Cybersecurity 2026

GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton

and end-user information, particularly for telecom - munications providers and certain digital service pro - viders. The TTDSG therefore reinforces cybersecurity expectations in sectors where service availability and data confidentiality are critical. EU Cybersecurity and Digital Resilience Regulations CRA The CRA (EU Regulation 2024/2847) is the first EU regulation that sets minimum cybersecurity require - ments for all networked products available on the EU market. The CRA introduces horizontal cybersecu - rity requirements for products with digital elements, focusing on security-by-design, vulnerability handling and secure life cycle management. It applies to manu - facturers and other economic operators placing cov - ered products on the EU market, regardless of their place of establishment. Owing to its product-based approach, the CRA has strong extraterritorial effect and is particularly relevant for software vendors and industrial manufacturers operating in or supplying the EU market. The CRA came into force in December 2024, with the main requirements applying from the end of 2027. AI Act The AI Act (EU Regulation 2024/1689) establishes a risk-based regulatory framework for AI systems, including obligations relating to system securi - ty, robustness and risk management. While not a cybersecurity law in the narrow sense, it has signifi - cant cybersecurity relevance where AI systems are exposed to manipulation, misuse or operational fail - ure. The Act applies to providers and deployers of AI systems used or placed on the EU market, including those established outside the EU. In practice, it adds an additional security and governance layer for AI- based systems alongside NIS2, DORA and the CRA. GDPR The GDPR (EU Regulation 2016/679) constitutes an important horizontal pillar of cybersecurity law by imposing binding technical and organisational secu - rity requirements for the protection of personal data. In practice, many cyber-incidents involve personal data and therefore trigger parallel GDPR security and breach notification obligations. Owing to its broad

scope and extraterritorial reach, the GDPR plays a central role in shaping cybersecurity practices across sectors, particularly where data security and cyber- risk intersect. DORA DORA (EU Regulation 2022/2554) establishes a sec - tor-specific and highly prescriptive framework for ICT risk management in the financial sector. It covers gov - ernance, incident reporting, resilience testing and the management of ICT third-party risks. The regulation applies to a broad range of regulated financial entities and indirectly affects ICT service providers through contractual and supervisory requirements. DORA reflects the EU legislature’s approach of imposing deeper and more detailed cybersecurity obligations where systemic financial stability is at stake. Across all regimes, cybersecurity obligations are large - ly risk-based and technology-neutral in Germany. As a result, guidance, standards and codes of practice play a decisive practical role in shaping compliance expec - tations. They are particularly relevant in supervisory assessments and audits, in contractual cybersecurity baselining with customers and suppliers, and in post- incident reviews assessing whether security measures were adequate and reasonable. In practice, organisa - tions therefore often treat recognised standards and authority guidance as effectively binding, even where they are not formally mandated by law. 1.3 Cybersecurity Regulators Germany’s cybersecurity regulatory landscape is characterised by a multi-layered supervisory model, combining a central technical authority with sector- specific regulators and data protection authorities to ensure effective oversight, enforcement and co-ordi - nated incident response across the economy. BSI The BSI is the central cybersecurity authority in Germany. Its mandate covers the supervision and enforcement of the new BSIG, including the imple - mentation of NIS2, as well as the protection of critical infrastructure and the co-ordination of national cyber - security efforts.

143 CHAMBERS.COM

Powered by