Press Releases
>
ONEKEY Study: Businesses Still Have Significant Ground to Cover on Cyber Resilience Act Readiness

ONEKEY Study: Businesses Still Have Significant Ground to Cover on Cyber Resilience Act Readiness

ONEKEY Study: Businesses Still Have Significant Ground to Cover on Cyber Resilience Act Readiness
Tanja Sommer
Tanja Sommer
TablE of contents

READY TO UPGRADE YOUR RISK MANAGEMENT?

Make cybersecurity and compliance efficient and effective with ONEKEY.

See it in Action
  • CEO Jan Wendenburg: “German industry is on the right track when it comes to the Cyber Resilience Act, but implementation should be significantly accelerated.”
  • “AI-driven cyberattacks will increasingly target industrial machines and systems.”
  • Far fewer than half of companies are focused on the September 11, 2026 deadline.

Düsseldorf, 25 August 2026 – According to an alarming finding in the new “IoT & OT Cybersecurity Report 2026” presented by the Düsseldorf-based cybersecurity company ONEKEY, the German business community is neglecting the Cyber Resilience Act (CRA). The report is based on a survey of 200 German industrial companies regarding their strategies for implementing the EU’s latest cybersecurity regulation relating to operational technology (OT). OT is used to control physical systems and processes, as well as connected devices that exchange data over the internet (the Internet of Things, or IoT). The report is available here: https://www.onekey.com/resource/onekey-iot-ot-cybersecurity-report-2026

A significant proportion — 45 per cent — stated that they were either barely familiar with or completely unfamiliar with the requirements. This is noteworthy because the first CRA obligations will take effect on 11 September this year. From this date onwards, manufacturers, importers and distributors of connected devices, machines and systems will be required to report any actively exploited vulnerabilities in their products, as well as any related serious security incidents.

ONEKEY CEO Jan Wendenburg clarified: “With a few exceptions, this also applies to all products already on the market, not just new developments as is often mistakenly assumed.” The 'IoT & OT Cybersecurity Report 2026' provides the following examples:

  • Connected machines and control systems
  • Routers, firewalls, and network devices
  • IoT and smart home devices
  • Operating systems, apps, and other software
  • Industrial control software
  • Cloud functions, if necessary for product operation

According to the new ONEKEY report, industrial companies that view themselves solely as users may still be affected and fall under the Cyber Resilience Act. For example: A company that buys connected machines solely for its own production, but imports them directly from Asia, may be considered an importer under the CRA if it transfers the machines to a subsidiary or sister company.

Only One-third Are Familiar With The Deadlines

Nevertheless, 46 per cent of the companies surveyed said they were familiar with the Cyber Resilience Act, and 21 per cent said they were very familiar with it. The survey also found that 43 percent are aware that the first phase of CRA requirements will take effect in September. However, 60 per cent admit that they are not familiar with subsequent phases and deadlines of the EU security regulation. 'In fact, there are three additional CRA implementation deadlines in the EU before the Cyber Resilience Act takes full effect on 11 December 2027,' said ONEKEY CEO Jan Wendenburg. According to the report, however, only one-third of the companies surveyed are aware of these deadlines.

Slow Implementation of the CRA

According to the 'IoT & OT Cybersecurity Report 2026', the implementation of the Cyber Resilience Act (CRA) in the business sector is proceeding at a correspondingly slow pace. As part of the survey, ONEKEY sought to determine how well-prepared companies are regarding the CRA.

The survey found that 25 percent of respondents described themselves as 'very well prepared' in terms of risk management, 22 percent in terms of security requirements, 20 percent in terms of documentation and the security updates required by the CRA throughout the entire product lifecycle, and 17 percent in terms of internal processes and technical evidence. Meanwhile, 39 per cent have addressed technical evidence but have only partially implemented it, while 37 per cent have done the same for documentation, 34 per cent for internal processes and security updates, and 26 per cent for risk management.

Conversely, according to the report, approximately one-third of companies are not yet prepared for the Cyber Resilience Act in terms of their internal processes, risk management or security update management. Thirty percent have barely begun to address the security requirements that the EU will soon make mandatory, nor have they initiated the technical verification process.

ONEKEY CEO Jan Wendenburg summed up the situation: “The results show a wide range: A small proportion considers itself very well prepared; many companies are in the midst of implementation; and about one-third has barely begun.”

The Biggest Challenges

One of the key questions in the ONEKEY survey was: What are the biggest challenges that businesses face when trying to comply with the requirements of the Cyber Resilience Act? The 'IoT & OT Cybersecurity Report 2026' provides the answers. According to 62 percent of the companies surveyed, the greatest difficulty stems from the requirement to report security incidents within 24 hours, which takes effect on 11 September this year. Thirty percent stated that this aspect is causing them serious problems. For 30 per cent of companies, assessing compliance with the EU directive — that is, determining whether their product portfolio complies with the Cyber Resilience Act, or if there is still work to be done — proves extremely problematic. Similarly, creating software bills of materials (SBOMs) is the main hurdle for just as many companies, with at least 60 percent of those surveyed having not yet resolved this issue.

“Having a complete overview of all the software used in a company’s own products is fundamental to CRA compliance,” said Jan Wendenburg, emphasizing this point. He elaborated: ‘If you don’t have a complete understanding of your software, you won’t know what security vulnerabilities might exist within it.’ In fact, vulnerability management — that is, identifying and addressing vulnerabilities in software — remains an unresolved problem for 62 per cent of companies. For nearly a quarter of firms, it is one of the biggest challenges on the path to CRA compliance.

Two-thirds of the companies surveyed are struggling with the 'Security by Design/Security by Default' approach required by law, with 24 per cent considering it a critical factor. This means that cybersecurity must be integrated into a product's development from the outset, and the product must be shipped with secure default settings. Nearly a quarter of companies view security throughout the entire product lifecycle as a serious problem, while another 40 per cent see it as a surmountable hurdle. According to the report, only around 15 percent do not view any of these aspects as a challenge, possibly because they have not yet examined them in detail.

One-fifth Will Be CRA-compliant by 2027

Despite the many challenges involved, one-third of companies are aiming to achieve full compliance with the EU regulation by 11 December next year, when the Cyber Resilience Act comes into full effect. From that date onwards, all newly placed devices, machines and systems containing digital elements must fully comply with the CRA's cybersecurity requirements. More than a quarter (26 per cent) are aiming to achieve this by the end of this year, while eight per cent believe they are already compliant. Currently, 13 percent of companies fear that they will not have adapted their product range in time for the Cyber Resilience Act to take full effect on 11 December 2027.

“The Pace of Implementation Would Need to Be Significantly Accelerated.”

Jan Wendenburg concluded: “While the German industry is moving in the right direction with their approach to the Cyber Resilience Act, the implementation process should be significantly accelerated.” This is not only true in light of the approaching regulatory deadlines. The threat landscape is intensifying due to increasingly automated and AI-powered cyberattacks. Recent incidents at OpenAI and Anthropic demonstrate just how real this risk has become. During security tests, AI models escaped the test environments and attacked real external systems. “These incidents make it clear that powerful AI agents are already capable of independently executing multi-stage attack chains and exploiting vulnerabilities,” said Jan Wendenburg. According to the CEO of ONEKEY, in the future, not only will data centres and traditional IT systems be at risk, but networked machines, production facilities and industrial control systems will be too. A successful attack could result in data theft, production outages, process manipulation and, in the worst case, physical damage.

“Companies should not view the implementation of the CRA as a mere compliance task, but rather as an important component of their operational risk management,” explained Jan Wendenburg.

CRA Fast Start for a Structured Approach

ONEKEY's “CRA Fast Start” program enables manufacturers of connected devices, machines and systems to assess their products for CRA compliance in a structured manner, eliminating lead times. The concept is based on three pillars: CRA Readiness Assessment; systematic vulnerability management; and continuous monitoring. The first step is to analyze a company’s current level of readiness regarding CRA requirements. Moving forward, continuous vulnerability management and ongoing monitoring ensure that vulnerabilities are identified, transparency is created for software supply chains, and sustained compliance with CRA requirements is guaranteed. This supports not only compliance with CRA obligations, but also internal governance and risk management processes. ONEKEY has explained the approach and scope of the program in this regard.

“With CRA Fast Start, we enable manufacturers to quickly and systematically start working towards achieving the CRA compliance required by law,” said Jan Wendenburg, ONEKEY's CEO, when explaining the offering.

Share

About Onekey

ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life.

CONTACT:
Sara Fortmann

Senior Marketing Manager
sara.fortmann@onekey.com

euromarcom public relations GmbH
team@euromarcom.de

Make cybersecurity and compliance efficient and effective with ONEKEY.