Cybersecurity 2026

GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton

Cybersecurity Obligations for In-Scope Entities Entities designated as essential or important are sub - ject to risk-based cybersecurity obligations rather than fixed technical prescriptions. These typically include: • implementing appropriate risk management meas - ures; • maintaining incident detection and response capa - bilities; and • complying with structured incident-reporting requirements, including the new three-stage report - ing regime under the BSIG. The focus is on organisational capability, governance and preparedness, rather than on compliance with specific technologies. Role of Authorities and Guidance The BSI is the competent authority responsible for supervising cybersecurity obligations for KRITIS. It issues guidance, technical recommendations and sector-specific information that play an important practical role in interpreting statutory duties. While such guidance is not always formally binding, it is widely treated as authoritative in supervisory prac - tice, audits and post-incident assessments. Recent BSI publications have focused in particular on sup - ply chain security, cloud dependencies and incident- handling processes. Scope Uncertainties and Practical Clarifications Despite the more systematic framework introduced by NIS2 and the revised BSIG, uncertainty around the scope of application remains a key practical issue. This particularly affects entities that do not fall within traditional critical infrastructure categories but play an enabling role in digital or industrial ecosystems. Uncertainty most commonly arises in relation to digi - tal services and managed service providers. While data centres and certain cloud or network services are explicitly covered, the classification of hybrid or specialised services – such as platform or Software as a Service (SaaS) providers – often requires a functional assessment rather than a simple sector-based test. Similar questions arise for managed service providers, where it is not always clear whether they are directly in

are no longer limited to a small group of operators but apply to a wider set of organisations whose disruption could have significant societal or economic effects. Designation Criteria and Categories of Entities Germany distinguishes between different categories of in-scope entities, largely following the NIS2 logic. The BSIG classifies organisations as “essential” or “important” entities based on their sector, function and relevance, rather than purely on ownership or public status. Designation criteria typically combine: • sectoral relevance; • functional importance for society or the economy; and • size or materiality thresholds, such as employee numbers or turnover. This results in a substantial expansion of scope, with many medium-sized companies now subject to formal cybersecurity obligations for the first time. Covered Sectors and Services The framework covers a broad range of sectors tradi - tionally associated with critical infrastructure, includ - ing: • energy; • healthcare; • transport; • finance; • water and food supply; and • information technology and telecommunications. In addition, the scope now explicitly extends to digital and technology-driven services, reflecting their sys - temic importance. This includes certain digital infra - structure providers, data centres, cloud services and operators that play a key role in enabling essential services. Managed service providers and other ICT service providers may fall within scope directly if they meet the relevant criteria, or indirectly through contractual and supervisory requirements imposed on their cus - tomers. This reflects a clear policy choice to address supply chain and dependency risks as part of critical infrastructure protection.

145 CHAMBERS.COM

Powered by