Academy

TrustSource Training

Learn how to secure your software supply chain with TrustSource — from SCA and SBOM through vulnerability management to CRA and license compliance. Registration on the training platform is free and all curricula can be browsed upfront. Some courses are free, others are paid. To start a course you are redirected to the training platform.

Level
Topics

6 courses

Free

CRA Basics – What Manufacturers Need to Know Now

A concise introduction to the Cyber Resilience Act: what it means, who it affects, its four core obligations, and what the first step toward compliance looks like. No prior knowledge of EU product law required.

Beginner 55 min
cracompliancesecurityeacgbasics

Marcus Hale

Free

Coordinated Vulnerability Disclosure – Professional Playbook

The professional playbook for CVD: assess vulnerabilities with CVSS, EPSS and SSVC, navigate difficult situations, and build your own CVD process and bug-bounty policy. With real-world stories from Heartbleed and Log4Shell. Prerequisite: none. It helps to have already taken the free EACG starter course "CVD Basics" first — this course assumes a working understanding of the topic and builds on it.

Advanced 2 hr 5 min
securitycvdvulnerability-disclosurepsirtbug-bountycvssepssssvccsafeacg

Tess Calder & Marcus Hale

Free

Coordinated Vulnerability Disclosure – Basics

A compact introduction to Coordinated Vulnerability Disclosure: what CVD is, why it exists, which roles are involved, and what finders and vendors must concretely do. Relevant for everyone subject to the Cyber Resilience Act or NIS2.

Beginner 42 min
securitycvdvulnerability-disclosureeacgcranis2

Marcus Hale & Tess Calder

Free

Understand and Manage TrustSource Legal Settings

Learn how TrustSource resolves open-source license obligations and how to configure the Legal Questionnaire for your projects and modules. Covers the solver mechanics, all questionnaire fields, practical workflow, and common edge cases.

Intermediate
trustsourceopen-source-compliancelegallicensing

CGM

Free

Open Source Compliance – Basics

A foundation course on open source compliance: why it matters, the pillars of an open source program, change management, the OpenChain / ISO 5230 standard, open source boards and policies, and compliance tooling capabilities. Designed for developers, product owners, and anyone starting their compliance journey.

Beginner ~52 min
open-sourcecomplianceopenchainsbomgovernancetrustsource

Jan Thielscher

Free

Threat Modeling – From Concept to Countermeasure

A hands-on course on threat modeling: why it pays off, what it is, how the process works, which methods exist (with a focus on STRIDE), a fully worked practical example, and the transition into risk management. Note: This course is voiced by AI voices (AI narrated).

Intermediate
securitythreat-modelingstrideeacgAI narrated

Marcus Hale & Tess Calder