PortaRegulus
HOME
13 // INTEL · PRODUCT

Five hours, a real exam, and a credential that verifies without us.

A free EU Cyber Resilience Act certification for the manufacturers, compliance managers, and engineers who have to do the work.

PortaRegulus Intel CRA · Product 06 Aug 2026

Article 14 reporting binds manufacturers from 11 September 2026, and the regulation applies in full from 11 December 2027. In most of the companies inside that scope, one person has been handed CRA readiness on top of an existing job. We built an eight-module certification course for that person, put a graded exam at the end of it, and made the whole thing free.

What a person-level certificate can and cannot claim

Worth settling first, because the CRA invites the confusion. Conformity under the Cyber Resilience Act attaches to a product, through conformity assessment, technical documentation, and the EU Declaration of Conformity. It never attaches to a person. No individual certificate makes a product compliant, and anyone selling one that claims otherwise is selling something the regulation does not recognise.

What a person-level credential can do is evidence competence. The manager who owns CRA readiness usually has to convince somebody above them that the work is in capable hands, and a consultant pitching CRA delivery has to convince a manufacturer of the same thing. A graded, verifiable certificate answers that question. It is a claim about the holder rather than about any product they touch, and it should be read that way.

Eight modules, five hours

The curriculum follows the regulation in the order a manufacturer meets it.

Five hours of study in total, carrying 6 CPE credits for anyone maintaining a CISSP, CISA, or CISM. Each module ends in a quiz that has to be passed at 70 percent before the next module opens.

The exam is the part that matters

A completion badge issued for scrolling to the bottom of a page is worth what it costs to obtain. We wanted the certificate to survive somebody actually checking it, which meant building an exam that skimming does not pass.

The final exam draws 60 questions from a bank of 939, so no two sittings are alike. Ninety minutes, 75 percent to pass, three attempts, and it only unlocks once every module quiz has been passed. Starting an attempt consumes it. The result returns a per-module breakdown rather than an answer key, so the exam stays a measurement rather than becoming a study guide.

A credential that does not depend on us

The certificate is issued as an Open Badges 3.0 achievement credential, which is a W3C Verifiable Credential. It is signed with an Ed25519 key, and the public half is published at did:web:cvdportal.com. Any verifier can resolve that key and check the signature without contacting us, asking our permission, or trusting that our servers are up.

Revocation runs through a hosted Bitstring Status List, so a withdrawn certificate reports itself as withdrawn rather than quietly disappearing. Disclosure is tiered. A member of the public following a verification link sees the holder's name, the credential, its level, its standing, and the month it was earned. The exact date, the score, and the employer are visible only to the holder. The assertion itself carries a salted hash of the email address rather than the address.

Porta Regulus BV is the issuer of record, and the credential goes onto a LinkedIn profile in one click.

The limits, stated plainly

The credential is issued at the Foundational level, and that label is doing real work. The exam is free, taken online, and unproctored, with attempts capped at three. That supports a knowledge credential. It falls short of an identity-verified professional qualification, and we would rather say so than let somebody discover it later.

The course is training material. It is not legal advice, it is not accredited, and it does not come from a notified body. Higher tiers are planned as the harmonised standards publish ahead of December 2027, and they will be separate credentials with a stronger integrity model.

Why we give it away

The market that has to comply with the CRA is mostly small manufacturers who did not plan for it and cannot buy their way out. Every one of them we train is a company more likely to publish a disclosure policy, meet a reporting deadline, and hold a technical file that survives inspection. That raises the floor in the market we work in, and it costs us the price of writing the material once.

The course is open now, with no account and no card. Start at cvdportal.com/academy/cra-manufacturer. Consultants and delivery partners have their own track at cvdportal.com/partners/academy.

Learn the regulation. Prove it.