More than half of German industrial companies have assigned dedicated staff to prepare for the European Union’s Cyber Resilience Act, as manufacturers of connected products face growing pressure to overhaul cybersecurity processes and product development.
A survey of 200 German industrial companies by cybersecurity company ONEKEY found that 20% had established a dedicated team to prepare for the regulation, while a further third had allocated at least some employees to the task.
The scale of the teams varies. Some 28% of respondents said they had assigned up to 10 people to CRA compliance, while 22% had larger teams. A further 16% were relying on no more than three specialists, while 19% had yet to allocate any staff.
The Cyber Resilience Act is designed to establish cybersecurity requirements for connected devices, machines and other products containing digital elements sold in the EU. Manufacturers, distributors and importers will need to demonstrate that products are protected against cyber threats, while also documenting security risks and maintaining vulnerability-management processes.
For companies with large portfolios of industrial IoT and operational technology products, the regulation could require significant changes to existing development and support processes.
“[The] Cyber Resilience Act is having a profound impact on manufacturers of products with digital components,” said Jan Wendenburg, Chief Executive of ONEKEY.
The European Commission estimates that the direct cost of implementing the legislation could reach €29bn. The market for affected hardware and software generates about €1.485tn in annual revenue, according to the Commission’s impact assessment.
According to the survey, half of respondents said their IT security department had primary responsibility for compliance, while 26% placed responsibility with product development. Compliance and legal departments accounted for 15% each.
At an individual level, product managers were the most commonly identified owners of CRA responsibilities, cited by 31% of companies, followed by cybersecurity analysts at 26% and compliance managers at 23 %. Heads of software development and chief information security officers accounted for 15% and 13% respectively.
More than a quarter of companies, 27%, said CRA compliance was important enough to be handled by senior management or the board.
Companies can face fines of up to €15m or 2.5% of global annual revenue, whichever is higher, for certain violations.
Despite the resources being committed, many companies expect they will need outside help. Some 61% have already budgeted, or are planning to budget, for the transition, while only 18% believe they can manage without external assistance.
The regulation is also expected to affect how quickly companies can bring new connected products to market. More than 60% of respondents expect the development of new or updated devices, machines and systems to take longer as a result of CRA requirements. Meanwhile 28%, expect development times to become “significantly longer”.
The CRA requires manufacturers to build cybersecurity into products “by design and by default”, conduct and document risk assessments, use secure default settings, manage vulnerabilities and provide security updates throughout the intended support period.
From December 11 2027, products within the scope of the regulation cannot be placed on the EU market unless they comply with the CRA.
The legislation includes transitional provisions for products already on the market, but these do not provide blanket protection for an entire product range. Significant changes to existing products can bring them within the scope of the new requirements.
