GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton
national certification schemes, the implementation of EU-wide certification frameworks and the supervision of recognised bodies and schemes. The German approach combines nationally estab - lished frameworks with emerging EU-wide certifica - tion schemes, allowing organisations to demonstrate cybersecurity assurance at product, service and organisational level. Core National Frameworks A central pillar of German cybersecurity practice is BSI IT-Grundschutz, a comprehensive methodology for implementing and operating an information secu - rity management system (ISMS). IT-Grundschutz is widely regarded as more prescriptive and detailed than purely risk-based standards and is frequently used in the public sector and regulated industries. Closely linked to this is ISO/IEC 27001 certification based on IT-Grundschutz, which allows organisations to demonstrate compliance with the international ISO 27001 standard while applying the BSI’s methodol - ogy. This certification is voluntary as a matter of law, but it is often a de facto reminder for procurement, outsourcing decisions and regulatory expectations. In the automotive sector, cybersecurity assurance is commonly demonstrated through TISAX (Trusted Information Security Assessment Exchange). While TISAX is not a statutory certification, it is effectively mandatory for suppliers that handle sensitive informa - tion within automotive supply chains, and plays a key role in market access. EU Cybersecurity Certification Framework At EU level, the EU Cybersecurity Act establishes a harmonised certification framework for ICT products, services and processes. Certification schemes under this framework are based on defined assurance levels (basic, substantial and high) and aim to ensure com - parability across member states. A key scheme for Germany is EUCC (European Com - mon Criteria-based cybersecurity certification), which builds on the well-established Common Criteria meth- odology and has been operational since February 2025. EUCC is expected to progressively replace or
align national Common Criteria schemes, particularly for products with cross-border relevance. In addition, EUCS, the EU cybersecurity certification scheme for cloud services, is currently under develop - ment by ENISA. While not yet applicable, it is expect - ed to become highly relevant for cloud providers and regulated customers once adopted. Sector-Specific Security Requirements Beyond certification schemes, Germany applies sec - tor-specific cybersecurity obligations, most notably for operators of critical infrastructures (KRITIS). These entities are subject to enhanced security and compli - ance requirements under the German implementation of EU cybersecurity law, supervised by the BSI. While KRITIS rules do not mandate a specific certification, recognised frameworks such as IT-Grundschutz or ISO 27001 are commonly used to demonstrate com - pliance. Across all frameworks, cybersecurity certification in Germany is typically voluntary in law but mandatory in practice. Certifications and recognised assessment schemes are frequently required by public-sector cus - tomers, regulated entities and large industrial clients as a condition for procurement, outsourcing or sup - ply chain participation. As EU schemes gain traction, organisations that operate cross-border increasingly need to align national certification strategies with EU- wide requirements. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection In Germany, cybersecurity requirements for the pro - cessing of personal data are primarily governed by the GDPR, supplemented by the Federal Data Protection Act (BDSG). Organisations must implement appropri - ate technical and organisational measures based on a risk-based approach, addressing confidentiality, integrity, availability and system resilience. The law avoids prescriptive technical standards. Instead, security measures must reflect the nature of the data, the purposes of processing, potential risks to individuals and the state of the art. In practice, this
154 CHAMBERS.COM
Powered by FlippingBook