LatestMark Carney meets with ‘Forever Canadian’ campaigners in Banff

Canadian business, markets & economy · Saturday, 12 September 2026

Business

German firms lag on EU Cyber Resilience Act as reporting deadline kicks in

Only 29 % of German companies say they grasp the EU Cyber Resilience Act’s relevance, while 38 % cannot assess its impact, as the first mandatory reporting obligations start on 11 September 2026.

Bundesamt für Sicherheit in der Informationstechnik (BSI) headquarters in Bonn, Germany

29 % of German firms say they understand the EU Cyber Resilience Act’s significance for their business, while 38 % cannot assess its impact, as the first mandatory reporting deadline becomes active on 11 September 2026.1

Survey snapshot

The figures come from a representative Bitkom survey of 1,003 German companies that have at least ten employees and €1 million in turnover. The survey was reported by Heise on 12 September 2026.1

Bitkom Survey Awareness of the EU Cyber Resilience Act (Germany)
Awareness levelPercentage
Know significance for own business29 %
Heard of CRA but cannot assess impact38 %
Heard of CRA (overall)67 %
Completely unaware28 %
Source: Heise article quoting Bitkom survey

What the reporting deadline entails

The EU Cyber Resilience Act (CRA) obliges manufacturers of products with digital elements to report any actively exploited vulnerability or serious security incident within 24 hours of discovery.2 The deadline for this first‑time reporting started on 11 September 2026, meaning that from that day onward manufacturers must submit an early‑warning notice for each qualifying event.2

The Act applies to a wide range of connected products – from routers and industrial control systems to standalone software – and will affect all new devices placed on the EU market after 11 December 2027. However, the reporting obligation is already in force for existing products as soon as a vulnerability is actively exploited.2

For German manufacturers, the low awareness rates signal a potential compliance gap. With only 29 % confident they understand the regulation, many firms may still be configuring internal processes, incident‑response teams and reporting channels to meet the 24‑hour rule.1

Non‑compliance could trigger enforcement actions by national authorities, including fines or market‑access restrictions. The Federal Office for Information Security (BSI) – headquartered in Bonn and employing roughly 1,100 staff – is tasked with overseeing the CRA’s implementation in Germany.3 While the packet does not provide figures on current compliance levels, the survey’s 38 % who have heard of the Act but cannot assess its impact are the most likely group to face reporting challenges in the short term.

From a market perspective, firms that achieve early compliance may gain a competitive edge by demonstrating stronger cyber‑risk management to customers and partners. Conversely, firms lagging behind could see reputational damage if a breach is reported late or not at all.

What remains unknown

  • The survey does not break down awareness by sector, size or region, so it is unclear which industries are most at risk.
  • There is no data on how many manufacturers have already put 24‑hour reporting procedures in place.
  • Future enforcement metrics – such as the number of breach notifications filed in the first quarter after the deadline – have not been published.

Bitkom has not released a follow‑up study, and the CRA’s own monitoring reports are expected later in the year. Until those figures appear, the 29 %/38 % split provides the clearest snapshot of German firms’ readiness on the day the reporting clock started.

Stakeholders are advised to review internal vulnerability‑management workflows immediately and to engage with the BSI for guidance on the new reporting obligations.

About the author

Lucas Bennett

Reporting for CityAM Canada on business and the wider Canadian economy.

All work by Lucas Bennett ›