ONEKEY Study: Businesses Still Have Significant Ground to Cover on Cyber Resilience Act Readiness
AI-summarised brief · reviewed before publication
The Düsseldorf‑based cybersecurity firm ONEKEY released its IoT & OT Cybersecurity Report 2026, revealing that German industrial firms are largely unprepared for the EU Cyber Resilience Act (CRA). A survey of 200 companies showed 45 % are barely or completely unfamiliar with the regulation, even though the first CRA obligations begin on 11 September 2024, requiring manufacturers, importers and distributors to report exploited vulnerabilities and serious incidents. Only 46 % claim general familiarity and 21 % say they are very familiar; 43 % know the September deadline, while 60 % lack awareness of later phases ending 11 December 2027. ONEKEY CEO Jan Wendenburg warned that the rule applies to existing products and to firms that act as importers, such as those moving Asian‑made machines to directly subsidiaries.
💡 Why It Matters
- · The awareness gap leaves essential production lines vulnerable at a moment when EU law will force immediate disclosure of attacks, giving cyber‑criminals a broader window to strike.