Cybersecurity 2026

GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton

IT Security Act 2.0 (IT-SiG 2.0) The IT Security Act 2.0 strengthens Germany’s nation - al cybersecurity framework by expanding security obligations for operators of critical infrastructure and other particularly relevant entities. It reinforces the role of the BSI, introduces stricter security requirements for certain components and services, and enhances the State’s ability to respond to significant cyber-threats. While partly superseded by the NIS2 implementation, it remains relevant as a structural pillar of German IT security law. Critical and essential entities (KRITIS) regulation framework (critical infrastructure) The German KRITIS framework defines and governs the protection of critical infrastructure, meaning facili - ties, systems and services whose disruption would have significant consequences for public safety, eco - nomic stability or the functioning of society. KRITIS covers sectors such as energy, healthcare, transport, water, food supply, information technology and tel - ecommunications. Operators are classified as so-called “KRITIS enti - ties” based on sector-specific thresholds and func - tional relevance. Once in scope, they are subject to enhanced cybersecurity and resilience obligations, including the implementation of appropriate security measures and incident reporting. The KRITIS frame - work therefore operates as a risk-based identification mechanism, determining which operators are subject to heightened protection requirements. Even with the broader scope introduced by NIS2 and the new BSIG, the KRITIS regime remains practically relevant. It continues to serve as a reference point for elevated security expectations and supervisory atten - tion, particularly for operators whose failure could cause systemic disruption. KRITIS thus remains a cornerstone of Germany’s approach to safeguarding essential services against cyber-threats. Telecommunications and Telemedia Data Protection Act (TTDSG) The TTDSG complements the General Data Protec - tion Regulation (GDPR) in the context of electronic communications and digital services. It governs the confidentiality and security of communications data

and significantly strengthens Germany’s cybersecurity framework. The BSIG substantially expands the scope of cybersecurity regulation and introduces enhanced requirements for risk management, incident reporting and supervisory oversight. Who is in scope The BSIG extends cybersecurity obligations to a much broader range of organisations across additional sec - tors. Around 30,000 additional entities are brought into scope, classified as “essential” and “important” entities. This represents a fundamental shift from a narrow critical infrastructure focus to a broader, econ - omy-wide baseline. Key obligations In-scope entities must implement minimum cyber - security measures, including risk management con - cepts, back-up and recovery mechanisms, encryption and incident-handling processes. A new three-stage incident reporting regime replaces the previous noti - fication system and requires earlier and more struc - tured engagement with the authorities. Strengthened role of the BSI The BSIG significantly expands the supervisory and enforcement powers of the BSI, including broader audit rights and the ability, in certain cases, to require co-operation from manufacturers. The BSI also oper - ates a central online platform for information exchange with affected entities, reinforcing its role as Germany’s central cybersecurity authority. Public sector co-ordination For the federal administration, the BSIG establishes a central co-ordination function through a Federal CISO, strengthening cybersecurity governance within public institutions. Territorial reach and background The BSIG primarily applies to entities operating in Germany but has practical cross-border relevance for international groups with German operations. It is the national implementation of NIS2, adopted in Novem - ber 2025 and entering into force in December 2025 after a delayed legislative process, with the aim of raising the overall cybersecurity level across the EU.

142 CHAMBERS.COM

Powered by