14.09.2026 • News

EU Cyber Resilience Act: Study Reveals Implementation Shortcomings in Industry

The reporting requirements of the EU Cyber Resilience Act (CRA) have been in effect since September 11, 2026, but many German industrial companies are not yet sufficiently prepared, either organizationally or technically

Photo

This is shown by the PwC Product Security Survey 2026, for which PwC Germany surveyed 100 companies with digital products.

Although 88% are familiar with the CRA in general terms and 85% are involved in product cybersecurity, 50% do not have an external reporting channel for security incidents, even though the CRA requires a publicly accessible reporting channel. 27% have no internal process for product-related security issues. Only 19% have a thorough understanding of the requirements, and 3% consider themselves fully compliant.

Technical fundamentals such as updatable products (94%), documented development processes (84%), and risk assessments (83%) are widespread. However, end-to-end product security engineering across the entire lifecycle is often lacking; for example, only 27% create SBOMs for the majority of their portfolio. Small and medium-sized enterprises (SMEs), in particular, lag behind larger companies in terms of CRA maturity.

The full study is available for download here.

Would you like to learn more about CRA?

A webinar on September 24 will provide information on all aspects of the EU Cyber Resilience Act.

Sign up now

Award

AutomationsBest Award

AutomationsBest Award

The AutomationsBest Award is now entering its 4rd round. The award will be presented at SPS - Smart Production Solutions in Nuremberg.

Digital Events

Digital Event Calendar 2026
live or on demand

Digital Event Calendar 2026

By participating in our free digital events, you can stay up to date in your field of expertise.

most read