According to an alarming finding in the new “IoT & OT Cybersecurity Report 2026” presented by the Düsseldorf-based cybersecurity company ONEKEY, the German business community is neglecting the Cyber Resilience Act (CRA). The report is based on a survey of 200 German industrial companies regarding their strategies for implementing the EU’s latest cybersecurity regulation relating to operational technology (OT). OT is used to control physical systems and processes, as well as connected devices that exchange data over the internet (the Internet of Things, or IoT). A significant proportion — 45 per cent — stated that they were either barely familiar with or completely unfamiliar with the requirements. This is noteworthy because the first CRA obligations will take effect on 11 September this year. From this date onwards, manufacturers, importers and distributors of connected devices, machines and systems will be required to report any actively exploited vulnerabilities in their products, as well as any related serious security incidents. ONEKEY CEO Jan Wendenburg clarified: “With a few exceptions, this also applies to all products already on the market, not just new developments as is often mistakenly assumed.” The ‘IoT & OT Cybersecurity Report 2026’ provides the following examples: - Connected machines and control systems - Routers, firewalls, and network devices - IoT and smart home devices - Operating systems, apps, and other software - Industrial control software - Cloud functions, if necessary for product operation According to the new ONEKEY report, industrial companies that view themselves solely as users may still be affected and fall under the Cyber Resilience Act. For example: A company that buys connected machines solely for its own production, but imports them directly from Asia, may be considered an importer under the CRA if it transfers the machines to a subsidiary or sister company. Only One-third Are Familiar