started · updated
EU Cyber Resilience Act imposes new reporting duties on 29,500 German firms from September 2026
The EU Cyber Resilience Act (CRA) will take effect on 11 September 2026, introducing mandatory incident‑reporting for manufacturers and other operators. Companies must notify exploited vulnerabilities and serious security incidents to ENISA and the national CSIRT within 24 hours and submit a detailed analysis within 72 hours. Around 29,500 German enterprises fall within the scope, yet only about 11,500 have registered with the BSI so far.
For machine‑tool OEMs, the act adds specific timelines: full CRA compliance, including a CE mark that meets the new security standards, is required by 11 December 2027. Manufacturers must provide security updates for the entire expected service life of their products, which can exceed a decade. Non‑compliance can lead to fines of up to €15 million or 2.5 % of worldwide annual turnover, and machines lacking a CRA‑compliant CE mark will lose EU market access. The regulation also threatens retrofit revenue streams and places additional strain on engineering resources, as firms must manage multiple software versions and prioritize patch deployment throughout a product’s lifecycle.