Skip to main content

Half of German Firms Build Dedicated Teams for EU Cyber Resilience Act

Düsseldorf – September 12, 2026 -- More than half of German industrial companies have assigned internal teams to prepare their connected products for the EU Cyber Resilience Act (CRA), while over 60 percent are also turning to external specialists, according to the new "IoT & OT Cybersecurity Report 2026" from Düsseldorf-based cybersecurity firm ONEKEY. The findings are based on a survey of 200 German industrial companies regarding CRA readiness.

One-fifth of firms have launched full internal CRA teams

Twenty percent of surveyed companies have set up a dedicated internal team to adapt their product range to CRA requirements, while another third have partially assigned staff to the task. Team size varies sharply: 28 percent have assembled groups of up to ten people, and 22 percent have staffed even larger teams. Sixteen percent manage with three or fewer specialists, and 19 percent have assigned no one at all to the issue.

Market impact reaches €1.485 trillion, with compliance costs up to €29 billion

ONEKEY CEO Jan Wendenburg cited the European Commission's impact assessment, which estimates the affected European hardware and software market generates roughly €1.485 trillion in annual revenue, with billions of devices across Europe subject to the regulation. The Commission puts direct CRA implementation costs at up to €29 billion.

Sixty-one percent of firms plan to rely on external compliance support

Most companies cannot manage CRA transition with in-house resources alone: 61 percent have either reserved budget for external help or are planning to do so, while only 18 percent believe they can proceed without outside assistance.

CRA responsibility splits unevenly across departments

Half of the companies have assigned CRA compliance to their IT security department, more than a quarter (26 percent) to product development, and 15 percent each to compliance or legal departments. At the leadership level, product managers (31 percent), cybersecurity analysts (26 percent), compliance managers (23 percent), heads of software development (15 percent) and Chief Information Security Officers (13 percent) most often carry responsibility.

More than a quarter escalate CRA compliance to board level

In 27 percent of companies, CRA compliance has become a matter for the executive board or management directly. Wendenburg noted that violations of core cybersecurity requirements or manufacturer obligations under the CRA can trigger fines of up to €15 million or 2.5 percent of global annual revenue, whichever is higher.

Deadline set for December 11 next year, with no blanket grandfathering

The CRA requires cybersecurity "by design and by default," documented risk assessments, secure default settings, vulnerability management and security updates throughout a product's support period. From December 11 next year, no digital devices, machines or systems may enter the EU market without CRA compliance. Existing products retain limited grandfathering, but this protection applies only to units already delivered — not to an entire product line or model — and any substantial modification triggers full compliance obligations.

Over 60 percent expect longer product development timelines

More than 60 percent of surveyed companies anticipate increased development time for new or updated devices, machines and systems, with 28 percent expecting "significantly longer" timelines. Twenty-one percent remain uncertain about the impact, while 17 percent expect no change.

Published by
fairsonline_team
Company
Products
News Type