Country Overview Updated: August 2026

Cyber Resilience Act Enforcement in Germany

Learn how the EU Cyber Resilience Act applies to companies in Germany, including local market surveillance and enforcement by BSI.

Core Definition

The Cyber Resilience Act is an EU Regulation, meaning it applies directly in Germany without the need for national transposition. However, enforcement and market surveillance activities will be conducted by national authorities like BSI. Any product with digital elements sold or made available in Germany must comply with CRA standards by December 2027.

Key Compliance Steps for Germany

  1. Identify Local Representatives: If you are based outside the EU but selling into Germany, appoint an Authorized Representative in the Union.
  2. Monitor BSI Guidelines: Follow any localized guidance or translation of standards provided by BSI.
  3. Prepare ENISA Reporting: Ensure your vulnerability reporting pipelines are connected to the central ENISA platform and your national CSIRT.
  4. Localize Documentation: Ensure that the required EU Declaration of Conformity and user instructions are available in the languages required by Germany.

How This Plays Out in Practice

BSI already runs Germany's IT-Sicherheitsgesetz enforcement infrastructure and is expected to extend that existing market-surveillance capacity to CRA products rather than building a separate process from scratch.

What to Watch For

Germany's strong industrial-automation and automotive-software sectors mean BSI's CRA enforcement is likely to focus early attention on ICS and connected-vehicle software.

Assess Your CRA Readiness

Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to Germany.

Need help with CRA? Ask the assistant.
Need help with CRA? Ask the assistant.