GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton
1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy Germany’s cybersecurity regulation strategy is primar - ily shaped by the “Cybersecurity Strategy for Ger - many 2021”, which sets the central policy framework through 2026. The strategy frames cybersecurity as a shared responsibility of the State, the private sec - tor and society, reflecting Germany’s highly digitalised economy and its exposure to cyber-risks. It responds to a persistently high threat level, with Germany regarded as a primary target for cyber-attacks. The strategy pursues three overarching objectives: • strengthening digital sovereignty; • improving the protection and resilience of critical infrastructure; and • enhancing the State’s and the economy’s ability to prevent, detect and respond to cyber-incidents. Cybersecurity is thus positioned as a resilience and security issue rather than a purely technical compli - ance matter. Core Components of the Strategy A key element is the strengthening of the Federal Office for Information Security (BSI) as Germany’s central cybersecurity authority. The BSI acts as the main co-ordinating body, develops security stand - ards, facilitates information-sharing and supports both public authorities and private companies in improving cyber-resilience. The strategy places strong emphasis on the protec - tion of critical infrastructure, particularly in sectors such as energy, healthcare and transport. Increasing the resilience of these sectors is considered essential to safeguarding public services and economic stabil - ity. In parallel, the strategy promotes secure digitali - sation, including the development and use of secure digital products and services, complemented by EU initiatives such as the Cyber Resilience Act (CRA). The National Cyber Defence Centre is further devel - oped as a co-operation and crisis response platform, enabling co-ordinated action by security authori -
ties during major cyber-incidents. The strategy also addresses the role of business and society, promot - ing minimum security standards, cybersecurity aware - ness, education and a broader security culture. Legislative Implementation and Scope Building on this strategic framework, Germany has recently enacted and proposed legislation that increas - ingly aligns national law with EU-level cybersecurity instruments, most notably through the implementation of NIS2 and related amendments to German IT securi - ty law. This legislative approach significantly broadens the scope of cybersecurity obligations beyond tradi - tional critical infrastructure to a wider range of sec - tors and organisations whose disruption could have economic or societal impact. Across sectors, the legislature frames cybersecu - rity regulation as a risk-based governance task. The focus is on organisational responsibility, management accountability, supply chain security and operational resilience, rather than prescriptive technical require - ments. This reflects a deliberate policy choice to cre - ate a scalable, cross-sector cybersecurity baseline capable of addressing systemic risks in an increas - ingly interconnected economy. 1.2 Cybersecurity Laws Germany’s cybersecurity framework in 2026 is a lay - ered national and EU regime. National law, centred on the role of the BSI, establishes baseline organisational duties, while EU instruments – in particular NIS2, the Digital Operational Resilience Act (DORA), the CRA and the AI Act – introduce harmonised, sector-specific and product-focused cybersecurity and risk manage - ment obligations. National Core Framework New BSI Act (BSIG) – implementation of NIS2 Subject matter The central national framework is built around the role of the BSI and organisation-focused cybersecu - rity duties (risk management, incident handling, and security governance requirements for in-scope enti - ties). The new Act on the Federal Office for Information Security and on Information Security in Institutions (BSIG) has been in force since 2 December 2025. It implements the EU NIS2 Directive into German law
141 CHAMBERS.COM
Powered by FlippingBook