CRA Workshop
Cyber Resilience Act Workshop
A practical CRA workshop for your products and teams, delivered by Daniel Thompson-Yvetot and starting from two days.
Bring engineering, product, security, compliance, legal and leadership teams together to turn CRA requirements into clear responsibilities, practical decisions and next steps.
Thank you
We have your question and will be in touch within two working days.
The workshop is tailored to your products, current level of preparation and the questions facing your organisation. It can be delivered online or in person at your location.
Who is the CRA workshop for?
The CRA workshop is designed for organisations that need to build a shared understanding of the Cyber Resilience Act across several teams. It may be particularly useful for:
- Manufacturers of software, connected products and other products with digital elements
- Organisations preparing one product, a product family or a wider product portfolio for the EU market
- Companies whose CRA responsibilities are divided between engineering, product, security, compliance, legal and leadership teams
- Manufacturers that already have relevant processes and documentation but need to identify where gaps remain
- Organisations preparing for CRA vulnerability reporting, technical documentation or conformity assessment
- Manufacturers based outside the European Union that are preparing to place products on the EU market
What can a CRA workshop cover?
The content is agreed in advance and adapted to your organisation, products and current stage of CRA preparation. Topics may include:
CRA scope and organisational responsibilities
Understand which products and business activities fall within the scope of the CRA and clarify the responsibilities of the relevant teams and economic operators.
Product classification and conformity route
Work through the likely classification of your products and understand how classification affects the available conformity-assessment route.
CRA gap and documentation mapping
Map your existing policies, processes, technical documents and product evidence against the relevant CRA requirements. Identify where suitable evidence already exists, where it needs improvement and where new work may be required.
Vulnerability management and reporting
Examine how vulnerabilities and severe incidents are identified, assessed, escalated, documented and reported. This can include preparation for the 24-hour, 72-hour and final-report deadlines that apply to reportable vulnerabilities and incidents.
Software supply chain and third-party components
Review how your organisation identifies and manages open-source software, commercial components and other digital dependencies included within its products.
Secure product development and support
Consider how security by design, vulnerability remediation, security updates and support-period responsibilities should be reflected in your product-development and maintenance processes.
Technical documentation and evidence
Identify the technical documentation and evidence required to support CRA conformity and determine which teams are responsible for producing and maintaining it.
What will your team receive?
A CRA compliance workshop is intended to produce practical results, not only a general explanation of the Regulation. Depending on the agreed scope, the outputs may include:
Documentation and evidence map
A structured view of the relevant documentation and evidence already available, incomplete or missing.
Responsibility matrix
A clear allocation of CRA responsibilities across engineering, product, security, compliance, legal, procurement and leadership teams.
Vulnerability reporting workflow
An agreed route for vulnerability intake, assessment, escalation, decision-making, evidence preservation and regulatory reporting.
Prioritised action plan
A practical list of actions, owners, dependencies and recommended priorities following the workshop.
Shared understanding across teams
A common view of the organisation's CRA responsibilities, current position and next steps.
The specific outputs are agreed as part of the workshop scope.
A workshop built around your products
Generic presentations can explain what the Cyber Resilience Act says. A tailored CRA workshop helps your teams understand how its requirements affect your organisation and products in practice.
This preparation allows the workshop to focus on your products, evidence, responsibilities and decisions.
Before the workshop, we discuss
- The products or product families to be covered
- Your organisation's role and route to the EU market
- The teams that should participate
- Your current level of CRA preparation
- The documents and processes already available
- The principal questions the workshop should resolve
Is a workshop the right format for your organisation?
A Cyber Resilience Act workshop may be the right choice when
- Several teams need to understand how their responsibilities connect
- Your organisation needs to apply CRA requirements to specific products
- Relevant documentation exists across different departments but has not been mapped against the CRA
- Internal responsibilities for vulnerability management and reporting remain unclear
- Your teams need to agree on priorities and an implementation plan
If your organisation needs detailed product analysis, continuing specialist support or help resolving complex gaps, CRA consultancy may be more appropriate.
How a CRA workshop works
- Step 01
Initial discussion
We discuss your organisation, products, participants and the outcomes you want the workshop to achieve.
- Step 02
Workshop scope and agenda
Comply.Land prepares a proposed scope covering the topics, format, participants, timing, expected outputs and price.
- Step 03
Online or in-person delivery
Comply.Land delivers the workshop online or in person. Participants work through the agreed CRA topics using examples and questions relevant to your organisation.
- Step 04
Outputs and next steps
You receive the agreed outputs, priorities and recommended next steps. If the workshop identifies questions requiring deeper product analysis or implementation support, these can be scoped separately after the workshop.
Who will deliver your workshop?

Your workshop will be led by Daniel Thompson-Yvetot, founder and CEO of Comply.Land and CrabNebula and co-creator of the Tauri open-source framework.
Daniel combines practical software-development experience with direct involvement in European technical standardisation. As an ETSI Rapporteur, he has led the drafting of three harmonised standards intended to translate Cyber Resilience Act requirements into European technical specifications.
He wrote Manufacturing European Software, the first published book dedicated to the Cyber Resilience Act, and is a member of the Open Regulatory Compliance Working Group, which follows the impact of the CRA and Product Liability Directive on software manufacturers.
Daniel was named Cybersecurity Leader of the Year by the Malta Information Technology Agency and speaks regularly across Europe on CRA compliance, open-source governance and software security.
Learn more about Daniel and the Comply.Land teamCRA workshop format and price
The workshop duration starts at two days. It can be delivered online or in person at your organisation's location.
Travel and accommodation expenses are charged separately when an in-person workshop is held outside Malta.
The final duration and price depend on the scope, number and complexity of products, required preparation, number of participants and agreed outputs.
Every workshop includes a copy of Risk, Evidence and Conformity, Comply.Land's practical guide to risk assessment, evidence management and CRA compliance documentation.
Frequently asked questions about the CRA workshop
Is the workshop delivered online or in person?
Both formats are available. The most suitable format depends on the objectives, number and location of participants and the level of collaboration required.
How long is the CRA workshop?
The workshop starts from two days. The recommended duration depends on the number and complexity of the products, the topics to be covered, the number of participating teams and the outputs your organisation needs.
Who should participate?
Participants may include representatives from engineering, product management, product security, compliance, legal, procurement and leadership. The appropriate participants depend on the topics and products included in the workshop.
Can the workshop cover more than one product?
Yes. It can cover one product, a product family or a wider portfolio. The number and complexity of the products will affect the preparation, agenda, duration and price.
Do we need to prepare documents before the workshop?
Where relevant, we may ask you to identify or provide selected documents and process information before the workshop. This allows the session to focus on your actual preparation rather than general requirements. Any document-sharing arrangements will be agreed in advance.
Does the workshop provide certification?
No. A Comply.Land workshop provides practical guidance, analysis and agreed outputs. It does not constitute certification or a formal third-party conformity assessment.
What happens after the workshop?
Your organisation can use the agreed outputs and action plan to continue the work internally. If further product-specific analysis or implementation support is required, this can be scoped separately.
Plan your CRA workshop
Tell us about your products, participating teams and the questions you want the workshop to address. We will propose an appropriate format, scope, agenda, duration and price.