GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton
scope or primarily affected through contractual obli - gations imposed by regulated customers. Further ambiguities result from complex group and cross-border structures, especially where IT or secu - rity functions are centralised outside Germany, and from the application of size and materiality thresholds to fast-growing or platform-based business models. In practice, the BSI’s guidance and FAQs play a deci - sive role in resolving these questions, with supervisory interpretation tending towards a broad and inclusive approach to critical-infrastructure cybersecurity. 2.2 Critical Infrastructure Cybersecurity Requirements Germany’s baseline cybersecurity requirements for critical and essential entities are risk-based and prin - ciple-driven. Rather than mandating specific technical controls, the legal framework requires organisations to implement appropriate technical and organisational measures aligned with their risk profile, criticality and dependencies. In practice, supervisory focus lies on governance, incident readiness and demonstrable operational capability. Regulators and auditors place less emphasis on for - mal policies and more on whether organisations can prevent, detect, respond to and recover from cyber- incidents in a timely and structured manner. Docu - mentation, testing and evidence of effective imple - mentation are therefore central. Core expectations include clear governance and accountability at management level, auditable poli - cies and controls, and the use of recognised security frameworks to demonstrate state-of-the-art imple - mentation. Organisations must maintain visibility over critical assets and dependencies, perform continuous risk assessments and prioritise controls based on realistic threat scenarios. Supply chain security is a key focus. Critical suppliers and outsourced services – particularly cloud services – require enhanced governance, contractual security obligations and operational co-ordination, including incident-response alignment.
Entities are also expected to operate effective vulner - ability and patch management, supported by monitor - ing and detection capabilities. Where technical reme - diation is limited, compensating controls are required. Finally, incident response, business continuity and recovery are central pillars. Authorities expect realistic, tested response plans, robust back-up and recovery capabilities, and resilience planning that addresses systemic and prolonged disruptions. Overall, compli - ance is measured by operational resilience, not by the absence of incidents. 2.3 Incident Response and Notification Obligations Incident response and notification obligations in Ger - many follow a layered and parallel reporting model. The applicable requirements depend on the legal regime in scope, most notably the BSIG (NIS2 imple - mentation), sector-specific regimes such as DORA for financial entities, and the GDPR where personal data is affected. The overall legislative approach prioritises early situational awareness, followed by structured updates and post-incident transparency. Rather than relying on a single notification, the frame - work is designed around graduated reporting, allowing authorities to react early while receiving progressively more detailed information as the incident evolves. BSIG (NIS2 Implementation) Under the BSIG, incident notification obligations are triggered by a significant cybersecurity incident affect - ing an essential or important entity. Significance is assessed on a risk-based basis, taking into account factors such as the impact on service availability, integrity or confidentiality, the number of affected users, the duration of the incident and its geographi - cal spread. The threshold is deliberately broad and requires organisations to make an early classification even where technical facts are incomplete. The focus is on whether the incident has, or is likely to have, a material operational or societal impact. According to Section 37 BSIG (in conjunction with NIS2), signifi - cant security incidents must be reported to the BSI. The deadlines include an early warning (initial report) within 24 hours of becoming aware of the incident,
146 CHAMBERS.COM
Powered by FlippingBook