Cyber Resilience Act Trained Professional (CybResActTPro) program



Overview

The Cyber Resilience Act (CRA) is a landmark EU regulation aimed at enhancing the cybersecurity of products with digital elements throughout their lifecycle. As cyber threats grow in sophistication, the CRA mandates robust security measures, impacting manufacturers, importers, and distributors on a global scale.

The CRA emerges as a critical regulatory framework in today’s volatile geopolitical landscape, where cyber threats are increasingly weaponized by state and non-state actors. As digital infrastructures face growing risks from adversaries targeting national security and economic stability, the CRA plays a vital role in ensuring that products with digital elements are less vulnerable to exploitation.

In this evolving geopolitical environment, the CRA is more than just a regulation—it is a strategic initiative designed to foster resilience, security, and trust in an increasingly hostile cyber landscape.

The marketplace is clearly demanding qualified professionals with the knowledge and skills needed to ensure compliance with this regulation.


Objectives

The program has been designed to provide with the skills needed to understand and support compliance with the European Cyber Resilience Act (CRA).

It also provides with the skills needed to pass the Cyber Resilience Act Trained Professional (CybResActTPro) exam, and to receive the Certificate of Completion, that provides independent evidence to firms and organizations that you have a quantifiable understanding of the subject matter.


Target Audience

The program is beneficial to:

1. Manufacturers, Distributors, Importers and Developers of hardware and software products with digital elements placed on the market of the European Union. They must comply with CRA requirements for cybersecurity by design, and ensure their products are secure throughout their lifecycle.

2. Risk managers, responsible for identifying, analyzing, and mitigating risks to organizational objectives, including the CRA.

3. Compliance managers, ensuring that organizational practices align with applicable regulations, including the CRA.

4. Internal and external auditors, tasked with assessing compliance with cybersecurity and regulatory standards, including the CRA.

5. Cybersecurity and ICT managers and professionals, and software engineers.

6. Consultants, suppliers, and service providers that work for companies and organizations that have to comply with the CRA. They must align their services with CRA requirements to support client compliance.


Course Synopsis.


Introduction.
• The Cyber Resilience Act Trained Professional (CybResActTPro) exam.
• The certificate of completion.


Part 1 - The European Union. How does the legislative process work?
• Key institutions.
• The European Commission, the most important institution for risk and compliance professionals.
• How does the legislative process work?
• The European System of Financial Supervision (ESFS).
• Legal acts after the Treaty of Lisbon.
• Delegated acts, supplementing or amending certain non-essential elements of a basic act.
• Implementing acts.
• Regulatory technical standards (RTS).
• Implementing technical standards (ITS).
• The European Data Protection Supervisor and the European Data Protection Board.
• The Committee of European Auditing Oversight Bodies (CEAOB).
• The European External Action Service.
• The Common Foreign and Security Policy (CFSP).
• The Common Security and Defence Policy (CSDP).
• The European Network and Information Security Agency (ENISA).
• The NIS Cooperation Group.
• The European cyber crisis liaison organisation network (EU-CyCLONe).
• The High-Level Expert Group on Artificial Intelligence (AI HLEG).


Part 2 - Before the Cyber Resilience Act.
• The EU’s Cybersecurity Strategy for the Digital Decade.
• The need for the Cyber Resilience Act.


Part 3 - The Cyber Resilience Act.

CHAPTER I, GENERAL PROVISIONS.
• Article 1, Subject matter.
• Article 2, Scope.
• Article 3, Definitions.
• Article 4, Free movement.
• Article 5, Procurement or use of products with digital elements.
• Article 6, Requirements for products with digital elements.
• Article 7, Important products with digital elements.
• Article 8, Critical products with digital elements.
• Article 9, Stakeholder consultation.
• Article 10, Enhancing skills in a cyber resilient digital environment.
• Article 11, General product safety.
• Article 12, High-risk AI systems.


CHAPTER II, OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE.
• Article 13, Obligations of manufacturers.
• Article 14, Reporting obligations of manufacturers.
• Article 15, Voluntary reporting.
• Article 16, Establishment of a single reporting platform.
• Article 17, Other provisions related to reporting.
• Article 18, Authorised representatives.
• Article 19, Obligations of importers.
• Article 20, Obligations of distributors.
• Article 21, Cases in which obligations of manufacturers apply to importers and distributors.
• Article 22, Other cases in which obligations of manufacturers apply.
• Article 23, Identification of economic operators.
• Article 24, Obligations of open-source software stewards.
• Article 25, Security attestation of free and open-source software.
• Article 26, Guidance.


CHAPTER III, CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTS.
• Article 27, Presumption of conformity.
• Article 28, EU declaration of conformity.
• Article 29, General principles of the CE marking.
• Article 30, Rules and conditions for affixing the CE marking.
• Article 31, Technical documentation.
• Article 32, Conformity assessment procedures for products with digital elements.
• Article 33, Support measures for microenterprises and small and medium sized enterprises, including start-ups.
• Article 34, Mutual recognition agreements.


CHAPTER IV, NOTIFICATION OF CONFORMITY ASSESSMENT BODIES.
• Article 35, Notification.
• Article 36, Notifying authorities.
• Article 37, Requirements relating to notifying authorities.
• Article 38, Information obligation on notifying authorities.
• Article 39, Requirements relating to notified bodies.
• Article 40, Presumption of conformity of notified bodies.
• Article 41, Subsidiaries of and subcontracting by notified bodies.
• Article 42, Application for notification.
• Article 43, Notification procedure.
• Article 44, Identification numbers and lists of notified bodies.
• Article 45, Changes to notifications.
• Article 46, Challenge of the competence of notified bodies.
• Article 47, Operational obligations of notified bodies.
• Article 48, Appeal against decisions of notified bodies.
• Article 49, Information obligation on notified bodies.
• Article 50, Exchange of experience.
• Article 51, Coordination of notified bodies.


CHAPTER V, MARKET SURVEILLANCE AND ENFORCEMENT.
• Article 52, Market surveillance and control of products with digital elements in the Union market.
• Article 53, Access to data and documentation.
• Article 54, Procedure at national level concerning products with digital elements presenting a significant cybersecurity risk.
• Article 55, Union safeguard procedure.
• Article 56, Procedure at Union level concerning products with digital elements presenting a significant cybersecurity risk.
• Article 57, Compliant products with digital elements which present a significant cybersecurity risk.
• Article 58, Formal non-compliance.
• Article 59, Joint activities of market surveillance authorities.
• Article 60, Sweeps.


CHAPTER VI, DELEGATED POWERS AND COMMITTEE PROCEDURE.
• Article 61, Exercise of the delegation.
• Article 62, Committee procedure.


CHAPTER VII, CONFIDENTIALITY AND PENALTIES.
• Article 63, Confidentiality.
• Article 64, Penalties.
• Article 65, Representative actions.


CHAPTER VIII, TRANSITIONAL AND FINAL PROVISIONS.
• Article 66, Amendment to Regulation (EU) 2019/1020.
• Article 67, Amendment to Directive (EU) 2020/1828.
• Article 68, Amendment to Regulation (EU) No 168/2013.
• Article 69, Transitional provisions.
• Article 70, Evaluation and review.
• Article 71, Entry into force and application.


Part 4 - NIS 2, DORA, CER, and the Cyber Resilience Act.
• The “lex specialis derogat legi generali” (special law repeals general laws) doctrine.
• The CRA is not lex specialis. It is designed to complement the other legal acts.


Part 5 - Other EU Directives and Regulations.
Strategic consolidation of compliance projects for multiple EU Regulations and Directives.
1. The NIS 2 Directive.
2. The Digital Operational Resilience Act (DORA).
3. The Critical Entities Resilience Directive (CER).
4. The European Data Act.
5. The European Data Governance Act (DGA).
6. The Digital Services Act (DSA).
7. The Digital Markets Act (DMA).
8. The Artificial Intelligence Act (AI Act).
9. The European Digital Identity Regulation (eIDAS 2.0).
10. The European Chips Act.
11. The EU Cyber Solidarity Act.
12. The Corporate Sustainability Due Diligence Directive (CSDDD).
13. The Artificial Intelligence Liability Directive.
14. The Digital Networks Act (DNA).
15. The European ePrivacy Regulation.
16. The European Health Data Space (EHDS).
17. The European Financial Data Space (EFDS).
18. The Financial Data Access (FiDA) Regulation.
19. The Payment Services Directive 3 (PSD3), Payment Services Regulation (PSR).
20. The Internal Market Emergency and Resilience Act (IMERA).
21. The European Media Freedom Act (EMFA).
22. The Digital Fairness Act.
23. The European Space Law (EUSL).


Become a Cyber Resilience Act Trained Professional (CybResActTPro)

This is a Distance Learning with Certificate of Completion program, provided by Cyber Risk GmbH. The General Terms and Conditions for all legal transactions made through the Cyber Risk GmbH websites (hereinafter “GTC”) can be found at: https://www.cyber-risk-gmbh.com/Impressum.html

Each Distance Learning with Certificate of Completion program (hereinafter referred to as “distance learning program”) is provided at a fixed price, that includes VAT. There is no additional cost, now or in the future, for any reason.

We will send the distance learning program via email up to 24 hours after the payment (working days). Please remember to check the spam folder of your email client too, as emails with attachments are often landed in the spam folder.

You have the option to ask for a full refund up to 60 days after the payment. If you do not want one of our distance learning programs for any reason, all you must do is to send us an email, and we will refund the payment, no questions asked.

Your payment will be received by Cyber Risk GmbH (Dammstrasse 16, 8810 Horgen, Switzerland, Handelsregister des Kantons Zürich, Firmennummer: CHE-244.099.341). Cyber Risk GmbH will also send the certificates of completion to all persons that will pass the exam.

The all-inclusive cost is 297 USD (US Dollars).


First option: You can purchase the Cyber Resilience Act Trained Professional (CybResActTPro) program with VISA, MASTERCARD, AMEX, Apple Pay, Google Pay etc.

Purchase the CybResActTPro program here (VISA, MASTERCARD, AMEX, Apple Pay, Google Pay etc.)





Second option: QR code payment.

i. Open the camera app or the QR app on your phone.

ii. Scan the QR code and possibly wait for a few seconds.

iii. Click on the link that appears, open your browser, and make the payment.


CybResActTPro QR Payment


Third option: You can purchase the Digital Operational Resilience Act Trained Professional (DORATPro) program with PayPal

You will be redirected to the PayPal web site.



What is included in the cost of the distance learning program:


A. The official presentations (1068 slides).

The presentations are effective and appropriate to study online or offline. Busy professionals have full control over their own learning and are able to study at their own speed. They are able to move faster through areas of the course they feel comfortable with, but slower through those that they need a little more time on.


B. Up to 3 online exam attempts per year.

Candidates must pass only one exam. If they fail, they must study the official presentations and retake the exam. Candidates are entitled to 3 exam attempts every year.

If candidates do not achieve a passing score on the exam the first time, they can retake the exam a second time.

If they do not achieve a passing score the second time, they can retake the exam a third time.

If candidates do not achieve a passing score the third time, they must wait at least one year before retaking the exam. There is no additional cost for additional exam attempts. To learn more, you may visit: https://www.european-cyber-resilience-act.com/Distance_Learning_Programs_Exam_Certificate_of_Completion.pdf


C. The certificate of completion, with a scannable QR code for verification.

You will receive your certificate via email in Adobe Acrobat format (pdf), with a scannable QR code for verification, 7 business days after you pass the exam. A business day refers to any day in which normal business operations are conducted (in our case Monday through Friday), excluding weekends and public holidays.




D. Cyber Risk GmbH will develop a web page dedicated to each certified professional (https://www.cyber-risk-gmbh.com/Your_Name.htm).

When third parties scan the QR code on your certificate, they will visit this web page (https://www.cyber-risk-gmbh.com/Your_Name.htm), and they will be able to verify that you are a certified professional, and your certificates are valid and legitimate.

In this web page we will have your name, all the certificates you have received from us, and pictures of your certificates.

This is an example: https://www.cyber-risk-gmbh.com/Emma_Schmidt.html

You can print your certificate that you will receive in Adobe Acrobat format (pdf). With the scannable QR code, all third parties can verify the authenticity of each certificate in a matter of seconds. Professional certificates are some of the most frequently falsified documents. Employers and third parties need an easy, effective, and efficient way to check the authenticity of each certificate. QR code verification is a good response to this demand.



E. A $100 discount for your second (and each additional) program.

The all-inclusive cost of your first program is $297. The all-inclusive cost of your second (and each additional) program is $197. It includes the exam, the certificate of completion, and all the updated and amended programs at no cost until January 31, 2028.



Frequently Asked Questions for the distance learning programs.


1. I want to know more about Cyber Risk GmbH.


“Cyber Risk GmbH” is a company incorporated in Switzerland.
Registered address: Dammstrasse 16, 8810 Horgen, Switzerland.
Company number: CHE-244.099.341.
Cantonal Register of Commerce: Canton of Zürich.
Swiss VAT number: CHE-244.099.341 MWST.
EU VAT number: EU276036462. Cyber Risk GmbH is registered for EU VAT purposes in Germany (Bundeszentralamt für Steuern, One-Stop-Shop, Nicht EU-Regelung) for the sale of services in the EU. Cyber Risk GmbH declares and pays EU VAT in a single electronic quarterly return submitted to Germany, and the German Bundeszentralamt für Steuern forwards the EU VAT due to each member State of the EU.


Cyber Risk GmbH was founded in Horgen, Switzerland, by George Lekatis, an acclaimed expert in risk and compliance management. The company specializes in providing advanced cybersecurity and compliance training, helping organizations navigate and implement complex European, U.S., and international cybersecurity regulations. Additionally, Cyber Risk GmbH supports professionals in completing online training programs, passing exams, and obtaining Certificates of Completion, which serve as independent verification of their expertise for firms and organizations.

George Lekatis serves as the General Manager of Compliance LLC, a company incorporated in Wilmington, NC, with offices in Washington, DC. Compliance LLC provides risk and compliance training in 58 countries. Several of its business units function as highly successful associations, offering a wide range of services to their members, including membership programs, regular updates (weekly or monthly), specialized training, certification, Authorized Certified Trainer (ACT) programs, advocacy, and other professional services.

George is the president of the International Association of Risk and Compliance Professionals (IARCP, https://www.risk-compliance-association.com). He leads the team responsible for developing and maintaining the Certified Risk and Compliance Management Professional (CRCMP) program. The CRCMP certification is widely regarded as a preferred credential by companies and organizations. For more information on the demand for CRCMPs, you may visit: https://www.risk-compliance-association.com/CRCMP_Jobs_Careers.pdf


CRCMP careers

George has acquired over 20,000 hours of experience as a seminar leader, providing training and executive coaching in information security and risk management to leading global organizations across 36 countries. He holds a Master of Laws (LL.M.) in International Business Law from the University of London (Queen Mary and UCL). Beginning his career as a mathematician, George has since earned 60 professional certifications in information security, risk management, and IT. His credentials include the Certified Information Systems Security Professional (CISSP) lead instructor, Steganography Investigator, and certifications from the Internet Security Systems (ISS) in Internet Scanner, Database Scanner, and System Scanner. He is also a Checkpoint Certified Security Administrator (CCSA), Microsoft Certified Systems Engineer (MCSE), and Microsoft Certified Trainer (MCT). As an expert witness and litigation consultant, he is qualified to investigate and provide testimony on compliance with European, U.S., and international regulations.

George Lekatis is a highly sought-after expert on Basel III, with deep expertise in helping international firms and financial conglomerates develop controls and systems to meet complex regulatory requirements. He serves as the President of the Basel III Compliance Professionals Association (BiiiCPA, https://www.basel-iii-association.com), the world’s largest association of Basel III professionals, dedicated to supporting compliance across the global financial sector.

George also serves as the President of the Sarbanes-Oxley Compliance Professionals Association (SOXCPA, https://www.sarbanes-oxley-association.com), the world’s largest association of Sarbanes-Oxley professionals.

Our instructors are professionals with extensive, real-world experience in their respective fields. They are equipped to deliver full-time, part-time, or short-form programs, all customized to suit your specific requirements. Beyond teaching, our instructors provide hands-on guidance, offering real-world insights that help bridge the gap between theory and practice. You will always be informed ahead of time about the instructor leading your program.



“Cyber Risk GmbH Training Programs” are training programs developed, updated and provided by Cyber Risk GmbH, and include:
a) In-House Instructor-Led Training programs,
b) Online Live Training programs,
c) Video-Recorded Training programs,
d) Distance Learning with Certificate of Completion programs.


“Cyber Risk GmbH websites” are all websites that belong to Cyber Risk GmbH, and include the following:


a. Sectors and Industries.

1. Cyber Risk GmbH

2. Social Engineering Training

3. Healthcare Cybersecurity

4. Airline Cybersecurity

5. Railway Cybersecurity

6. Maritime Cybersecurity

7. Oil Cybersecurity

8. Electricity Cybersecurity

9. Gas Cybersecurity

10. Hydrogen Cybersecurity

11. Transport Cybersecurity

12. Transport Cybersecurity Toolkit

13. Hotel Cybersecurity

14. Sanctions Risk

15. American Privacy Rights Act of 2024 (APRA)

16. Travel Security


b. Understanding Cybersecurity.

1. What is Disinformation?

2. What is Steganography?

3. What is Cyberbiosecurity?

4. What is Synthetic Identity Fraud?

5. What is a Romance Scam?

6. What is Cyber Espionage?

7. What is Sexspionage?

8. What is the RESTRICT Act?


c. Understanding Cybersecurity in the European Union.

1. The NIS 2 Directive

2. The Digital Operational Resilience Act (DORA)

3. The Critical Entities Resilience Directive (CER)

4. The European Data Act

5. The European Data Governance Act (DGA)

6. The European Cyber Resilience Act (CRA)

7. The Digital Services Act (DSA)

8. The Digital Markets Act (DMA)

9. The European Chips Act

10. The Artificial Intelligence Act

11. The Artificial Intelligence Liability Directive

12. The Framework for Artificial Intelligence Cybersecurity Practices (FAICP)

13. The EU Cyber Solidarity Act

14. The Digital Networks Act (DNA)

15. The European ePrivacy Regulation

16. The European Digital Identity Regulation

17. The European Media Freedom Act (EMFA)

18. The Corporate Sustainability Due Diligence Directive (CSDDD)

19. The Systemic Cyber Incident Coordination Framework (EU-SCICF)

20. The European Health Data Space (EHDS)

21. The European Financial Data Space (EFDS)

22. The Financial Data Access (FiDA) Regulation

23. The Payment Services Directive 3 (PSD3), Payment Services Regulation (PSR)

24. Internal Market Emergency and Resilience Act (IMERA)

25. The European Cyber Defence Policy

26. The Strategic Compass of the European Union

27. The European Space Law (EUSL)

28. The EU-US Data Privacy Framework

29. The EU Cyber Diplomacy Toolbox



2. Is there any discount available for the distance learning programs?

We do not offer a discount for your first program. You have a $100 discount for your second and each additional program.

After you purchase the Cyber Resilience Act Trained Professional (CybResActTPro) program at $297, you can purchase:

a. The NIS 2 Directive Trained Professional (NIS2DTP) program at $197. You can find more about the program at: https://www.nis-2-directive.com/NIS_2_Directive_Trained_Professional_(NIS2DTP).html.

b. The Digital Operational Resilience Act Trained Professional (DORATPro) program at $197. You can find more about the program at: https://www.digital-operational-resilience-act.com/Digital_Operational_Resilience_Act_Trained_Professional_(DORATPro).html .

c. The Critical Entities Resilience Directive Trained Professional (CERDTPro) program at $197. You can find more about the program at: https://www.critical-entities-resilience-directive.com/Critical_Entities_Resilience_Directive_Trained_Professional_(CERDTPro).html.

d. The Digital Services Act Trained Professional (DiSeActTPro) program at $197. You can find more about the program at: https://www.eu-digital-services-act.com/DiSeActTPro_Training.html.

e. The Digital Markets Act Trained Professional (DiMaActTPro) program at $197. You can find more about the program at: https://www.eu-digital-markets-act.com/DiMaActTPro_Training.html.

f. The Data Governance Act Trained Professional (DatGovActTP) program at $197. You can find more about the program at: https://www.european-data-governance-act.com/DatGovActTP_Training.html.

g. The European Chips Act Trained Professional (EChipsActTPro) program at $197. You can find more about the program at: https://www.european-chips-act.com/European_Chips_Act_Trained_Professional_(EChipsActTPro).html .

h. The Data Act Trained Professional (DataActTPro) program at $197. You can find more about the program at: https://www.eu-data-act.com/Data_Act_Trained_Professional_(DataActTPro).html .

i. The Artificial Intelligence Act Trained Professional (AIActTPro) program at $197. You can find more about the program at: https://www.artificial-intelligence-act.com/Artificial_Intelligence_Act_Trained_Professional_(AIActTPro).html .

In order to receive the URL for the discounted cost for your second and each additional program, please send us an email with title: “Please send me the URL for the discounted cost.”

In the email, please let us know:

a. Which was the name and email address of the person or legal entity that had purchased the first program.

b. Which is the program you want to purchase now at $197 instead of $297.

You will receive the URL for the discounted cost for your second and each additional program in less than 48 hours (working days). Please remember to check your spam folder too.



3. Are there any entry requirements or prerequisites required for enrolling in the training programs?

There are no entry requirements or prerequisites for enrollment. Our programs give the opportunity to individuals of all levels to learn, grow, and develop new skills without the need for prior qualifications or specific experience.



4. I want to learn more about the exam.

You can take the exam online from your home or office, in all countries.

It is an open book exam. Risk and compliance management is something you must understand and learn, not memorize. You must acquire knowledge and skills, not commit something to memory.

You will be given 90 minutes to complete a 35-question exam. You must score 70% or higher.

The exam contains only questions that have been clearly answered in the official presentations.

All exam questions are multiple-choice, composed of two parts:

a. A stem (a question asked, or an incomplete statement to be completed).

b. Four possible responses.

In multiple-choice questions, you must not look for a correct answer, you must look for the best answer. Cross out all the answers you know are incorrect, then focus on the remaining ones. Which is the best answer? With this approach, you save time, and you greatly increase the likelihood of selecting the correct answer.

TIME LIMIT - This exam has a 90-minute time limit. You must complete this exam within this time limit, otherwise the result will be marked as an unsuccessful attempt.

BACK BUTTON - When taking this exam you are NOT permitted to move backwards to review/change prior answers. Your browser back button will refresh the current page instead of moving backward.

RESTART/RESUME – You CANNOT stop and then resume the exam. If you stop taking this exam by closing your browser, your answers will be lost, and the result will be marked as an unsuccessful attempt.

SKIP - You CANNOT skip answering questions while taking this exam. You must answer all the questions in the order the questions are presented.

When you are ready to take the exam, you must follow the steps described at "Question h. I am ready for the exam. What must I do?", at:

https://www.european-cyber-resilience-act.com/Distance_Learning_Programs_Exam_Certificate_of_Completion.pdf



5. How comprehensive are the presentations? Are they just bullet points?

The presentations are not bullet points. They are effective and appropriate to study online or offline.



6. Do I need to buy books to pass the exam?

No. If you study the presentations, you can pass the exam. All the exam questions are clearly answered in the presentations. If you fail the first time, you must study more. Print the presentations and use Post-it to attach notes, to know where to find the answer to a question.



7. Is it an open book exam? Why?

Yes, it is an open book exam. Risk and compliance management is something you must understand and learn, not memorize. You must acquire knowledge and skills, not commit something to memory.



8. Do I have to take the exam soon after receiving the presentations?

No. You can take the exam any time. Your account never expires. You have lifetime access to the training program. If there are any updates to the training material and you have not passed the exam, you will receive the updated program free of charge.



9. Do I have to spend more money in the future to keep my certificate of completion valid?

No. Your certificate of completion will remain valid, without the need to spend money or to take another exam in the future.



10. Ok, the certificate of completion never expires, but things change.

Recertification would be a great recurring revenue stream for Cyber Risk GmbH, but it would also be a recurring expense for our clients. We resisted the temptation to "introduce multiple recurring revenue streams to keep business flowing", as we were consulted. No recertification is needed for our programs.

Things change, and this is the reason you need to visit the "Reading Room" of Cyber Risk GmbH every month, and read the monthly newsletter with updates, alerts, and opportunities, to stay current. You may visit:

https://www.cyber-risk-gmbh.com/Reading_Room.html



11. Which is your refund policy?

Cyber Risk GmbH has a very clear refund policy: You have the option to ask for a full refund up to 60 days after the payment. If you do not want one of our programs for any reason, all you must do is to send us an email, and we will refund the payment after one business day, no questions asked.



12. I want to receive a printed certificate. Can you send me one?

Unfortunately this is not possible. You will receive your certificate via email in Adobe Acrobat format (pdf), with a scannable QR code for verification, 7 business days after you pass the exam. A business day refers to any day in which normal business operations are conducted (in our case Monday through Friday), excluding weekends and public holidays.

Cyber Risk GmbH will develop a dedicated web page for each professional (https://www.cyber-risk-gmbh.com/Your_Name.html). In your dedicated web page we will add your full name, all the certificates you have received from Cyber Risk GmbH, and the pictures of your certificates.

When third parties scan the QR code on your certificate, they will visit your dedicated web page, and they will be able to verify that you are a certified professional, and your certificates are valid and legitimate.

Professional certificates are some of the most frequently falsified documents. Employers and third parties need an easy, effective, and efficient way to check the authenticity of each certificate. QR code verification is a good response to this demand.

You can print your certificate that you will receive in Adobe Acrobat format. With the scannable QR code, all third parties can verify the authenticity of each certificate in a matter of seconds.



13. Why should I choose your training programs?

I. There are many new Directives and Regulations in the EU, and our target audience is overwhelmed and has little time to spare. Cyber Risk GmbH has developed training programs that can assist them in understanding the new requirements, and in providing evidence that they are qualified, as they must pass an exam to receive their certificate of completion.

II. Our training programs are flexible and convenient. Learners can access the course material and take the exam at any time and from any location. This is especially important for those with busy schedules.

III. The all-inclusive cost of our programs is very low. There is no additional cost for each program, now or in the future, for any reason.

IV. If you purchase a second program, you have a $100 discount. The all-inclusive cost for your second (and each additional) program is $197.

V. There are 3 exam attempts per year that are included in the cost of each program, so you do not have to spend money again if you fail.

VI. No recertification is required. Your certificates of completion never expire.

VII. The marketplace is clearly demanding qualified professionals in risk and compliance management. Certified professionals enjoy industry recognition and have more and better job opportunities.

VIII. Firms and organizations hire and promote fit and proper professionals who can provide evidence that they are qualified. Employers need assurance that managers and employees have the knowledge and skills needed to mitigate risks and accept responsibility. Supervisors and auditors ask for independent evidence that the process owners are qualified, and that the controls can operate as designed, because the persons responsible for these controls have the necessary knowledge and experience.

IX. Professionals that gain more skills and qualifications often become eligible for higher-paying roles. Investing in training can have a direct positive impact on a manager's or employee's earning potential.


Cyber Risk GmbH, some of our clients