Article 14 reporting binds manufacturers from 11 September 2026, and the regulation applies in full from 11 December 2027. In most of the companies inside that scope, one person has been handed CRA readiness on top of an existing job. We built an eight-module certification course for that person, put a graded exam at the end of it, and made the whole thing free.
What a person-level certificate can and cannot claim
Worth settling first, because the CRA invites the confusion. Conformity under the Cyber Resilience Act attaches to a product, through conformity assessment, technical documentation, and the EU Declaration of Conformity. It never attaches to a person. No individual certificate makes a product compliant, and anyone selling one that claims otherwise is selling something the regulation does not recognise.
What a person-level credential can do is evidence competence. The manager who owns CRA readiness usually has to convince somebody above them that the work is in capable hands, and a consultant pitching CRA delivery has to convince a manufacturer of the same thing. A graded, verifiable certificate answers that question. It is a claim about the holder rather than about any product they touch, and it should be read that way.
Eight modules, five hours
The curriculum follows the regulation in the order a manufacturer meets it.
- CRA foundations, the four dates in the timeline, and the Article 2 scope boundaries
- Product classification across the default, important, and critical tiers
- Annex I Part I, the secure-by-design essential requirements
- Annex I Part II, vulnerability handling and the software bill of materials
- Article 13, the manufacturer's lifecycle obligations and the clocks attached to each
- Article 14, reporting actively exploited vulnerabilities and severe incidents
- Conformity assessment, technical documentation, and CE marking
- Economic operators, market surveillance, and the penalty structure
Five hours of study in total, carrying 6 CPE credits for anyone maintaining a CISSP, CISA, or CISM. Each module ends in a quiz that has to be passed at 70 percent before the next module opens.
The exam is the part that matters
A completion badge issued for scrolling to the bottom of a page is worth what it costs to obtain. We wanted the certificate to survive somebody actually checking it, which meant building an exam that skimming does not pass.
The final exam draws 60 questions from a bank of 939, so no two sittings are alike. Ninety minutes, 75 percent to pass, three attempts, and it only unlocks once every module quiz has been passed. Starting an attempt consumes it. The result returns a per-module breakdown rather than an answer key, so the exam stays a measurement rather than becoming a study guide.
A credential that does not depend on us
The certificate is issued as an Open Badges 3.0 achievement credential, which is a W3C Verifiable
Credential. It is signed with an Ed25519 key, and the public half is published at
did:web:cvdportal.com. Any verifier can resolve that key and check the signature without
contacting us, asking our permission, or trusting that our servers are up.
Revocation runs through a hosted Bitstring Status List, so a withdrawn certificate reports itself as withdrawn rather than quietly disappearing. Disclosure is tiered. A member of the public following a verification link sees the holder's name, the credential, its level, its standing, and the month it was earned. The exact date, the score, and the employer are visible only to the holder. The assertion itself carries a salted hash of the email address rather than the address.
Porta Regulus BV is the issuer of record, and the credential goes onto a LinkedIn profile in one click.
The limits, stated plainly
The credential is issued at the Foundational level, and that label is doing real work. The exam is free, taken online, and unproctored, with attempts capped at three. That supports a knowledge credential. It falls short of an identity-verified professional qualification, and we would rather say so than let somebody discover it later.
The course is training material. It is not legal advice, it is not accredited, and it does not come from a notified body. Higher tiers are planned as the harmonised standards publish ahead of December 2027, and they will be separate credentials with a stronger integrity model.
Why we give it away
The market that has to comply with the CRA is mostly small manufacturers who did not plan for it and cannot buy their way out. Every one of them we train is a company more likely to publish a disclosure policy, meet a reporting deadline, and hold a technical file that survives inspection. That raises the floor in the market we work in, and it costs us the price of writing the material once.
The course is open now, with no account and no card. Start at cvdportal.com/academy/cra-manufacturer. Consultants and delivery partners have their own track at cvdportal.com/partners/academy.