The Cyber Resilience Act and Embedded Security Training courses, workshops and bespoke programmes

Implementing the Cyber Resilience Act (CRA) in practice

The Cyber Resilience Act imposes new mandatory requirements on manufacturers of digital products.

For embedded systems, this means: security by design, structured processes, traceable documentation and long-term maintainability.

Our training courses and workshops provide in-depth knowledge and practical implementation skills – tailored to different levels of experience and technical depth.

Our methodology

  • Practice-orientated content with direct product reference
  • Clear structure from regulatory requirements to technical implementation
  • Concrete deliverables instead of theoretical discussion
  • Workshops based on real architectures
  • Focus on embedded systems and Linux/Yocto

Your benefit

  • Reduction of regulatory risks
  • Structured safeguarding of your embedded products
  • Traceable documentation for CE conformity
  • Sustainable integration of security into your development processes

Whether you need an initial overview, an in-depth, bespoke analysis or solid expert knowledge at the Yocto level: we tailor our approach precisely to your specific needs.

Please feel free to contact us with no obligation!

Create understanding. Categorise requirements. Recognising the need for action.

Training: Fundamentals of Embedded Security & the Cyber Resilience Act

 

Management, product managers, project managers, developers with no prior knowledge of security

Understanding of regulatory requirements and their impact on embedded products and development processes.

2 hours (online)

  • Objectives and Scope of the Cyber Resilience Act
  • Product Categories and Risk Classes
  • Basic cybersecurity requirements
  • CE marking and conformity assessment
  • Reporting obligations and deadlines
  • Roles and responsibilities throughout the supply chain
  • Clear classification of the company’s own products within the CRA framework
  • Overview of necessary technical and organisational measures
  • Understanding the implications for development, maintenance and support
  • A basis for strategic decisions

Workshop: CRA in Practice

 

Companies planning their first concrete steps towards implementation

Translating regulatory requirements into actionable business measures.

0.5–1 day (online or on-site)

  • Establishing a PSIRT process
  • Vulnerability monitoring and CVE management
  • Security Updates and Product Lifecycle
  • Documentation requirements
  • Structured identification of areas for action
  • Outline of the PSIRT structure
  • Overview of necessary process adjustments
  • List of measures for CRA compliance
  • Clearly defined next steps

Take the first step towards CRA-compliant embedded products. We’ll provide you with guidance and an overview.

Get clarity now

Secure systems in a structured way. Analyse risks methodically.

Cybersecurity workshop for embedded systems

Developers and architects who use SYS TEC platforms (e.g. sysWORXX / Yocto)

Systematic validation of a specific embedded product, taking regulatory requirements into account.

1–2 days (on-site recommended)

  • Architectural Overview (Secure Boot, Signing, Update Strategy)
  • Definition of system boundaries and trust boundaries
  • Creation of a data flow model
  • Analysis of product-specific threats
  • Derivation of technical protective measures
  • Relation to CRA-compliant documentation
  • Documented data flow model
  • Identified threats and risks
  • Detailed catalogue of measures
  • Structured security requirements for the product

Threat Modelling Workshop

Development and architecture teams

A methodologically sound safety analysis of a real-world system.

2–3 days (on-site)

  • System boundaries and confidence limits
  • Data Flow Diagrams (DFD)
  • STRIDE-based threat analysis
  • Risk assessment and prioritisation
  • Derivation of appropriate countermeasures
  • Documentation modules for CRA compliance
  • Complete Threat Model
  • Prioritised Risk List
  • Documented security measures
  • A usable basis for technical documentation

Minimise regulatory risks through clear processes. We’ll show you how structured hedging works.


Develop a security concept

Mastering security engineering at distribution and process level.

Expert workshop: Embedded security engineering with Yocto

Senior developers, architects, companies with their own Yocto distribution

Independent implementation and integration of security mechanisms into build, update and compliance processes.

3 days (condensed) or 5 days (with an extended practical component)

Session 1: Yocto Security Engineering

  • Secure Boot Implementation
  • Key Management and Signature Chains
  • OTA architectures
  • RAUC A/B update strategies
  • Image hardening
  • Securing the Build Pipeline

    Session 2: SBOM & Vulnerability Management

  • SBOM Creation (SPDX / CycloneDX)
  • Automated CVE Analysis
  • Patch strategy and backporting
  • Reproducible builds

    Session 3: CRA-compliant process integration

  • Security by Design in the development process
  • Incident response integration
  • Lifecycle management
  • Documentation requirements from a developer’s perspective

    Session 4: Security Testing

  • Static Analysis
  • Fuzzing Basics
  • Preparing for Penetration Tests
  • Validation of hardening measures
  • Implementation strategy for a secure Yocto distribution
  • Structured SBOM and CVE workflow
  • Integration of security into development processes
  • Practical knowledge transfer to the team

Take control of system-level security engineering. Technically sound and implemented in a practical manner.

Develop your engineering expertise

Optional: Personalised additions

CRA Readiness Quick Assessment

Security review of existing products

Support with setting up a PSIRT

Tailored in-house training courses

Over 30 years’ experience in embedded systems – combined with in-depth security expertise: together, we’ll make your systems resilient against hacker attacks.

Arrange a no-obligation initial consultation now

Get in touch now

Ihr Vertriebsteam der SYS TEC electronic

Your contact person: Ihr Vertriebsteam der SYS TEC electronic

Department: We're happy to help:

Email: sales@systec-electronic.com
Phone: +49 3765 38600-2110

Search the website

The internal search function finds pages, documents and blog posts.
Please enter a search term.

What are you looking for?

Frequently searched for:

  • EMC testing
  • Project management
  • Prototype manufacturing
Cookies and Data Protection
Exit the dialogue box and return to the top of the page