go back
Cyber Resilience Act Training

Cyber Resilience Act Training for Developers

The Cyber Resilience Act requires security measures to be addressed when developing and maintaining software. This training course presents the requirements in a practical manner tailored to a technical audience.

General Information

Open Training

3 days on site in Bern
English-language training
Practice-based delivery for software developers
Overview of security activities specific to the Cyber Resilience Act

Target Group

Software developers

Application Examples

Overview of security activities specific to the Cyber Resilience Act.

Description

With the increasing significance of software systems for digital products comes an increase in the number of threats to which these systems are exposed. A developer training course specifically referencing the Cyber Resilience Act is decisive for embedding security into the development process at an early stage and minimising risks effectively.

The EU's Cyber Resilience Act increases the requirements for a large number of products and aims to ensure more comprehensive and consistent implementation of security measures throughout the development process.

Participants learn how to fulfil the requirements of the Cyber Resilience Act and implement appropriate measures and activities in real-world scenarios. The course is based on our own experience in software development projects, enabling us to share real-life best practices.

Training Contents

Agenda

  1. 1Introduction to security: motivation and security goals
  2. 2Context: CRA and software security
  3. 3Secure design: threat modelling, security requirements, risk assessment
  4. 4Secure coding: security principles, cryptography, coding guidelines
  5. 5Supply chain security: threats and solutions, SBOM
  6. 6Secure testing: static and dynamic security testing, test tooling
  7. 7Secure operations: logging, monitoring, alerting, incident management
  8. 8Secure processes: DevSecOps, secure development lifecycle

Typical Questions We Answer

  • What role do developers play in the practical implementation of the CRA?
  • How can software developers identify and assess threats and risks for their software?
  • What security requirements should be taken into account during software development, and how can they be implemented?
  • What best practices exist for implementing authentication, authorisation, or cryptographic processes?
  • How important is supply chain security, and what measures does the CRA require?
  • What tools and methods are available for testing and monitoring software security?

Why inovex Academy?

Curated Content

Our trainers convey security content that matters in real projects and can be transferred directly into development processes.

Field-Tested Trainers

The trainers come from software development, security and cloud practice and know how regulatory requirements are implemented in projects.

Concrete Best Practices

The training connects CRA requirements with methods such as threat modelling, secure coding, security testing and DevSecOps.

Small Training Groups

Small groups create room for exchange and questions from participants' own development contexts.

Trainers

Our trainers are field-tested experts in their areas of expertise. Through their work in projects, they continuously expand their knowledge and pass it on in an application-oriented and practice-oriented way.

Photo of Dr Michael Gerhäuser

Dr Michael Gerhäuser

Software developmentWeb application security

Dr Michael Gerhäuser has been working professionally as a software developer since 2014 and joined inovex in 2022. He specialises in the design and implementation of web applications, both frontend and backend with operations and monitoring, and is also interested in software performance and web application security.

Photo of Simon Dreher

Simon Dreher

Security & Cloud Platform EngineeringCloud security

Simon Dreher is a Security & Cloud Platform Engineer at inovex. In his projects, he builds platforms for and with developers and successfully navigates the balance between security and usability. He is particularly interested in Kubernetes and cloud security.

Photo of Michael Fuchs

Michael Fuchs

Software security engineeringDevSecOps

Michael Fuchs has been working at the intersection of software development and IT security since 2018. As a Software Security Engineer, he supports development teams at conception and implementation level, focusing on strong authentication, DevSecOps practices and zero-trust concepts.

Photo of Dr. Christoph Erhardt

Dr. Christoph Erhardt

Embedded systemsSecurity

At inovex, Dr. Christoph Erhardt develops software platforms for medical devices based on open source technologies. He has been gaining experience in conducting training courses since 2007, initially in academic teaching and since 2019 also in the private sector.

Upcoming Open Training Dates

19.01. - 21.01.2027
English
Bern
CHF 1,799 p.p. plus VAT
Slots available
Book now
01.06. - 03.06.2027
English
Bern
CHF 1,799 p.p. plus VAT
Slots available
Book now

No suitable date? We will be happy to plan an individual training course for your company.

You can contact us by email at any time: academy@inovex.swiss

Frequently Asked Questions

Why is the Cyber Resilience Act important for developers?+

The Cyber Resilience Act strengthens cybersecurity in the EU and has a direct impact on developers. It requires secure digital products, clearer responsibilities and the integration of security measures throughout the development process.

How is the training structured?+

The training covers three practice-based days. The agenda includes security foundations, CRA context, secure design, secure coding, supply chain security, security testing, secure operations and secure processes.

Will I receive a certificate after completing the training?+

Yes, all participants receive a signed certificate of participation after completing the training.