IT-Compliance

Your contacts for this practice area:

  • Roman Ronneburger (CRA, NIS2, DORA, incident response, media-law crisis communication)
  • Linda Seiffert (cybersecurity compliance, contract drafting, supply-chain security)
  • Dr. Dirk Fischer (management liability, governance, insolvency and liability matters)
  • In technical cooperation: Robin Data and Prof. Dr. Döring (technical experts)

In 2026, cybersecurity is no longer a peripheral technical topic but a central compliance discipline in German and European commercial law. With the entry into force of the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), the applicability of the Cyber Resilience Act for the central reporting obligations, and the DORA Regulation applicable in the financial sector, the regulatory pressure on companies and public bodies is growing at a pace that would have been unthinkable just a few years ago. Added to this are sector-specific critical-infrastructure rules, the new Product Liability Directive 2024/2853 and the EU Cyber Solidarity Regulation.

SES Berlin advises companies, corporate groups, public bodies and critical infrastructures along every stage of the cybersecurity lifecycle: from strategic preparation, through ongoing compliance and incident-response management, to defence in administrative and civil-court proceedings.

Our advisory focus at a glance

We support clients in more than twelve typical constellations of IT security law:

  • Gap analysis and roadmap development for the CRA, NIS2, DORA and sector-specific cybersecurity requirements
  • Setting up and maintaining cybersecurity compliance management systems (CSMS)
  • Risk assessments, including the corporate-law liability of management
  • Cybersecurity-by-design in product development and software architecture
  • Contract drafting along the software and component supply chain
  • Incident-response support from the first hour to the final report
  • Crisis communication and media law in the event of a cybersecurity incident
  • Official notifications to the BSI, BlnBDI, BaFin and sector-specific supervisors
  • Defence of management board members and managing directors in liability and supervisory proceedings
  • Support with certifications under ISO/IEC 27001, TISAX, C5 and BSI IT-Grundschutz
  • Preparation and evaluation of penetration tests, red-team exercises and TLPT under DORA
  • Training and management awareness for the management board, IT, data protection and business functions

NIS2, CRA and DORA: legal framework and implementation

Implementing the new cybersecurity regulation is not a purely technical task. It requires legal precision at the interface between administrative, corporate, contract and liability law. Anyone who sets up a cybersecurity compliance programme without understanding the obligations arising from the NIS2 implementation act, the Cyber Resilience Act and DORA in their reciprocal interconnection risks duplication of work, gaps and, in the worst case, personal liability for management.

We begin every engagement with a structured gap analysis. Which regulations apply? Which sector classification applies? Which thresholds (headcount, annual turnover, balance-sheet total) have been reached? From this stocktake, we develop a prioritised roadmap that typically spans twelve to twenty-four months and brings the obligations under NIS2, the CRA and, where applicable, DORA into a consolidated cybersecurity governance.

We support the implementation of cybersecurity compliance management systems (CSMS). At the centre lies the integration with an information security management system under ISO/IEC 27001 or BSI IT-Grundschutz, the embedding into existing risk management and the coordination with data protection governance. We ensure that the CSMS operationally fulfils the NIS2 risk-management measures — backup concepts, cryptography, multi-factor authentication, supply-chain security, training, asset management — while covering the CRA-specific requirements for vulnerability handling and the SBOM.

The risk assessment covers not only technical but also corporate-law aspects. Under Section 38 NIS2UmsuCG, members of management are personally liable for breaches of risk-management obligations. Added to this are the general liability rules of stock-corporation and limited-liability-company law — Section 91(2), Section 93 AktG, Section 43 GmbHG — which are activated where cybersecurity governance is deficient. Recent BGH case law on compliance duties and the growing activity of D&O insurers are sharpening awareness of this liability. We review D&O cover, analyse the allocation of the burden of proof and develop documentation standards that demonstrate management acted in accordance with its duties.

Cybersecurity-by-design is not merely a technical design principle but a legal obligation under Art. 13 CRA and Art. 25 GDPR. We support product development and software architecture in its implementation — from secure default configuration to reduction of the attack surface, strict authentication, encryption in transit and at rest, separation of privileges and consistent logging and tamper resistance.

In contract drafting along the supply chain, we place particular emphasis on cyber clauses: minimum information-security requirements, audit rights, vulnerability-reporting obligations between the parties, penetration-test clauses, patching obligations, subcontractor approvals, data-location provisions, exit mechanisms and penalties. We ensure these clauses do not fall into the traps of German standard-terms law (Sections 305 et seq. BGB) while meeting the NIS2 obligation to ensure supply-chain security.

The Cyber Resilience Act, NIS2 and DORA in practice

The Cyber Resilience Act covers manufacturers, importers and distributors of products with digital elements. We advise on conformity assessment, technical documentation, CE marking, SBOM maintenance, vulnerability management and the reporting processes that must be activated from 11 September 2026 within 24, 72 and 14 days. We assess whether the product falls into the category of important products (Class I) or critical products (Class II) and adjust the conformity procedure accordingly.

The NIS2UmsuCG has expanded the group of covered companies in Germany from around 4,500 critical-infrastructure operators to roughly 30,000 essential and important entities. The registration deadline with the BSI runs until 6 March 2026. We assess the classification, coordinate the registration and implement the catalogues of obligations relating to risk-management measures, reporting, management liability and training.

DORA has, since 17 January 2025, obliged financial entities and their ICT third-party providers to maintain comprehensive ICT risk management. We support banks, insurers, investment firms and FinTechs in establishing the register of information, adapting ICT contracts to Art. 30 DORA, preparing threat-led penetration tests (TLPT) and reporting major ICT incidents.

Critical infrastructure and sector-specific rules

Even within the scope of NIS2, the sector-specific cybersecurity rules remain relevant. The BSI Act covers critical-infrastructure operators (Section 8a BSIG). In energy, the Federal Network Agency's IT security catalogue applies in addition; in telecommunications, Sections 165 et seq. TKG; in healthcare, the critical-infrastructure regulation; in the financial sector, BAIT, VAIT, KAIT and ZAIT. We guide clients through the overlaps with the NIS2 implementation act following the principle of speciality.

Incident management and crisis response

In a cybersecurity incident, every hour counts. The success of crisis management depends less on technical recovery than on a well-considered legal and communications strategy. Mistakes in the first 24 hours risk fines, damages claims, reputational harm and personal liability of management.

Our incident-response support ideally begins before the emergency arises. Together with the client, we develop an incident-response playbook that rehearses the typical scenarios — ransomware, data exfiltration, manipulation, service outage, supply-chain incident — and defines escalation paths, responsibilities, the role of the forensic service provider and the reporting channels to insurers, authorities and contractual partners.

In an actual incident, we support the crisis team from the first assessment. We evaluate the reporting obligations in parallel — Art. 33 and 34 GDPR, NIS2 (24-hour early warning, 72-hour follow-up), the CRA (24/72/14-day scheme from 11 September 2026), DORA and sector-specific notifications under the BSIG — and coordinate them so that multiple reports remain consistent and contain no admissions that could later be used against the company.

Crisis communication is legally highly sensitive. Press releases, customer statements, partner notifications, board statements and employee communications must be aligned. We coordinate with the crisis team, the press officer and external consultants, paying attention to ad-hoc disclosure obligations under Art. 17 MAR, contractual information duties and the criminal-law assessment of individual statements.

Defence in administrative proceedings and civil damages proceedings is a distinct focus. We represent companies before the BlnBDI and BfDI in GDPR fine proceedings, before the BSI in NIS2 and CRA proceedings, before BaFin in DORA proceedings and before sector-specific supervisors, and conduct the civil-court defence against claims by injured customers, employees and partners, including collective actions under the German Consumer Rights Enforcement Act (VDuG).

Management liability in a cybersecurity incident under NIS2

Since the NIS2UmsuCG, the liability of management in a cybersecurity incident has become a distinct advisory focus. Members of management are personally liable for breaches of the NIS2 risk-management obligations, and the BSI can impose personal fines. Added to this are Section 93 AktG (duty of care), Section 91(2) AktG (risk early-warning system) and Section 43 GmbHG (duty of care of GmbH managing directors). We advise management preventively — clear documentation, robust risk-management reporting, regular training, D&O cover analyses — and in a crisis, examining personal lines of defence and coordinating with the D&O insurer. In criminally relevant constellations (e.g. Section 130 OWiG) we work with our white-collar crime colleagues.

Certifications and audits in IT security law

Certifications today are often a contractual and, in part, statutory prerequisite: ISO/IEC 27001, TISAX (automotive), the BSI's C5 (cloud), BSI IT-Grundschutz (public authorities and critical infrastructure) and the European cybersecurity certification schemes under the Cybersecurity Act (EUCC, EUCS). We support the preparation of certifications, formulate policies and procedural instructions, review audit reports and defend clients in review proceedings. For penetration tests, red-team exercises and TLPT, we ensure legally sound engagement (demarcation from Sections 202a et seq. StGB), clean contract drafting and careful handling of the test results.

Supply-chain security, supply chain and open source

Supply-chain security is one of the central new topics of IT security law. Both NIS2 and the CRA oblige companies to identify and address risks in the software and hardware supply chain; DORA adds third-party-management requirements for the financial sector. Open-source components — today typically 70 to 90 per cent of every business application — must be integrated in a licence-compliant manner, continuously monitored for vulnerabilities and documented in the SBOM. We develop supplier due-diligence processes, review Software Bills of Materials, draft cyber clauses for procurement contracts and support responses to vulnerability reports from the supply chain — from Log4Shell to the OpenSSL vulnerability, from the xz backdoor to compromised npm packages.

Cybersecurity contract drafting: SLAs, data processing agreements and ICT contracts

Contract drafting in the cybersecurity context is a discipline in its own right. We draft and negotiate:

  • Cybersecurity SLAs with security KPIs such as patch windows, detection times and MTTR
  • Data processing agreement annexes with supplementary security and reporting obligations
  • Penetration-test clauses, including scope, limitation of liability and rules of engagement
  • ICT third-party provider contracts under Art. 30 DORA
  • Supplier cyber clauses under NIS2 and the CRA
  • Bug-bounty and vulnerability-disclosure agreements with a legally sound safe-harbour clause
  • Incident-response retainers with forensic service providers
  • Cyber-insurance policy reviews and support in the event of a claim

Training and management awareness

Training is not optional but mandatory. NIS2 expressly requires regular training for management; DORA calls for continuous awareness programmes; the GDPR requires appropriate training for those entrusted with processing. We offer in-house workshops, webinars and tailored training for management, the IT security team, the data protection team, procurement and business functions, combining legal depth with practical examples from recent regulatory and case-law practice.


Cyber Resilience Act (CRA): In-depth client information on the new EU cybersecurity law for products with digital elements — What must be done? · FAQ · Regulation text.

IT-Compliance

Your contacts for this practice area:

  • Roman Ronneburger (CRA, NIS2, DORA, incident response, media-law crisis communication)
  • Linda Seiffert (cybersecurity compliance, contract drafting, supply-chain security)
  • Dr. Dirk Fischer (management liability, governance, insolvency and liability matters)
  • In technical cooperation: Robin Data and Prof. Dr. Döring (technical experts)

In 2026, cybersecurity is no longer a peripheral technical topic but a central compliance discipline in German and European commercial law. With the entry into force of the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), the applicability of the Cyber Resilience Act for the central reporting obligations, and the DORA Regulation applicable in the financial sector, the regulatory pressure on companies and public bodies is growing at a pace that would have been unthinkable just a few years ago. Added to this are sector-specific critical-infrastructure rules, the new Product Liability Directive 2024/2853 and the EU Cyber Solidarity Regulation.

SES Berlin advises companies, corporate groups, public bodies and critical infrastructures along every stage of the cybersecurity lifecycle: from strategic preparation, through ongoing compliance and incident-response management, to defence in administrative and civil-court proceedings.

Our advisory focus at a glance

We support clients in more than twelve typical constellations of IT security law:

  • Gap analysis and roadmap development for the CRA, NIS2, DORA and sector-specific cybersecurity requirements
  • Setting up and maintaining cybersecurity compliance management systems (CSMS)
  • Risk assessments, including the corporate-law liability of management
  • Cybersecurity-by-design in product development and software architecture
  • Contract drafting along the software and component supply chain
  • Incident-response support from the first hour to the final report
  • Crisis communication and media law in the event of a cybersecurity incident
  • Official notifications to the BSI, BlnBDI, BaFin and sector-specific supervisors
  • Defence of management board members and managing directors in liability and supervisory proceedings
  • Support with certifications under ISO/IEC 27001, TISAX, C5 and BSI IT-Grundschutz
  • Preparation and evaluation of penetration tests, red-team exercises and TLPT under DORA
  • Training and management awareness for the management board, IT, data protection and business functions

NIS2, CRA and DORA: legal framework and implementation

Implementing the new cybersecurity regulation is not a purely technical task. It requires legal precision at the interface between administrative, corporate, contract and liability law. Anyone who sets up a cybersecurity compliance programme without understanding the obligations arising from the NIS2 implementation act, the Cyber Resilience Act and DORA in their reciprocal interconnection risks duplication of work, gaps and, in the worst case, personal liability for management.

We begin every engagement with a structured gap analysis. Which regulations apply? Which sector classification applies? Which thresholds (headcount, annual turnover, balance-sheet total) have been reached? From this stocktake, we develop a prioritised roadmap that typically spans twelve to twenty-four months and brings the obligations under NIS2, the CRA and, where applicable, DORA into a consolidated cybersecurity governance.

We support the implementation of cybersecurity compliance management systems (CSMS). At the centre lies the integration with an information security management system under ISO/IEC 27001 or BSI IT-Grundschutz, the embedding into existing risk management and the coordination with data protection governance. We ensure that the CSMS operationally fulfils the NIS2 risk-management measures — backup concepts, cryptography, multi-factor authentication, supply-chain security, training, asset management — while covering the CRA-specific requirements for vulnerability handling and the SBOM.

The risk assessment covers not only technical but also corporate-law aspects. Under Section 38 NIS2UmsuCG, members of management are personally liable for breaches of risk-management obligations. Added to this are the general liability rules of stock-corporation and limited-liability-company law — Section 91(2), Section 93 AktG, Section 43 GmbHG — which are activated where cybersecurity governance is deficient. Recent BGH case law on compliance duties and the growing activity of D&O insurers are sharpening awareness of this liability. We review D&O cover, analyse the allocation of the burden of proof and develop documentation standards that demonstrate management acted in accordance with its duties.

Cybersecurity-by-design is not merely a technical design principle but a legal obligation under Art. 13 CRA and Art. 25 GDPR. We support product development and software architecture in its implementation — from secure default configuration to reduction of the attack surface, strict authentication, encryption in transit and at rest, separation of privileges and consistent logging and tamper resistance.

In contract drafting along the supply chain, we place particular emphasis on cyber clauses: minimum information-security requirements, audit rights, vulnerability-reporting obligations between the parties, penetration-test clauses, patching obligations, subcontractor approvals, data-location provisions, exit mechanisms and penalties. We ensure these clauses do not fall into the traps of German standard-terms law (Sections 305 et seq. BGB) while meeting the NIS2 obligation to ensure supply-chain security.

The Cyber Resilience Act, NIS2 and DORA in practice

The Cyber Resilience Act covers manufacturers, importers and distributors of products with digital elements. We advise on conformity assessment, technical documentation, CE marking, SBOM maintenance, vulnerability management and the reporting processes that must be activated from 11 September 2026 within 24, 72 and 14 days. We assess whether the product falls into the category of important products (Class I) or critical products (Class II) and adjust the conformity procedure accordingly.

The NIS2UmsuCG has expanded the group of covered companies in Germany from around 4,500 critical-infrastructure operators to roughly 30,000 essential and important entities. The registration deadline with the BSI runs until 6 March 2026. We assess the classification, coordinate the registration and implement the catalogues of obligations relating to risk-management measures, reporting, management liability and training.

DORA has, since 17 January 2025, obliged financial entities and their ICT third-party providers to maintain comprehensive ICT risk management. We support banks, insurers, investment firms and FinTechs in establishing the register of information, adapting ICT contracts to Art. 30 DORA, preparing threat-led penetration tests (TLPT) and reporting major ICT incidents.

Critical infrastructure and sector-specific rules

Even within the scope of NIS2, the sector-specific cybersecurity rules remain relevant. The BSI Act covers critical-infrastructure operators (Section 8a BSIG). In energy, the Federal Network Agency's IT security catalogue applies in addition; in telecommunications, Sections 165 et seq. TKG; in healthcare, the critical-infrastructure regulation; in the financial sector, BAIT, VAIT, KAIT and ZAIT. We guide clients through the overlaps with the NIS2 implementation act following the principle of speciality.

Incident management and crisis response

In a cybersecurity incident, every hour counts. The success of crisis management depends less on technical recovery than on a well-considered legal and communications strategy. Mistakes in the first 24 hours risk fines, damages claims, reputational harm and personal liability of management.

Our incident-response support ideally begins before the emergency arises. Together with the client, we develop an incident-response playbook that rehearses the typical scenarios — ransomware, data exfiltration, manipulation, service outage, supply-chain incident — and defines escalation paths, responsibilities, the role of the forensic service provider and the reporting channels to insurers, authorities and contractual partners.

In an actual incident, we support the crisis team from the first assessment. We evaluate the reporting obligations in parallel — Art. 33 and 34 GDPR, NIS2 (24-hour early warning, 72-hour follow-up), the CRA (24/72/14-day scheme from 11 September 2026), DORA and sector-specific notifications under the BSIG — and coordinate them so that multiple reports remain consistent and contain no admissions that could later be used against the company.

Crisis communication is legally highly sensitive. Press releases, customer statements, partner notifications, board statements and employee communications must be aligned. We coordinate with the crisis team, the press officer and external consultants, paying attention to ad-hoc disclosure obligations under Art. 17 MAR, contractual information duties and the criminal-law assessment of individual statements.

Defence in administrative proceedings and civil damages proceedings is a distinct focus. We represent companies before the BlnBDI and BfDI in GDPR fine proceedings, before the BSI in NIS2 and CRA proceedings, before BaFin in DORA proceedings and before sector-specific supervisors, and conduct the civil-court defence against claims by injured customers, employees and partners, including collective actions under the German Consumer Rights Enforcement Act (VDuG).

Management liability in a cybersecurity incident under NIS2

Since the NIS2UmsuCG, the liability of management in a cybersecurity incident has become a distinct advisory focus. Members of management are personally liable for breaches of the NIS2 risk-management obligations, and the BSI can impose personal fines. Added to this are Section 93 AktG (duty of care), Section 91(2) AktG (risk early-warning system) and Section 43 GmbHG (duty of care of GmbH managing directors). We advise management preventively — clear documentation, robust risk-management reporting, regular training, D&O cover analyses — and in a crisis, examining personal lines of defence and coordinating with the D&O insurer. In criminally relevant constellations (e.g. Section 130 OWiG) we work with our white-collar crime colleagues.

Certifications and audits in IT security law

Certifications today are often a contractual and, in part, statutory prerequisite: ISO/IEC 27001, TISAX (automotive), the BSI's C5 (cloud), BSI IT-Grundschutz (public authorities and critical infrastructure) and the European cybersecurity certification schemes under the Cybersecurity Act (EUCC, EUCS). We support the preparation of certifications, formulate policies and procedural instructions, review audit reports and defend clients in review proceedings. For penetration tests, red-team exercises and TLPT, we ensure legally sound engagement (demarcation from Sections 202a et seq. StGB), clean contract drafting and careful handling of the test results.

Supply-chain security, supply chain and open source

Supply-chain security is one of the central new topics of IT security law. Both NIS2 and the CRA oblige companies to identify and address risks in the software and hardware supply chain; DORA adds third-party-management requirements for the financial sector. Open-source components — today typically 70 to 90 per cent of every business application — must be integrated in a licence-compliant manner, continuously monitored for vulnerabilities and documented in the SBOM. We develop supplier due-diligence processes, review Software Bills of Materials, draft cyber clauses for procurement contracts and support responses to vulnerability reports from the supply chain — from Log4Shell to the OpenSSL vulnerability, from the xz backdoor to compromised npm packages.

Cybersecurity contract drafting: SLAs, data processing agreements and ICT contracts

Contract drafting in the cybersecurity context is a discipline in its own right. We draft and negotiate:

  • Cybersecurity SLAs with security KPIs such as patch windows, detection times and MTTR
  • Data processing agreement annexes with supplementary security and reporting obligations
  • Penetration-test clauses, including scope, limitation of liability and rules of engagement
  • ICT third-party provider contracts under Art. 30 DORA
  • Supplier cyber clauses under NIS2 and the CRA
  • Bug-bounty and vulnerability-disclosure agreements with a legally sound safe-harbour clause
  • Incident-response retainers with forensic service providers
  • Cyber-insurance policy reviews and support in the event of a claim

Training and management awareness

Training is not optional but mandatory. NIS2 expressly requires regular training for management; DORA calls for continuous awareness programmes; the GDPR requires appropriate training for those entrusted with processing. We offer in-house workshops, webinars and tailored training for management, the IT security team, the data protection team, procurement and business functions, combining legal depth with practical examples from recent regulatory and case-law practice.


Cyber Resilience Act (CRA): In-depth client information on the new EU cybersecurity law for products with digital elements — What must be done? · FAQ · Regulation text.