Only 3 in 10 German Companies Ready for Cyber Resilience Act Enforcement

As the Cyber Resilience Act takes effect on September 11, only 29% of German companies understand its implications, highlighting a significant compliance challenge.

    Key details

  • • The Cyber Resilience Act requires reporting exploited security vulnerabilities within 24 hours starting September 11, 2026.
  • • Only 29% of German companies understand the CRA’s impact on their operations, per Bitkom survey.
  • • A central reporting platform managed by Germany's BSI will launch on the enforcement date with no pre-registration.
  • • Bitkom highlights the CRA’s role in strengthening European cybersecurity standards but notes practical implementation challenges.

The Cyber Resilience Act (CRA) comes into force on September 11, 2026, requiring manufacturers to report exploited security vulnerabilities and serious security incidents involving software or connected devices within 24 hours, with further detailed reports due within 72 hours. Despite the law’s imminent start, a recent Bitkom survey reveals that only 29% of German companies fully understand how the CRA impacts their business operations. While 67% have heard of the law, 38% cannot assess its relevance, and 28% remain completely unaware.

Bitkom President Dr. Ralf Wintergerst emphasized the CRA’s importance in enhancing cybersecurity across Europe by establishing binding minimum requirements for digital products and promoting “Security by Design.” He acknowledged, however, that implementing these standards is a significant challenge for companies, which must be both willing and able to comply.

To facilitate compliance and secure information exchange, the Federal Office for Information Security (BSI) will manage a centralized European platform for reporting vulnerabilities and incidents, which will go live alongside the CRA enforcement date. Companies cannot pre-register or trial the system before then, adding another implementation hurdle.

This preparedness gap underlines the urgency for German companies to accelerate their understanding and readiness to comply with the CRA, which mandates rapid reporting of cybersecurity breaches to improve resilience and trust in digital products. The CRA aims to set a new standard for cybersecurity in Europe, but stakeholders face practical challenges ahead as the new reporting requirements become enforceable starting September 11, 2026.

This article was translated and synthesized from German sources, providing English-speaking readers with local perspectives.

Source comparison

The key details of this story are consistent across the source articles

The top news stories in Germany

Delivered straight to your inbox each morning.