News From the Wire

17:34:33 (UTC) 06-02-2026

PayBright adds VP of Operations and Director of Product

17:28:05 (UTC) 06-02-2026

New Personiv study reveals rise of the hybrid finance workforce

17:22:51 (UTC) 06-02-2026

NMI acquires Fee Navigator, adding AI-powered pricing intelligence to platform

17:16:11 (UTC) 06-02-2026

Velera appoints Brian Caldarelli as President

17:14:39 (UTC) 06-02-2026

Checkout.com enables stablecoin acceptance, partnering with Coinbase

17:04:34 (UTC) 06-02-2026

MANSA recognized in The Payments Power 50 2026

17:02:04 (UTC) 06-02-2026

Smartstream launches Smart Agents for back-office operations, proven across Tier 1 pilots

17:00:06 (UTC) 06-02-2026

ONEKEY releases 2026 IoT & OT Cybersecurity Report



News from the Wire

ONEKEY releases 2026 IoT & OT Cybersecurity Report

Tuesday, June 02, 2026 — 17:00:06 (UTC)

ONEKEY IoT & OT Cybersecurity Report: Following a Strong Response, the Survey for the 2026 Edition Is Now Open

Report Review 2025: Two-thirds of companies had not yet adequately prepared for the Cyber Resilience Act (CRA), even though the first CRA requirements will take effect in September 2026

Düsseldorf, June 2, 2026 — The Düsseldorf-based cybersecurity company ONEKEY has reported strong demand for its latest "IoT & OT Cybersecurity Report 2025." The report examines how well manufacturers of digital devices, machines, and systems are prepared for the EU’s Cyber Resilience Act (CRA). The CRA is the first EU regulation requiring manufacturers to comply with binding cybersecurity requirements throughout the entire product lifecycle and to systematically manage vulnerabilities.

A key finding of the IoT & OT Cybersecurity Report 2025 is that approximately two-thirds of companies are not yet adequately prepared for the CRA — despite the first provisions of the EU regulation for connected products taking effect later this year. It is estimated that hundreds of millions, potentially even billions, of digital products within the EU will be affected. The report is available to download here.

"The consistently high demand shows just how urgent this issue has become for affected manufacturers," said Jan Wendenburg, CEO of ONEKEY.

ONEKEY Strengthens Cyber Resilience: IoT & OT Cybersecurity Report 2026 and CRA Fast Start

To continue monitoring the current state of cybersecurity readiness, ONEKEY has launched a new survey focused on the Cyber Resilience Act. Companies in the target group, namely manufacturers of internet-connected digital products, can request the survey link by emailing info@onekey.com with “CRA Survey” in the subject line. Participants will receive early access to the latest findings.

In addition, ONEKEY now offers affected manufacturers a program called CRA Fast Start, designed to help companies review their products for Cyber Resilience Act compliance in a structured and efficient manner without lengthy preparation phases.

The package includes a CRA Readiness Assessment, as well as platform features for SBOM generation, vulnerability management, and firmware monitoring. This package helps companies efficiently implement CRA requirements and establish a sustainable compliance strategy.

First, ONEKEY analyzes a company’s current level of maturity regarding CRA requirements and identifies existing compliance gaps. An introductory workshop highlights the impact of the new regulation on the product portfolio. As part of a comprehensive review of existing processes, key areas such as software development and vulnerability management are evaluated. A gap analysis then identifies existing compliance gaps and highlights areas requiring action. Based on these findings, ONEKEY develops a practical roadmap to help companies efficiently and systematically implement CRA requirements.

The ONEKEY Product Cybersecurity & Compliance Platform enables organizations to continuously identify and monitor vulnerabilities and ensures ongoing transparency in the software supply chain through SBOM generation and vulnerability management. New vulnerabilities, affected libraries, and potential risks are identified and documented continuously. These features provide companies with ongoing transparency regarding the security status of their digital products and lay the foundation for long-term, sustainable compliance with CRA requirements.

Initial CRA Obligations Take Effect September 11, 2026

Starting September 11, 2026, the EU Cyber Resilience Act will require manufacturers to report actively exploited vulnerabilities and significant security incidents within strict timeframes while also meeting initial compliance obligations. By 2027, the full requirements will become mandatory, including comprehensive security and documentation obligations throughout the entire product lifecycle. Once the transition periods have expired, networked devices, machines, and systems may only be placed on the market if manufacturers can demonstrate continuous vulnerability management, documented security processes, and ongoing monitoring of their software and firmware components throughout the entire product lifecycle.

Companies that violate the Cyber Resilience Act risk fines of up to 15 million euros or 2.5 percent of their global annual turnover.

ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life.

Critical vulnerabilities and compliance violations in device firmware are automatically identified in binary code by AI-based technology in minutes – without source code, device, or network access. Proactively audit software supply chains with integrated Software Bills of Materials (SBOMs) generation. "Digital Cyber Twins" enable automated 24/7 post-release cybersecurity monitoring throughout the product lifecycle.

The patent-pending, integrated ONEKEY Compliance Wizard already covers the EU Cyber Resilience Act (CRA) and requirements according to IEC 62443-4-2, ETSI EN 303 645, UNECE R 155 and many others.

The Product Security Incident Response Team (PSIRT) is effectively supported by the integrated automatic prioritisation of vulnerabilities, significantly reducing the time to remediation.

Leading international companies in Asia, Europe and the Americas already benefit from the ONEKEY Product Cybersecurity & Compliance Platform (OCP) and ONEKEY Cybersecurity Experts.

Further information: ONEKEY GmbH, Sara Fortmann, email: sara.fortmann@onekey.com, Toulouser Allee 19A, 40211 Düsseldorf, Germany, web: onekey.com

Notice to readers: These are archived articles. Contact information, links and other details may be out of date. We regret any inconvenience.

Source: Company press release.

Categories: Reports and research

skyscraper ad