Düsseldorf — One-fifth of companies in Germany have set up an internal team to adapt their product portfolios to the requirements of the EU Cyber Resilience Act (CRA). Another third has assigned at least some of their employees to this task. These findings come from the latest ‘IoT & OT Cybersecurity Report 2026’ by the Düsseldorf-based cybersecurity company ONEKEY. The report is based on a survey of 200 German industrial companies regarding the CRA. Essentially, the EU regulation stipulates that all manufacturers, distributors, and importers of connected devices, machines, and systems with digital components connected to the Internet must comprehensively protect their products against cyberattacks and be able to demonstrate and document their security.
For companies with a broad portfolio of OT (operational technology) and IoT (Internet of Things) products, this is no easy task. According to the survey by ONEKEY, 28% of companies have assigned a team of up to ten people to the task. 22 % are working with an even larger team to prepare for and implement the Cyber Resilience Act. 16% manage with a maximum of three specialists, and nearly one-fifth (19%) have not assigned anyone to the task.
Jan Wendenburg, the CEO of ONEKEY, said, “The Cyber Resilience Act is having a profound impact on manufacturers of products with digital components.” He referenced the European Commission’s impact assessment, which states that the affected European hardware and software market generates approximately €1.485 trillion in annual revenue. In total, billions of devices in Europe are likely to be affected. The Commission estimates the direct cost of implementing the CRA to be up to €29 billion.*
CRA Responsibilities Are Distributed Across a Wide Range of Functions
According to the “IoT & OT Cybersecurity Report 2026,” most companies are unable to manage the CRA transition using their own staff and in-house resources. 61% of companies have set aside a budget for this transition or are planning to do so. However, only 18 % believe, based on their own assessments, that they do not need external assistance.
According to the ONEKEY Report, responsibility for CRA compliance is shared across different departments within companies. Half of the companies have assigned this responsibility to their IT security department. In more than a quarter (26%) of companies, this responsibility falls to the product development department. 15% each place it under the compliance and legal departments, respectively.
The range of responsibilities is similarly broad when broken down by leadership positions: The five most common positions are product manager (31%), cybersecurity analyst (26%), compliance manager (23%), head of software development (15%), and chief information security officer (13%).
CRA Compliance Should Be a Top Priority
Notably, more than a quarter of all companies (27%) consider strict compliance with the Cyber Resilience Act important enough for it to be handled by top management, i.e., the board or executive management. “Considering that violations of basic cybersecurity requirements or key manufacturer obligations can result in fines of up to €15 million or 2.5 percent of global annual revenue, whichever is higher, companies would be well advised to make CRA compliance a top priority,” says ONEKEY CEO Jan Wendenburg.
Significant Implications for Product Development and Market Launch
Depending on the industry, the Cyber Resilience Act can profoundly impact product development and market launch. Specifically, the CRA requires that cybersecurity be firmly embedded in devices “by design and by default,” that risk assessments be documented, that default settings be secure, that vulnerability management be effective, and that security updates be provided throughout the entire intended support period. From December 11, 2027, no devices, machines, or systems with digital components can be sold in EU countries unless they comply with the CRA. While there is temporary grandfathering for existing products, the CRA still applies if significant changes are made. Crucially, this grandfathering applies only to individual product units already placed on the market, not across an entire product series or models.
According to the “IoT & OT Cybersecurity Report 2026,” more than 60% of surveyed companies expect development of new or updated devices, machines, and systems to take longer. 28% expect development times to be “significantly longer.” Meanwhile 21% are still unsure, and 17% do not anticipate any changes.
CRA Fast Start Supports Internal Teams
For companies that have already assigned their own employees or teams to handle CRA implementation, external expertise can simplify and accelerate the process. ONEKEY’s “CRA Fast Start” program enables manufacturers of connected devices, machines, and systems to verify their products’ CRA compliance in a structured manner eliminating lead times. As part of a CRA Readiness Assessment, experts collaborate with relevant teams to review product requirements, existing vulnerability response processes, SBOM documentation, and organizational responsibilities. Based on this review, they identify compliance gaps and prioritize specific action steps. Systematic vulnerability management and continuous monitoring subsequently help uncover vulnerabilities, create transparency across the software supply chain, and detect new security vulnerabilities early on. In this way, CRA Fast Start combines the expertise of ONEKEY’s consultants with the automated analysis capabilities of its platform, helping internal teams maintain compliance with CRA requirements.
