Skip to main content
BUSINESS • 8 min read

The Cyber Resilience Act (CRA): building hands-on cyber capability across your product teams

For most of the past two decades, a product's security wasn’t explicitly owned by the team building it. Security primarily someone else's job. A dedicated security team, a security operations center, a specialist with "security" in their title owned it, while the people writing the code, running the pipeline and signing off the release were rarely expected to hold much security knowledge of their own. The Cyber Resilience Act (CRA) unwinds that arrangement. By treating cybersecurity as a property of the product across its whole lifecycle, from design through to the support period after release, the CRA draws engineering, DevOps, QA, product and leadership into the work of building security into products.

Bringing non-specialists into security work is now a practical objective for anyone planning how to prepare a team. The teams now adding security to their responsibilities have, in many cases, never trained for it. It’s crucial that they have the support to build real, working capability, starting from wherever they are today.

TL;DR:

  • The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements placed on the European Union (EU) market, applied across the product lifecycle.
  • The CRA spreads responsibility for security beyond a dedicated security team and into teams including engineering, DevOps, QA, product and leadership functions.
  • The practical response is hands-on capability in secure development, vulnerability management and incident response, built on solid foundations.
  • Applied, in-browser training lets someone with no security background start from zero, learn in short feedback loops, and progress toward validated, demonstrable capability at their own pace.

What is the Cyber Resilience Act (CRA)?

The Cyber Resilience Act is an EU regulation, Regulation (EU) 2024/2847, that sets cybersecurity requirements for products with digital elements sold on the EU market, applied across the product's whole lifecycle. It is designed to make security a built-in property of hardware and software products rather than an afterthought added late, and it reaches the full range of digital products, from connected devices and firmware to standalone software.

The regulation is already in force, with its main obligations phasing in through 2027. The European Commission's Cyber Resilience Act page and its summary of the legislative text set out the scope, obligations and timelines in full.

Which teams does the Cyber Resilience Act affect inside an organization?

The CRA brings the whole product team into cyber security, extending responsibility beyond a dedicated security function and into the roles that design, build, test and ship digital products. Security is no longer owned solely by the security operations center (SOC) or a specialist security team.

In practice, that reaches a wide set of functions across the product lifecycle:

  • Engineering and DevOps. The people writing and shipping code carry much of the work of building security in from the design stage, since design-stage weaknesses tend to be the costliest to fix later.
  • QA and testing. Testing functions increasingly need to check for security issues alongside functional ones.
  • Product and platform. Product and platform teams shape decisions that affect a product's security posture, so they benefit from enough fluency to make security-informed choices.
  • Leadership. Leaders setting priorities and signing off releases need a working understanding of the trade-offs involved.

Because security knowledge has often been concentrated in a specialist team rather than among the engineers writing the code, spreading capability across these functions is fundamental to compliance.

What cyber security capabilities does the CRA point to?

The CRA points to a set of practical cyber security capabilities that live across the process of product development, each of which maps onto skills a team can learn and demonstrate. The regulation frames these at a high level, and the underlying capabilities include:

  • Security by design. Building security into a product from the design stage, informed by risk, so products ship in a secure default state.
  • Secure development practices. Applying secure coding, dependency management and security testing across the software development lifecycle, so issues are caught early.
  • Vulnerability management. Identifying, documenting and remediating vulnerabilities in a product throughout its supported life.
  • Coordinated vulnerability disclosure. Running a policy and mechanism for receiving and handling vulnerability reports, including from external researchers.
  • Incident response. Detecting, triaging and responding to security incidents in a structured way.
  • Ongoing cybersecurity accountability. Sustaining security practice, documentation and evidence over the life of a product rather than treating it as a one-time task.

Each of these is a capability a team can develop through hands-on practice, which is where a training approach makes the difference between awareness and ability.

Why do product teams need hands-on cyber security capability rather than awareness training?

Product teams need hands-on capability because the CRA asks them to build security into day-to-day engineering work, and applying security in practice is a different skill from recognizing it in a slideshow. Policies, tooling and an annual awareness session can raise awareness, yet they rarely produce the working ability to write secure code, predict or manage a vulnerability, let alone handle an incident under pressure.

Applied, scenario-based practice tends to produce retained, usable knowledge that creates a shared language with cyber practitioners, and transfers directly into engineering and operational workflows. It also meets people where they are: content that spans from no prior security experience through to mid-senior practitioner level lets a whole team build relevant capability, whatever their starting point. Capability built this way fits around existing delivery work rather than disrupting it, so engineers, product managers and operational teams can develop skills without stepping away from shipping.

Building that capability safely calls for a sandboxed, in-browser environment rather than practice on production systems, so people can make mistakes, see the consequences, and learn without risk. That safe space is what lets a non-specialist get hands-on from the very first lesson.

How can someone with no background learn cyber security from scratch?

Someone with no security background can start safely by working through guided, in-browser labs that begin at the absolute fundamentals and build up one hands-on step at a time, inside a sandboxed environment where nothing they do touches a real system. Starting from zero is the norm rather than the exception, and the short feedback loop of trying something, seeing the result immediately, and moving on is what makes early progress stick.

A practical way for a mixed team to start is to match the entry point to each person's role and experience:

Capability area Who it suits Where a team can start
Foundations, from zero Product, QA, leadership, anyone new to security Pre Security and Cyber Security 101 paths
Security by design and secure development Engineering and DevOps DevSecOps path and the Secure SDLC room
Vulnerability management Engineering and security Threat and Vulnerability Management module
Incident response Engineering, operations and security Incident Response module and SOC Level 1 path
Validated, demonstrable capability Whole team, and leadership seeking evidence Practical certifications, from SEC0 through AI1

For people with no prior experience, TryHackMe's Pre Security and Cyber Security 101 paths build the underlying concepts, including how computers, networks and the web work, before moving into security itself. The learning happens in the browser with no setup, so a product manager or QA engineer can begin in minutes and build a shared vocabulary with the specialists they work alongside. Once the cyber security basics are in place, TryHackMe's AI security path and certification adds essential grounding for anyone whose work touches AI systems, from engineers to product managers.

How do product teams progress from cyber security foundations to validated capability?

A team progresses from foundations to validated capability by moving from introductory paths into role-relevant, hands-on content, then proving what people can do through practical assessment. The progression is designed so that each stage builds on the last, and people advance as their confidence and skill grow.

For engineering and DevOps functions, the DevSecOps learning path works through secure software development, source code security, dependency management, static and dynamic application security testing (SAST and DAST), continuous integration and delivery (CI/CD) pipeline security, and container security. The secure-by-design foundations are covered in the Secure Software Development Lifecycle room and the free Introduction to DevSecOps room, and the same path is framed for team leads in TryHackMe's DevSecOps training for teams. Vulnerability work is covered hands-on in the Threat and Vulnerability Management module and the Vulnerability Research module, and incident handling in the Incident Response module, the SOC Level 1 path and TryHackMe's guidance on learning incident response the hands-on way.

Because the CRA values demonstrable capability, a validated credential gives a team evidence of real ability rather than a record of course completion. TryHackMe's practical certification range is assessed through hands-on exams rather than multiple-choice questions, and it runs from foundational credentials such as Pre Security (SEC0) and Cyber Security 101 (SEC1) up to specialist ones, including AI Security (AI1), a hands-on certification for identifying, exploiting and defending real AI systems that assumes no prior AI background. As products increasingly embed AI, that kind of modern specialism becomes part of the same ladder a beginner can climb from the very foundations.

Frequently asked questions about the Cyber Resilience Act and cyber security training

What is the Cyber Resilience Act (CRA)?

The Cyber Resilience Act is an EU regulation, Regulation (EU) 2024/2847, that sets cybersecurity requirements for products with digital elements placed on the EU market, applied across the product lifecycle from design through post-market support. It is designed to make security a built-in property of hardware and software products. For its precise scope and obligations, the European Commission's Cyber Resilience Act page is the authoritative source.

Which teams inside an organization does the CRA affect?

The CRA affects the whole product team, reaching beyond a dedicated security function. Engineering and DevOps carry much of the work of building security into products, QA and testing check for security issues alongside functional ones, product and platform teams make decisions that affect security posture, and leadership sets priorities and signs off releases. Spreading capability across these functions, rather than concentrating it in a specialist team, is the central workforce challenge.

What cyber security skills do product teams need for the CRA?

Product teams need practical capability in secure development, vulnerability management and incident response, since those are the skill areas behind the CRA's capabilities. Secure development covers secure-by-design methodology, secure coding and pipeline security; vulnerability management covers identifying, documenting and remediating issues over a product's life; and incident response covers detecting, triaging and responding to incidents. Foundational security literacy across non-technical functions supports all three.

Can someone with no security background learn cyber security from scratch?

Yes. Guided, in-browser training lets a complete beginner start from the fundamentals and build up one hands-on step at a time, inside a sandboxed environment where nothing they do affects a real system. TryHackMe's Pre Security and Cyber Security 101 paths begin with how computers, networks and the web work before moving into security, so people from product, QA or engineering can start with no prior experience and progress at their own pace.

How can a team demonstrate the cyber security capability the CRA expects?

A team can demonstrate capability by validating it through practical, hands-on assessment rather than attendance records. Assessments that require a person to apply skills in a live environment produce evidence of what they can actually do, which supports the demonstrable, ongoing accountability the CRA emphasizes. TryHackMe's practical certifications, from foundational credentials through to specialist ones such as AI Security (AI1), provide that kind of verifiable record.

The CRA turns cybersecurity into a shared, whole-team practice, which gives organizations a clear reason to help non-specialists build real capability from the ground up. See how role-mapped, hands-on training helps teams start from zero and grow the cyber security capability the CRA calls for at TryHackMe for Business.

authorJoanna Duffy
Aug 16, 2026

Recommended

Get more insights, news, and assorted awesomeness around cyber training.

Join over 640 organisations upskilling their
workforce with TryHackMe