Observed Signal · Sep 11, 2026 · Regulation · Source: Retail-News · Impact: 4/5 · Sentiment: Negative
Only 3 in 10 firms know Cyber Resilience Act obligations
The European Cyber Resilience Act (CRA) will impose new reporting obligations starting September 11, 2026. Manufacturers must report actively exploited vulnerabilities and serious security incidents within 24 hours, followed by additional details within 72 hours and a final report. However, a Bitkom survey of 1,003 German companies reveals that only 29% understand the CRA's implications for their business. While 67% have heard of the law, many lack detailed knowledge. The central reporting platform will only go live on the deadline, hindering preparation. Bitkom supports the CRA's security-by-design principles but emphasizes the need for practical implementation.
Major EU regulation impacting all digital product manufacturers, including adtech infrastructure, with strict reporting timelines and low industry readiness.
Track Bitkom Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Starting September 11, 2026, manufacturers must report actively exploited vulnerabilities and serious security incidents within 24 hours.
- Additional information must be provided within 72 hours, followed by a final report.
- A Bitkom survey of 1,003 German companies found that only 29% know what the CRA means for their business.
- 67% of companies have heard of the CRA, but 38% only know the name, and 28% do not know it at all.
- The central European reporting platform will only be available on the deadline, preventing prior registration or testing.
- In Germany, the Federal Office for Information Security (BSI) is the responsible authority.
Connected Companies & Entities
1 Entity mapped“According to a Bitkom survey of 1,003 companies......”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
German Industry Struggles with Cyber Resilience Act
A Retail-News article (29 Aug 2026) reports on the ONEKEY “IoT & OT Cybersecurity Report 2026”, finding many German companies are insufficiently prepared for the EU Cyber Resilience Act (CRA). The study shows significant gaps in awareness, with 45% of firms little or not familiar with CRA requirements, limited knowledge of the first reporting deadline (11 September 2026), and slow progress on risk management, documentation, SBOMs, security updates and 24-hour incident reporting. The report warns that AI-driven attacks and the complexity of software transparency increase urgency. Many companies aim for full compliance by December 2027 but need to accelerate implementation.
How OSPOs Are Preparing Organizations for the EU Cyber Resilience Act
For organizations offering products with digital elements in the EU, the next major Cyber Resilience Act (CRA) deadline arrives on 11 September 2026. From that date, organizations covered by the reporting obligations must be ready to...
AI won't absolve firms under EU Cyber Resilience Act
The article explains that the EU Cyber Resilience Act (CRA), in force since December 2024, imposes strong security and liability obligations on any product with digital elements placed on the EU market. Key CRA deadlines: vulnerability reporting to ENISA becomes mandatory in September 2026 and full compliance is required by December 2027. Obligations include shipping products without known exploitable vulnerabilities, providing security updates for a minimum five-year supported lifetime, CE marking for covered products, 24-hour reporting of actively exploited vulnerabilities to ENISA, and fines up to €15 million or 2.5% of global turnover. The author warns that AI-assisted code (Copilot, Claude, Cursor examples) carries the same legal weight as handwritten code and recommends inventories, 24-hour reporting pipelines, AI-code audits, documented vulnerability-handling processes, and SLA updates.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
