In less than 3 years’ time, all products shipped to the EU will have to be CRA compliant – as a legal pre-condition of bearing the CE Mark. Product which use any sort of wireless communication will have to comply with most of the cybersecurity provisions much sooner.

This one-day, intensive training course, planned by experts and delivered in-person by an experienced training team, will equip engineers and project managers to return to their company ready to confidently map out a strategy based on a sound understanding of the requirements.

At each stage, we identify those resources which will allow further self-training and skills development so that delegates can begin their journey to subject expert status.

Practical and actionable information is provided based on embedded development scenarios, both MCU and MPU-based, and typical software frameworks.

No prior knowledge is required, although the content will be most beneficial to established embedded developers. Delegates can expect an intensive day of training, as a lot of ground is covered. Each delegate will receive a binder with presentation printouts which they can annotate, and a CPD certificate upon completion.

9.30am start. Coffee from 9am. Lunch provided.

Scope and requirements of CRA

  • Scope and timescale
  • Intersecting regulations and standards
  • Sources of guidance including IoTSF framework
  • Compliance of component technologies

The Risk Assessment

  • Threat modelling for embedded and IoT
  • Gap analysis
  • Reducing compliance costs

The Secure Software Development Lifecycle

  • Secure SDL resources and frameworks
  • Safe and secure programming
  • From concept to maintenance

Authentication and Secure Boot

  • Do I really need firmware authentication?
  • Understanding secure boot
  • Extending the chain of trust

A Product “Free from Exploitable Vulnerabilities”

  • SBOM Considerations
  • The role of Software Composition Analysis
  • Managing and mitigating CVEs

Maintaining and updating a secure product

  • Regulatory requirement for a “Support Period”
  • Maintaining freedom from vulnerabilities
  • Update requirements
  • Update mechanism technical overview

Secure supply chain

  • Supply chain risks
  • Secure provisioning

Conformity process and documentation

  • Adjacent standards
  • Demonstrating  CRA compliance
  • Documentation checklist

5.15pm finish

Engineers and managers with an understanding of embedded software development, but with no (or limited) prior knowledge of cyber-resilience product development are the intended audience. Please note that this is a technical training course, and may be of limited value to non-technical personnel.

The course is primarily lecture based, face-to-face training with opportunities for interaction and questioning. A small proportion of the content may be delivered by remote speakers.

£495 per delegate (excl. VAT) including refreshments and lunch

Please call on +44 1295 768800 or click “Purchase Online” on the right.

Highlights:

  • Scope and requirements of CRA

  • The Risk Assessment

  • The Secure Software Development Lifecycle

  • Authentication and Secure Boot

  • A Product “Free from Exploitable Vulnerabilities”

  • Maintaining and updating a secure product

  • Secure supply chain

  • Conformity process and documentation

Book Now:

Windows Embedded “Train the trainer” at our Oxfordshire HQ: