"The CRA establishes clear rules for cybersecurity across Europe for the first time. This is important to ensure that digital products become safer. However, if the rules are implemented too strictly, many companies could become overwhelmed," explains Dirk Binding, Head of Digital Economy at the German Chamber of Commerce and Industry (DIHK).
SMEs particularly affected – DIHK calls for proportionality
The DIHK welcomes the fact that European requirements are to be largely implemented into German law without additions. Especially considering that many companies currently have to meet requirements from multiple digital legislative acts simultaneously, limiting legal mandates to the bare essentials makes sense to avoid unnecessarily tying up further resources in companies through increased complexity.
"Many companies lack experts solely dedicated to such regulations. New obligations like increased reporting or documentation requirements can place a significant burden on them. Therefore, the rules must be implemented practically and in a way that companies can realistically follow in their day-to-day operations. Otherwise, many small and medium-sized enterprises will face serious challenges," says Dirk Binding.
In the introductory phase and for first-time violations, it is crucial to focus on implementation and orientation. "This is why we need clear assessments of whether measures are truly appropriate and consultations with affected businesses before penalties or interventions are imposed," urges Binding.
Support and guidelines urgently needed
The DIHK is calling for comprehensive information and support services, particularly for small and medium-sized enterprises. "Many companies are not even aware if the CRA applies to them. Some are even considering withdrawing products from the market due to the significant additional workload. This highlights that without good, timely information, things will become unnecessarily difficult for many. Clear explanations and sector-specific guidelines are essential – at the very latest, six months before the new rules come into force," states Dirk Binding.
Download
The DIHK provided a detailed statement on the implementation of the Cyber Resilience Act at the end of March:
DIHK's Statement on the Implementing Regulation CRA (only available in German) (PDF, 130 KB)
- Relevant in topic:
- Innovation and Digitalisation
- Key areas:
-
- Digitalisation
- Cybersecurity
- Economic Security
It has been translated with the assistance of AI.
No guarantee is made as to the accuracy or completeness of the translation.
Released 30.04.2026
Modified 01.09.2026
Contact
Sven Ehling
Spokesperson | Visual Communication