Germany's Cyber Resilience Act implementation bill and the BSI's proposed role

Germany's Cyber Resilience Act implementation bill and the BSI's proposed role

The Cyber Resilience Act is already in force, with its reporting duties applying from 11 September 2026. Germany's implementation bill would set national authority and procedure rules, but it had not completed Parliament at the latest recorded stage.

The legal position in Germany

Regulation (EU) 2024/2847, the Cyber Resilience Act, is directly applicable across the EU. It applies in stages: manufacturers' Article 14 duties to report actively exploited vulnerabilities and severe security incidents apply from 11 September 2026, while most of the Regulation applies from 11 December 2027.

Germany nevertheless needs national rules to identify competent authorities and establish national procedures. The Federal Government's bill, Bundestag Drucksache 21/6134, would chiefly amend the BSI Act for that purpose.

The Bundestag held the bill's first reading on 11 June 2026 and referred it to committees, led by the Committee on Internal Affairs, as recorded by the Bundestag. The Bundesrat raised no objections on 12 June 2026. These are procedural steps, not final enactment. At the latest official parliamentary stage covered here, the bill remained a government draft.

The BSI functions proposed by the bill

The bill would assign several Cyber Resilience Act functions to the Federal Office for Information Security, or BSI.

Proposed function What it would cover
Market-surveillance authority Monitoring compliance of products with digital elements and taking relevant national enforcement action.
Notifying authority Granting authority to qualifying conformity-assessment bodies and notifying them.
Coordinating CSIRT role Receiving and coordinating relevant reporting flows in Germany through CERT-Bund within the BSI.
Support measures Awareness and training measures, plus a proposed cyber-resilience regulatory sandbox for affected economic operators.

The Federal Government had already designated the BSI to the European Commission as Germany's notifying and market-surveillance authority, according to a 2025 BSI statement. That operational designation should not be confused with completion of the national bill.

The BSI's roles are distinct. Market surveillance concerns whether products made available on the market meet applicable requirements. The notifying-authority role concerns the bodies that assess conformity. The coordinating CSIRT role concerns the handling of specified vulnerability and incident reports; it does not make the BSI the recipient of every company security incident.

There are also authority rules and exceptions in the Cyber Resilience Act itself. Organisations should not assume that the BSI will be the market-surveillance authority for every product with digital elements in every case.

Conformity assessment and support provisions

Under the bill, DAkkS, Germany's national accreditation body, would normally assess conformity-assessment bodies. The BSI could carry out an assessment itself where a public interest exists, and would grant authority and notify qualifying bodies. This does not mean that the BSI would perform every accreditation or assessment itself.

Manufacturers should also avoid treating external third-party assessment as automatic for every product in Annex III or Annex IV. The applicable conformity-assessment route depends on the product classification, any relevant harmonised standards or common specifications, and the route selected under the Regulation.

The bill also proposes awareness and training measures and a cyber-resilience regulatory sandbox, particularly for small and medium-sized enterprises and open-source software stewards. These are proposed support provisions, and the bill does not create an entitlement to individual advice.

Reporting from 11 September 2026

From 11 September 2026, manufacturers must use ENISA's Single Reporting Platform for reports of actively exploited vulnerabilities and severe security incidents affecting product security. BSI operational guidance identifies CERT-Bund within the BSI as Germany's coordinating CSIRT.

The reporting obligation has defined statutory triggers. It does not require reporting every vulnerability or every incident affecting a business. Product-security teams should make sure that their triage process can identify the relevant triggers, preserve evidence, assign reporting ownership and meet the applicable deadlines.

The bill estimates that the BSI would receive around 2,000 reports annually. This is an administrative estimate in the draft, not an observed reporting volume.

What manufacturers should prepare

The national bill would not create the Cyber Resilience Act's substantive manufacturer duties. Those arise from the directly applicable Regulation. It would, however, make the relevant German authority and procedural landscape clearer.

Manufacturers and product-security teams operating in Germany can prepare by focusing on three practical areas:

  • Establish a clear path from vulnerability discovery and incident assessment to a timely Article 14 report through ENISA's platform.
  • Maintain the technical and governance evidence needed to demonstrate conformity if a market-surveillance authority requests it.
  • Confirm the applicable conformity-assessment route early, including whether standards, specifications or a third-party body affect the route for the product.

The bill's impact assessment says that it would create no additional compliance burden for citizens or businesses because the relevant duties arise from the Cyber Resilience Act. That is not a finding that compliance with the Regulation is cost-free. The same draft estimates administrative staffing, reporting volumes and associated public-sector costs, including up to 141 permanent posts by 2029.

What to monitor next

The immediate priority is the Cyber Resilience Act's reporting regime, which now applies independently of the national bill's completion. Organisations should also monitor the bill's progress through the Bundestag, any amendments to its proposed authority arrangements, and updates to BSI and ENISA operational guidance.

Until Parliament completes the process and the resulting legislation is promulgated, the proposed national amendments and commencement clauses should be treated as draft provisions rather than enacted German law.

Need help implementing cyber regulation?

Talk to Secuvi →