Resources

Access all training videos, session materials, and resources to boost your skills.

Explore the OSCRAT resources designed to help SMEs, manufacturers and other organisations understand the Cyber Resilience Act (CRA) and take practical steps towards compliance.

This section brings together practical guidance, real-world examples and capacity-building materials developed throughout the OSCRAT project to support organisations in understanding CRA requirements and applying them in practice.

The Resources page is organised into three sections:

  1. OSCRAT Platform Launch and Demo
    Explore resources dedicated to the launch and practical use of the final OSCRAT Platform. Discover the OSCRAT Final Event to learn about the official platform launch and the project’s main achievements, and explore the OSCRAT in Action demo to follow UPKIP’s real-world CRA assessment journey and see how the platform can support organisations in practice.
  2. OSCRAT Use Cases & Best Practices Report
    Discover 12 representative CRA assessment scenarios showing how different digital products can be assessed in practice — from product classification and SBOM analysis to security requirements, remediation and conformity decisions. The report translates CRA requirements into practical guidance and illustrates how the OSCRAT platform can support organisations throughout their compliance journey.
  3. Training Sessions
    Explore OSCRAT training resources providing practical guidance on CRA requirements and helping organisations strengthen their knowledge, improve their preparedness and move forward on their compliance journey.
  4. Workshops
    Access materials and recordings from OSCRAT workshops designed to raise awareness of the CRA, explore practical compliance challenges and provide useful insights for SMEs and other stakeholders working with digital products.

Together, these resources offer practical support to help organisations better understand the Cyber Resilience Act, build internal knowledge and strengthen their cyber resilience.

Start exploring them below 👇

1. OSCRAT Platform Launch and Demo

Explore the final OSCRAT Platform through two complementary resources dedicated to its official launch and practical application. The OSCRAT Final Event presents the platform within the broader project journey and CRA compliance context, while the OSCRAT in Action demo shows how the platform can be used in practice through UPKIP’s real-world Cyber Resilience Act assessment journey.

OSCRAT Final Event and Platform Launch

Discover the official launch of the final OSCRAT Platform and the project’s main achievements. The event explores key Cyber Resilience Act requirements, demonstrates how OSCRAT translates them into practical compliance workflows, and highlights cooperation with other European CRA initiatives.

Watch the video

OSCRAT in Action: Platform Demo and UPKIP’s Cyber Resilience Assessment Journey

Explore the OSCRAT Platform in practice through UPKIP’s real-world Cyber Resilience Act assessment journey. Discover the platform’s main features and workflow, learn how to navigate its cybersecurity compliance functionalities, and see how OSCRAT supports organisations in assessing products, managing cybersecurity information and preparing compliance documentation.

Coming soon

2. OSCRAT Use Cases and Best Practices report

The OSCRAT Use Cases and Best Practices Final Report turns the Cyber Resilience Act into practical, real-world guidance for SMEs, manufacturers and other organisations working with digital products. Through 12 representative assessment scenarios, the report shows how to move from product classification to SBOM and security analysis, compliance assessment, remediation and conformity decisions. It also highlights practical best practices and demonstrates how the OSCRAT platform can help organisations structure and simplify their CRA compliance journey.

Download the report

3. Training sessions

Training session 1: Setting the context - what CRA changes, and why it matters

The first session established a baseline: the CRA is not simply another “security best practice” document. It introduces horizontal cybersecurity requirements for products with digital elements, anchored in the reality that software and connectivity have turned product security into a market-wide and supply-chain-wide risk.

Key themes included:

  • The CRA’s structure (including why the annexes matter as the practical backbone of compliance)
  • The enforcement and compliance architecture around conformity assessment
  • How CRA aligns with a wider EU resilience framework, where different instruments target different layers (products vs organisations vs sectoral resilience)
Watch the video

Download the training materials

Training session 2: Scope, accountability, and the compliance obligations that will “stick”

The second session moved into the core operational questions SMEs tend to ask first:

  • “Are we in scope?”
  • “Which of our products are affected?”
  • “Who is responsible – and for what – across the supply chain?”


Participants explored how the CRA applies to products with digital elements, including hardware, software, and the remote data processing elements (for example, supporting cloud components) that are necessary for a product to function.

Watch the video

Download the training materials

Training Session 3: Standards and conformity assessment - how “compliance” becomes credible

The third session addressed what many organisations underestimate: under the CRA, compliance is not just about having security controls. It is about being able to prove, with structured evidence, that controls exist, are appropriate, and are maintained. This is where standards and conformity assessment enter as the bridge between legal requirements and technical reality. The training unpacked how the standards landscape supports CRA implementation, including:

  • Why ISO 27001-style management controls matter (governance, repeatability, evidence)
  • The role of laboratories and certification bodies (including the wider quality and certification ecosystem)
  • The “horizontal vs vertical” standards model – general principles plus sector-specific detail – and how European initiatives are accelerating harmonised standards that can later support presumption of conformity
Watch the video

Download the training materials

Training session 4: Implementation roadmaps - from gap analysis to CE readiness

The fourth session concluded the 2025 arc by translating “CRA theory” into a readiness roadmap. First, it reinforced that the annexes are not supplementary reading – they are the compliance roadmap. Annexes provide templates for EU Declarations of Conformity, define technical documentation expectations, and describe conformity assessment procedures that must be followed before placing products on the EU market.

Second, the session highlighted practical sequencing. A CRA gap analysis was presented as the “reality check” that prevents late-stage surprises – especially when moving toward conformity assessment or market entry decisions.

Third, the training clarified that CRA compliance can follow different paths depending on product risk:

  • Higher-risk products may require third-party evaluation by a notified body
  • Lower-risk products may allow self-assessment, but only under specific conditions and typically supported by relevant harmonised standards
Watch the video

Download the training materials

4. Workshops

Workshop 1_Technical documentation and conformity readiness

Watch the video

Download the training materials

Workshop 2 – Incident response planning and management

Watch the video

Download the training materials

Workshop 3 - Vulnerability handling

Watch the video

Download the training materials