Summary
- One in five surveyed German companies said they had created a dedicated internal CRA team.
- Another third had assigned employees to implementation, while 61% had allocated or planned budget.
- The figures come from a vendor-sponsored survey of 200 German industrial companies and should be read as an implementation indicator rather than a market census.
German manufacturers are putting dedicated people and budget behind the European Union’s Cyber Resilience Act, according to new industry research released as the regulation begins to move from preparation into operational reporting.
A survey published by ONEKEY found that one fifth of 200 German industrial companies had created a dedicated internal team to adapt products to CRA requirements. A further third said they had assigned employees to the work, while 61% had allocated or planned spending for implementation.
The survey is vendor-sponsored research from a company that sells product-security and compliance technology, so its findings should not be treated as an independent census of German industry. They nevertheless provide a useful view of how manufacturers are beginning to organise around obligations that reach well beyond conventional IT security.
The Cyber Resilience Act applies to a broad range of products with digital elements sold in the EU and places security obligations on manufacturers throughout the product lifecycle. Those requirements include vulnerability handling, secure development, security updates, technical documentation, and reporting.
Cyber Insider has already covered how the EU’s CRA reporting platform is entering its operational phase. The German data points to the organisational work sitting behind that regulatory mechanism.
Product security is difficult to allocate to a single department. Engineering teams understand the underlying software and firmware. Security teams may own vulnerability management. Legal and compliance functions interpret regulatory obligations. Procurement teams depend on component and software suppliers, while product managers determine release and support cycles.
That structure helps explain the emergence of dedicated CRA teams. The regulation does not simply ask a company to document a security policy; it can require manufacturers to change how vulnerabilities are identified, assessed, communicated, and fixed across products that may remain in the field for years.
For industrial companies, those products may also include machinery, connected equipment, control systems, gateways, or embedded devices that were designed long before the CRA existed. Retrofitting vulnerability processes and software inventories into established product lines can be considerably more difficult than applying them to newly developed software.
The survey found that more than 60% of respondents were also using external support. That may reflect a short-term implementation surge, but it points to another challenge: organisations need to retain enough internal ownership to make compliance sustainable after consultants and project teams leave.
The CRA’s reporting obligations increase that pressure because they introduce time-sensitive operational decisions. Manufacturers need to determine whether an incident or vulnerability falls within the reporting thresholds, obtain enough technical information to describe it accurately, and coordinate that process with remediation and customer communication.
Budget allocation is therefore only one measure of readiness. A manufacturer can fund compliance activity while still lacking complete software bills of materials, mature vulnerability disclosure processes, clear product ownership, or contractual leverage over suppliers whose components sit inside its products.
ONEKEY’s survey also found a minority of companies had not assigned personnel to CRA work. That gap will become harder to sustain as implementation moves away from future regulatory planning and into processes that have to function during actual vulnerability and incident events.
The German figures suggest the regulation is already changing organisational structures before its full application date. The next measure of maturity will be whether those teams can move from project-based preparation to routine product-security operations across engineering, support, suppliers, and compliance.





