ONEKEY IoT & OT Cybersecurity Report 2026
Surge in Cyberattacks on Industry: Urgent Action Needed for Stronger Protection
Final Push Toward CRA Compliance: Industry Is on the Right Track, but Implementation Must Accelerate

“The Cyber Resilience Act puts an end to the notion that manufacturerscan simply pass on responsibility for insecure software components tosuppliers. Anyone who brings a product to the European market under their ownname bears responsibility for the cybersecurity of the entire product.” Jan Wendenburg, CEO of ONEKEY
Background on the Cyber Resilience Act
The CyberResilience Act applies to devices, machines, and systems with digitalcomponents, as well as software and other connected products. These include,among other things, connected machines and control systems, routers, firewalls,and network devices; IoT and smart home devices; operating systems; apps;industrial control software; and cloud functions—provided they are necessaryfor a product’s operation.
The CRAregulations will take full effect on December 11, 2027. As of that date, no newproducts with an internet connection may be sold in the 27 countries of theEuropean Union if they do not meet the requirements of the Cyber ResilienceAct. However, one key obligation has been in effect since September 11, 2026:Distributors of digital products must report actively exploited vulnerabilitiesand serious security incidents. With certain exceptions, this also applies toproducts already on the market.
Formanufacturers, distributors, and importers, the CRA means they mustcomprehensively protect their products against hacker attacks and demonstrateand document their security. Violations of fundamental cybersecurityrequirements or key manufacturer obligations are punishable by fines of up to15 million euros or 2.5% of global annual revenue, whichever is higher.

“The Cyber Resilience Act puts an end to the notion that manufacturerscan simply pass on responsibility for insecure software components tosuppliers. Anyone who brings a product to the European market under their ownname bears responsibility for the cybersecurity of the entire product.” Jan Wendenburg, CEO of ONEKEY
Background on the Cyber Resilience Act
The CyberResilience Act applies to devices, machines, and systems with digitalcomponents, as well as software and other connected products. These include,among other things, connected machines and control systems, routers, firewalls,and network devices; IoT and smart home devices; operating systems; apps;industrial control software; and cloud functions—provided they are necessaryfor a product’s operation.
The CRAregulations will take full effect on December 11, 2027. As of that date, no newproducts with an internet connection may be sold in the 27 countries of theEuropean Union if they do not meet the requirements of the Cyber ResilienceAct. However, one key obligation has been in effect since September 11, 2026:Distributors of digital products must report actively exploited vulnerabilitiesand serious security incidents. With certain exceptions, this also applies toproducts already on the market.
Formanufacturers, distributors, and importers, the CRA means they mustcomprehensively protect their products against hacker attacks and demonstrateand document their security. Violations of fundamental cybersecurityrequirements or key manufacturer obligations are punishable by fines of up to15 million euros or 2.5% of global annual revenue, whichever is higher.
“The Cyber Resilience Act puts an end to the notion that manufacturerscan simply pass on responsibility for insecure software components tosuppliers. Anyone who brings a product to the European market under their ownname bears responsibility for the cybersecurity of the entire product.” Jan Wendenburg, CEO of ONEKEY
Background on the Cyber Resilience Act
The CyberResilience Act applies to devices, machines, and systems with digitalcomponents, as well as software and other connected products. These include,among other things, connected machines and control systems, routers, firewalls,and network devices; IoT and smart home devices; operating systems; apps;industrial control software; and cloud functions—provided they are necessaryfor a product’s operation.
The CRAregulations will take full effect on December 11, 2027. As of that date, no newproducts with an internet connection may be sold in the 27 countries of theEuropean Union if they do not meet the requirements of the Cyber ResilienceAct. However, one key obligation has been in effect since September 11, 2026:Distributors of digital products must report actively exploited vulnerabilitiesand serious security incidents. With certain exceptions, this also applies toproducts already on the market.
Formanufacturers, distributors, and importers, the CRA means they mustcomprehensively protect their products against hacker attacks and demonstrateand document their security. Violations of fundamental cybersecurityrequirements or key manufacturer obligations are punishable by fines of up to15 million euros or 2.5% of global annual revenue, whichever is higher.

Ready to automate your Product Cybersecurity & Compliance?
Make cybersecurity and compliance efficient and effective with ONEKEY.