< Back to all clusters
[TECHNOLOGY] · Germany · 2 sources

started · updated

EU Cyber Resilience Act forces German SMEs to fund security updates

The Cyber Resilience Act (CRA) entered into force in the EU in December 2024. While most obligations, including the separation of security and functional updates, become fully binding on 11 December 2027, reporting duties for actively exploited vulnerabilities and serious security incidents start on 11 September 2026. The regulation imposes a strict ban on bundling security patches with feature upgrades, requiring manufacturers to provide independent security updates for each supported software version.

German small and medium‑sized enterprises (SMEs) face particular challenges. The national implementation law offers only €1.28 million per year in state aid, far less than the funding earmarked for the related NIS2 directive. No size‑based exemptions exist; any company selling digital products in the EU must meet the CRA’s requirements, including risk‑based cybersecurity measures, vulnerability management, CE marking, lifecycle security, documentation, and personal liability for executives. As Ari Albertini, CEO of Ftapi, noted, “The new regulations force companies to think strategically about cybersecurity.” Experts advise SMEs to establish reporting processes, embed security‑by‑design, inventory supply‑chain components with a Software Bill of Materials, and consider the EU’s SECURE programme, which provides €16.5 million to support eligible firms.