EU Cyber Resilience Act: Study Reveals Implementation Shortcomings in Industry
The reporting requirements of the EU Cyber Resilience Act (CRA) have been in effect since September 11, 2026, but many German industrial companies are not yet sufficiently prepared, either organizationally or technically

This is shown by the PwC Product Security Survey 2026, for which PwC Germany surveyed 100 companies with digital products.
Although 88% are familiar with the CRA in general terms and 85% are involved in product cybersecurity, 50% do not have an external reporting channel for security incidents, even though the CRA requires a publicly accessible reporting channel. 27% have no internal process for product-related security issues. Only 19% have a thorough understanding of the requirements, and 3% consider themselves fully compliant.
Technical fundamentals such as updatable products (94%), documented development processes (84%), and risk assessments (83%) are widespread. However, end-to-end product security engineering across the entire lifecycle is often lacking; for example, only 27% create SBOMs for the majority of their portfolio. Small and medium-sized enterprises (SMEs), in particular, lag behind larger companies in terms of CRA maturity.
Would you like to learn more about CRA?
A webinar on September 24 will provide information on all aspects of the EU Cyber Resilience Act.
Sign up now










