LinkedIn
An Add to LinkedIn button on your certificate page opens LinkedIn's add-a-certification form with the credential name, the issuer, the issue month and year, the certificate URL and the certificate number already filled in. The certificate email carries the same link.
The button appears only when you open the page yourself, not to anyone else holding the link — otherwise it would offer to add your credential to their profile. It is also withheld from a revoked credential.
No expiry date is sent, because the credential has none.
Machine-readable verification (Open Badges 3.0)
Alongside the human-readable page, every certificate is published as a signed Open Badges 3.0 assertion — a W3C Verifiable Credential — at:
/academy/cra-manufacturer/certificate/<code>/assertion.json
It is a compact JWS signed with Ed25519. The issuer is did:web:cvdportal.com, and the public key is published at https://cvdportal.com/.well-known/did.json, so a verifier can check the signature without contacting us for a key.
The assertion contains no email address and no holder name. Identity is bound as a salted SHA-256 hash of the holder's email, using the Open Badges IdentityHash form. Someone who already knows the email can confirm it matches; nobody can work backwards from the assertion to a person, and the per-credential salt means two credentials held by the same person cannot be correlated.
Revocation is carried by a hosted Bitstring Status List at /api/credentials/status-list, where each issued credential owns one bit. A verifier fetches the whole list and reads one bit, so checking a credential reveals nothing about which credential is being checked.
No expiry is present in the assertion, matching the credential itself.
Standing: valid, superseded, revoked
A certificate always displays its current standing.
- Valid — issued, current, and not withdrawn.
- Superseded — a newer curriculum version has been published since it was earned. The credential remains genuine and is not withdrawn; the label simply tells a reader that the syllabus has moved on.
- Revoked — withdrawn by the issuer, for example when a certificate was issued in error. A revoked certificate keeps resolving at the same URL rather than disappearing, so anyone holding an old link learns that it is no longer valid. The reason is shown only to the holder.
Expiry
The Foundational credential does not expire. There is no recertification deadline and no renewal fee.
The issue date does the work an expiry date would: it tells a reader which vintage of CRA guidance you were assessed against. CRA obligations do not lapse on an anniversary, and the harmonised standards will publish on their own schedule, so a countdown would imply a precision that does not exist. When the syllabus moves materially, the curriculum version is bumped and older certificates are marked superseded — visible, honest, and without invalidating what you earned.
Levels
The credential is issued at the Foundational level. That is a deliberate, accurate label: the exam is free, taken online, unproctored, and capped at three attempts, which supports a knowledge credential rather than an identity-verified professional qualification.
Higher tiers are planned as the CRA harmonised standards are published ahead of the December 2027 application date. They will be separate credentials with their own syllabus and a stronger integrity model, not an automatic upgrade of certificates already issued.
Module emails
After you confirm your enrollment, we send one email per module, in order, spaced a few days apart. Each covers a piece of the regulation worth reading on its own and links to the matching module.
The sequence follows your actual progress rather than a fixed timetable. If you work ahead, it skips forward with you rather than introducing a module you have already passed. It stops on its own once you have been walked through all eight, and it stops immediately if you pass the final exam.
Every module email carries a one-click link to stop them. Doing so ends the module emails only. Your enrollment, your quiz and exam attempts, and any certificate already issued are all unaffected, and you keep receiving the transactional messages, which are the enrollment confirmation and the certificate itself.
Applying what the course teaches
The course teaches the obligations; it does not produce the file that discharges them. Each module page, the landing page and your certificate page point at the next step:
- Classify a product — answer the Annex III and Annex IV questions for one product and get its class and the conformity assessment route that follows. Free, no account.
- CRA exposure scan — reads a domain for the
security.txtand the coordinated vulnerability disclosure policy Annex I Part II requires, and reports what is missing. Free, no account. - The compliance workspace — carries a product from classification through the Annex I assessment and the technical documentation to a signed EU Declaration of Conformity and the Article 14 reporting path. The trial runs 14 days and takes no card.
The certificate email carries the same three links alongside the certificate and the LinkedIn add.
Notes and limitations
- The course is training material, not legal advice, and it is not an accredited or notified-body qualification. It demonstrates knowledge of the regulation's requirements.
- Because the course is free and account-free, enrolling a different email address starts a fresh set of attempts. The certificate names the email under which it was earned.
- A retake after certification keeps the original certificate ID, so links already shared stay valid.