Introduction to the Cyber Resilience Act for manufacturers
ORC-Learning-HubAbout This Course
This beginner-friendly, 1-hour session provides a foundational overview of the Cyber Resilience Act (CRA) and its implications for manufacturers. Whether you are a product manager, developer, or work in compliance, security, or marketing, this course will help you navigate the essential requirements of the CRA to better protect your users and your business.
What You Will Learn:
- The Purpose of the CRA: Understand why the legislation was created and how it shifts security responsibility to the manufacturer.
- Core Concepts & Terminology: Learn essential terms, roles, and the significance of the CE mark.
- User-Centric Security: Discover how to implement "secure by design" and "secure by default" principles.
- Product Lifecycle Management: Understand how to handle vulnerabilities, manage incidents, and utilise Software Bill of Materials (SBOMs) effectively.
- CRA & Open Source: Learn how the CRA interacts with Open Source projects and supply chains.
- Compliance & Impact: Review the obligations for manufacturers and the consequences of non-compliance.
Requirements
This course is designed for manufacturers and software stakeholders navigating CRA obligations. Ideally, learners should have a basic understanding of software supply chain management, secure-by-design principles, and the software development lifecycle (SDLC). No prior legal expertise is required, though familiarity with your organisation’s current product documentation processes will enhance the learning experience.
Course Staff
Olle E. Johansson
Olle E. Johansson (oej) is a consultant in the area of real-time communication, application security and embedded system security. He has been active in Open Source for many years as a developer, evangelist, trainer, and speaker in many conferences worldwide. Olle is a member of the OWASP SBOM Forum and the OWASP CycloneDX industry working group. He is currently working on the CycloneDX Transparency Exchange API standard (Koala). He is actively participating in ECLIPSE ORCWG and the OpenSSF. From 2026, Olle is representing OWASP in the ORCWG steering committee. As an invited expert, he contributes in ECMA International TC54 that works with software and systems transparency – including OWASP CycloneDX, package URL (PURL) and the Transparency Exchange API (TEA).
In the past, Olle was an active core developer in the Asterisk.org project, co-founder of the Astricon conference and creator of the Asterisk certifications and trainings. He has been a contributor to the Kamailio.org open source SIP proxy for many years and still run many in-house trainings and workshops in SIP and Kamailio.
During 2024 Olle launched SBOMEUROPE.EU together with Anthony Harrison from APH10 in Manchester, UK. Together, they publish white papers, videos on Youtube and during 2025 launching training classes, workshops and expert consultancy for risk management, application security and CRA compliance.
Olle is also a project leader for the Swedish DNS TAPIR project that is building Open Source software for analysing DNS resolver logs and finding bad actors.
Olle is the founder and CEO of Edvina AB, founded in 1987.
Frequently Asked Questions
What web browser should I use?
The Open edX platform works best with current versions of Chrome, Edge, Firefox, or Safari.
See our list of supported browsers for the most up-to-date information.