Cybersecurity 2026

GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton

At cross-sector level, cyber-resilience is primarily driven by the German implementation of the NIS2 Directive through the new BSIG. This regime targets organisations classified as essential or important enti - ties and emphasises governance, risk management, incident handling and continuity. It does not impose direct security-by-design requirements for individual products, but it indirectly raises security expectations for the systems and services used in critical opera - tions. Product-focused cyber-resilience is addressed by the CRA, which introduces binding, horizontal secu - rity-by-design and security-by-default requirements for products with digital elements placed on the EU market. The CRA clearly covers connected devices, embedded software and standalone software prod - ucts, regardless of where the manufacturer is estab - lished. Its main obligations will apply from 2027 and have a strong extraterritorial effect. Purely digital services, including SaaS, are generally not treated as products under the CRA where no soft - ware is placed on the market. They are instead primar - ily regulated through organisational regimes such as NIS2/new BSIG or sector-specific frameworks such as DORA in the financial sector. Overall, cyber-resilience in Germany is regulated across the full life cycle, with product design, service delivery and organisational governance addressed through complementary but distinct legal regimes. 4.2 Key Obligations Under Legislation In Germany, binding cyber-resilience obligations at product level are primarily set by the EU’s CRA, which applies directly and is enforced through the EU market surveillance system. Unlike organisational cybersecu - rity regimes, the CRA establishes security-by-design and life cycle obligations for products with digital ele - ments placed on the EU market. The focus is on pre - venting vulnerabilities, managing risks over time and ensuring accountability after market entry. Vulnerability Handling, Patching and Updates Manufacturers must implement structured vulnerabil - ity-handling processes covering detection, assess - ment, remediation and communication. Security updates must be provided throughout the defined

support period, which generally must reflect the prod - uct’s expected lifetime. Updates must be made avail - able in a way that allows users to install them effec - tively, ensuring that vulnerabilities can be mitigated in practice rather than only in theory. Post-Market Surveillance and Corrective Measures Cyber-resilience obligations continue after a product is placed on the market. Manufacturers must active - ly monitor products for vulnerabilities and incidents and take corrective action where non-compliance is identified. Depending on severity, this may range from issuing security updates to withdrawing or recalling products if risks cannot be adequately mitigated. Conformity Assessment, Marking and Certifications Before market placement, manufacturers must per - form a conformity assessment, prepare technical documentation and issue an EU declaration of con - formity. Compliant products must bear CE marking. For certain higher-risk product categories, conformity assessment may involve more stringent procedures, including third-party assessment, affecting develop - ment timelines and market access. Enforcement and Penalties Enforcement is carried out by market surveillance authorities – in Germany, primarily the BSI. Authorities may request information, order remediation, restrict market availability or require recalls. Administrative fines can reach up to EUR15 million or 2.5% of global annual turnover, depending on the type and severity of the infringement. Overall, the CRA combines finan - cial sanctions with strong corrective powers to ensure effective cyber-resilience in practice. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation Germany’s cybersecurity certification landscape is primarily governed by the BSI. The BSI acts as Ger - many’s National Cybersecurity Certification Author - ity (NCCA) under the IT Security Act 2.0 and the EU Cybersecurity Act. In this role, it is responsible for

153 CHAMBERS.COM

Powered by