Skip to main content
ENISA logo

The European Union Agency for Cybersecurity (ENISA) has published the results of a survey on how prepared small and medium-sized enterprises are for the Cyber Resilience Act. Released in June 2026, the report draws on 194 responses collected in February and March 2026 from companies in 31 countries and geographical groupings, including 25 EU Member States.

The Cyber Resilience Act enters into application in December 2027, introducing cybersecurity requirements for all products with digital elements placed on the EU market. Since SMEs make up the majority of manufacturers, distributors and importers of such products, their capacity to implement the regulation will shape its overall success.

A gap between awareness and capability

Two thirds of respondents (66%) had heard of the Cyber Resilience Act before taking the survey. Awareness alone, however, does not translate into readiness: only 13% reported a good or very good understanding of the documentation requirements, and 14% of conformity assessment procedures. More than half described their understanding of conformity assessment as limited or non-existent.

Awareness also varies sharply with company size - 94% among medium-sized companies, 74% among small ones and 62% among microcompanies.

Skills and training are the weakest link

The survey assessed maturity across five domains on a five-point scale, one of which covers awareness, competence and skills. The findings on training are stark: none of the microcompanies or small companies reported having formal, role-specific and documented training in place, and only 12% of medium-sized companies had reached that level. In practice, knowledge is shared informally, particularly in the smallest organisations.

The staffing picture reinforces this. While 93% of medium-sized companies have an internal staff member responsible for cybersecurity, 57% of microcompanies have no designated responsibility at all. The report notes that in many microcompanies the person expected to handle Cyber Resilience Act requirements is also responsible for development, customer management and daily operations.

Two practices explicitly required by the regulation are also the least adopted: threat modelling is used by 24% of respondents and software bills of materials by 35% - well below more familiar practices such as secure coding guidelines (43%) and code review (42%). ENISA concludes that closing this gap is less about explaining why these practices matter and more about showing how they can be applied in a small team.

What SMEs say they need

Respondents consistently prioritised practical, directly applicable support over general guidance:

  • templates for technical documentation (73%) and for documenting secure development practices (71%);
  • practical guidance, templates and checklists (69%);
  • step-by-step guidance for Cyber Resilience Act documentation (66%);
  • training sessions and webinars (60%);
  • sector-specific examples and use cases (56%).

Financial support was identified as a priority by 142 respondents, the highest figure for any single item. On distribution, the report notes that half of respondents belong to no industry association and that ENISA's own channels reach 37% directly, which means national authorities and industry associations need to be treated as active distribution partners rather than secondary audiences.

Why it matters for digital skills

The report is useful for anyone designing cybersecurity training, workforce strategies or SME support programmes. It identifies where the gap sits - not in awareness of the regulation, but in documentation practices, secure development capability and the absence of structured training in smaller organisations - and sets out the formats practitioners say they would actually use.

A note on the sample

Participation was voluntary and limited to professionally engaged respondents. ENISA states explicitly that the results should not be considered representative of the wider EU SME population, and that awareness and preparedness across the sector as a whole may be lower than the survey suggests.

Access

The report is available in English and can be downloaded free of charge from the ENISA website. It is published under a Creative Commons Attribution 4.0 licence.

Digital skills resource details

Target audience
Digital skills for the labour force.
Digital skills for ICT professionals and other digital experts.
Digital technology / specialisation
Digital skill level
Geographic scope - Country
Austria
Belgium
Bulgaria
Cyprus
Industry - field of education and training
Software and applications development and analysis
Target language
Bulgarian
Croatian
Czech
Danish
Dutch
English
Estonian
Finnish
French
German
Greek
Hungarian
Irish
Italian
Latvian
Lithuanian
Maltese
Polish
Portuguese
Romanian
Slovak
Slovenian
Spanish
Swedish
Geographical sphere
EU institutional initiative
Methodology

The report is based on a structured survey of SMEs conducted in February and March 2026, which received 194 responses from 31 countries and geographical groupings; 174 respondents fell within the scope of the Cyber Resilience Act. The sample covers microcompanies (1-9 employees), small companies (10-49) and medium-sized companies (50-249), following the European Commission definition. Alongside questions on awareness, understanding, current practices and anticipated challenges, the survey assessed maturity across five domains - governance and documentation; risk management and security by design; vulnerability and patch management; incident response and product life-cycle management; and awareness, competence and skills - using 17 questions scored on a five-point scale. Participation was voluntary, and ENISA notes that the results are not representative of the wider EU SME population.

Main document - File for download
Skills resource type
Report
0