CRA and RED Directive training
2 days
Understand the regulatory and normative requirements related to the cybersecurity of connected embedded equipment (IoT), anticipate upcoming legal obligations, and integrate cybersecurity from the design phase onward.

Program
Day 1: RED Directive and EN 18031
Welcome and introduction
- Presentation of the day's objectives
- Roundtable introduction of participants
- Current cybersecurity challenges in embedded systems
RED Directive (Radio Equipment Directive): Cybersecurity focus
- General presentation of the RED Directive (2014/53/EU)
- Focus on Article 3(3)(d), (e), (f): protection of personal data and privacy, protection against fraud, protection of the network and its integrity
- Impact of the enforcement of cyber requirements (mandatory since August 2025)
- Examples of equipment types concerned
Workshop: case study on a connected product. Which RED requirements apply?
EN 18031 standard: Security for IoT
- Context and status of the EN 18031 standard
- Access control, authentication and password management
- Secure software update
- Secure communications
- Attack surface reduction
- Logging and monitoring
- Cryptography
Workshop: express audit of an embedded firmware against the EN 18031 standard
Day 2: Cyber Resilience Act
Cyber Resilience Act (CRA): Understand and anticipate
- Presentation of the CRA regulation and its implementation timeline
- Obligations applicable to manufacturers, importers and distributors
- Scope and product categorization (class I, II, critical products)
- Technical and organizational requirements
- Legal aspects and penalties
Discussion: how to align your product roadmap with CRA deadlines?
Integrated compliance strategy
- Setting up a Secure by Design process
- Risk analysis tools and methods
- Vulnerability management (SBOM, CVE, VEX)
- Documentation best practices
Workshop: create a cybersecurity action plan for an embedded product
Feedback and conclusion
- Open Q&A with participants
- Resources to follow (ANSSI, ENISA, CENELEC, etc.)
