Skip to content
DS Content

Magazine for digital signage and DOOH

Read and put in contextTechnologyCyber Resilience Act

Cyber Resilience Act: what 29 percent means for operators

Bitkom asked how well companies know the Cyber Resilience Act. For screen operators the figure matters less than who in their supply chain carries the reporting duty.

By , , 3 min read

Chain of display, player, management software and operator; a yellow sign with a question mark above the first three, a check mark above the operator
Grafik: Kapaso GmbH

What happened

The association Bitkom published survey figures on the Cyber Resilience Act (CRA) in a press release a day before the first reporting duties began. It surveyed 1,003 companies in Germany with at least ten employees and at least one million euros in annual turnover, by telephone, in calendar weeks 16 to 23 of 2026. 67 percent know the CRA by name, but only 29 percent know what it means for their own company. 38 percent cannot judge what it means for them, and 28 percent have never heard of it. The occasion is 11 September: from that day manufacturers must report actively exploited vulnerabilities and serious security incidents within 24 hours.

One detail concerns manufacturers' practice. Bitkom writes (our translation from the German):

“Even well-prepared companies cannot register on the reporting platform in advance and rehearse the reporting routes, because the platform only goes live on the deadline.”

What this means for screen operators

The figure is a snapshot, not a statement about digital signage. The companies asked come from across the economy, and smaller businesses are not included. The shares given also do not add up to one hundred percent; the release does not say what the remainder is. It shows only that knowledge is patchy. Whether that also holds for the makers of your players and displays, it does not say.

The duty falls on manufacturers, not automatically on you. The release speaks of manufacturers. Whoever operates screens usually is not one. Still, find out who in your chain is a manufacturer: of the display, the media player, the management software. Whoever offers a player under their own name may become one. The release says nothing on that, nor on importers, retailers or fines.

What you can check now:

  1. An inventory. Device, software, version, manufacturer, source. Without it no question can be asked.
  2. A written query to suppliers. Where do I report a flaw? How will I learn of a flaw reported to you? Until when will my version receive security updates?
  3. An internal route. Who in the house receives a supplier's warning and decides whether an update goes in at once or a device is taken off the network? A warning in a mailbox with no owner does not help.
  4. An update commitment in the contract. Within what period are security updates brought to your devices, and who starts them?

A cautious conclusion. If the reporting platform only went live on the deadline, even well-prepared manufacturers had no rehearsal. That is the editors' judgement, not a statement of the source: in the first weeks, suppliers' processes may not yet be settled. It argues against postponing the query until the next contract meeting.

This article is not legal advice.

This magazine is published by Kapaso GmbH, which develops software for such screens. The article describes general practice and refers to no product.

DS Content kompakt

The magazine’s newsletter: three articles and one practical tip, by email about every two weeks.

More on this topic