German Industry Faces Challenges with Cyber Resilience Act Compliance
A recent survey reveals that only 46% of German companies are familiar with the Cyber Resilience Act's requirements. With the first obligations effective from September 11, 2026, a significant portion of the industry remains unprepared, including 30% of firms that have not started addressing compliance requirements.

The 'IoT & OT Cybersecurity Report 2026' indicates that only 46% of surveyed companies are aware of the Cyber Resilience Act (CRA), and merely 21% are very familiar with it. As the September 11, 2026 deadline approaches for initial obligations, 45% of firms are either unfamiliar or minimally aware of the Act.
Additionally, 60% lack knowledge of subsequent deadlines, with only a third aware of all phases leading to full compliance by December 11, 2027. Regarding preparedness, 25% of companies feel 'very well prepared' for risk management, while a third are unprepared in many areas, including internal processes and security updates.
Major challenges include reporting security incidents within 24 hours and assessing product compliance. The CEO of ONEKEY emphasizes the urgency for companies to enhance their CRA compliance efforts, particularly in light of increasing AI-driven cyber threats. The CRA Fast Start initiative aims to provide manufacturers with structured support to meet compliance requirements efficiently.




Comments