Certified Cyber Resilience Act Risk Assessment Foundation (CCRA-FA) Certification Program by Tonex

The Certified Cyber Resilience Act Risk Assessment Foundation (CCRA-FA) program introduces participants to the EU Cyber Resilience Act, its risk-based structure, and the cybersecurity responsibilities of manufacturers, importers, distributors, software producers, and product teams.
This certification is designed for professionals who need to understand how CRA risk assessment affects product design, security engineering, technical documentation, vulnerability handling, and conformity planning.
Learning Objectives
Participants will learn how to:
- Explain the purpose and scope of the Cyber Resilience Act.
- Identify products with digital elements subject to CRA obligations.
- Understand risk-based cybersecurity requirements.
- Recognize the relationship between CRA, RED, NIS2, CE marking, and product conformity.
- Identify lifecycle cybersecurity obligations for digital products.
- Understand the role of technical documentation, vulnerability handling, and security updates.
- Support internal CRA readiness planning.
Target Audience
- Product managers
- Engineering managers
- Compliance professionals
- Cybersecurity analysts
- Embedded systems engineers
- Software development managers
- Quality and regulatory teams
- Procurement and supplier assurance teams
- Executives needing CRA awareness
Prerequisites
No formal prerequisites. Basic understanding of cybersecurity, software products, embedded systems, or product compliance is helpful.
Program Modules
Module 1: Introduction to the Cyber Resilience Act
- CRA purpose and regulatory intent
- Products with digital elements
- Manufacturer and economic operator responsibilities
- CRA timeline and transition planning
Module 2: CRA Risk-Based Cybersecurity Model
- Risk assessment principles
- Cybersecurity-by-design and by-default
- Product lifecycle cybersecurity
- Threats, vulnerabilities, and misuse cases
Module 3: CRA Essential Cybersecurity Requirements
- Secure design and development
- Secure configuration
- Authentication and access control
- Secure communication
- Data protection and confidentiality
- Integrity, availability, and resilience
- Attack surface reduction
Module 4: Vulnerability Handling and Security Updates
- Vulnerability disclosure
- Security patching
- End-of-support planning
- Incident reporting readiness
- Product security monitoring
Module 5: CRA Documentation and Compliance Readiness
- Technical documentation
- Risk assessment records
- Security requirements traceability
- Evidence preparation
- Internal readiness checklist
Exam Domains and Weights
| Domain | Weight |
| CRA Scope, Timeline, and Applicability | 20% |
| Risk Assessment Fundamentals | 25% |
| Essential Cybersecurity Requirements | 25% |
| Vulnerability Handling and Update Obligations | 20% |
| Documentation and Compliance Readiness | 10% |
Exam Format
- 40 multiple-choice questions
- 90 minutes
- Closed book
- Online or proctored
- Passing score: 70%
Credential Validity
Valid for 3 years.