Cybersecurity 2026

GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton

National Cyber Defence and Response Structures Germany operates a National Cyber Defence Centre (Cyber-AZ), which serves as a co-operation and co- ordination platform for security authorities in serious cyber-incidents. While it does not act as a regulator itself, it enables information-sharing and joint situ - ational awareness among authorities responsible for cybersecurity, intelligence and law enforcement. CERT-Bund, operated by the BSI, functions as the central national cyber-incident response team, sup - porting public authorities and private operators with technical analysis, warnings and incident co-ordi - nation. In addition, sectoral or organisational CERTs operate in specific industries and typically liaise with the BSI during significant incidents. Overall, Germany’s cybersecurity enforcement model combines central technical co-ordination by the BSI with sector-specific supervision and data protec - tion oversight. The authorities’ approach focuses on risk-based supervision, organisational capability and incident readiness, supported by strong investiga - tive powers and co-ordinated response mechanisms. This multi-layered structure reflects the legislature’s view of cybersecurity as a cross-sector and systemic responsibility rather than a purely technical compli - ance issue. 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation Cybersecurity for critical and essential entities (KRI - TIS) in Germany is governed by a layered framework combining national law with EU requirements. At national level, the core pillars are the new BSIG, in force since December 2025, and the long-standing KRITIS framework for critical infrastructure. These regimes are now closely aligned with the EU’s NIS2 Directive, which significantly expands and reshapes the scope of regulated entities. The overall approach moves away from a narrow focus on traditional critical infrastructure towards a broader resilience model. Cybersecurity obligations

The BSI has extensive supervisory and investiga - tive powers, including the right to request informa - tion, conduct audits, review security concepts and incident-response measures, and issue binding orders to remedy deficiencies. Under the BSIG, it can also impose sanctions and, in certain cases, require co-operation from manufacturers or service provid - ers. The BSI operates Germany’s national Computer Emergency Response Team (CERT-Bund) and acts as the primary recipient and co-ordinator of cyber- incident notifications from in-scope entities. Sectoral Supervisory Authorities In regulated sectors, cybersecurity supervision is often exercised by sector-specific regulators, either independently or in co-ordination with the BSI. For example, in the financial sector, supervisory authori - ties such as the Federal Financial Supervisory Author - ity (BaFin) enforce cybersecurity and ICT risk manage - ment obligations under DORA, supported by binding technical standards and supervisory guidance. These authorities typically have powers to request information, conduct on-site inspections, require remediation measures and impose administrative sanctions. Sectoral incident response expectations are usually embedded in supervisory frameworks, with close co-ordination between regulators and the BSI where incidents have broader cybersecurity rel - evance. Data Protection Authorities Germany’s federal and state data protection authori - ties play an important role where cyber-incidents involve personal data. They enforce the GDPR and national data protection law, including security obli - gations and breach notification requirements. Their investigative tools include audits, information requests and corrective measures, and they may impose sig - nificant administrative fines. In practice, cybersecurity incidents frequently trigger parallel procedures before cybersecurity and data protection authorities, requiring co-ordinated incident management by affected organisations.

144 CHAMBERS.COM

Powered by