Country guide

The CRA in Germany: BSI, notified bodies and your deadlines

Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.

The Cyber Resilience Act is an EU Regulation, not a Directive. It applies directly in Germany without any national transposition law, so a product "made available on the Union market" is, for German companies, made available in Germany. What changes at the national level is enforcement: who notifies conformity assessment bodies, who watches the market, and who sets the penalties. This guide focuses on those German angles while anchoring every claim to the regulation text.

What "the Union market" means for you

For a German company, placing a product on the market is the trigger. The regulation defines it without reference to any one Member State, so the same act that serves customers in Berlin serves the whole EU.

“the first making available of a product with digital elements on the Union market”

The deadlines that bind German companies

The dates are Union-wide. Article 14 reporting binds manufacturers from 11 September 2026; the notified-body machinery opened on 11 June 2026; full application lands on 11 December 2027.

“This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026.”

Notified bodies and the BSI

If your product needs third-party conformity assessment, a notified body performs it. Notified bodies are designated by national notifying authorities under Chapter IV, which has applied since 11 June 2026.

“NOTIFICATION OF CONFORMITY ASSESSMENT BODIES”

“a conformity assessment body designated in accordance with Article 43 and other relevant Union harmonisation legislation”

In Germany the BSI (Bundesamt für Sicherheit in der Informationstechnik) is the notifying authority for CRA conformity assessment bodies: it assesses, designates and notifies the bodies that may certify products under the regulation. The BSI also chairs the administrative cooperation group of the market surveillance authorities (AdCo CRA), which is a coordinating role, not the surveillance role itself. Which German bodies carry out market surveillance rests on the national CRA implementing act (CRA-Durchführungsgesetz), still in the legislative process at the time of writing; confirm current designations on the notification page linked above before you engage a notified body. These German national-implementation claims are sourced from the BSI's own pages, not from the Official Journal corpus anchoring the rest of this site, and may change once the CRA-Durchführungsgesetz is adopted.

Market surveillance and penalties in Germany

Market surveillance authorities check compliance and can act on significant-risk products. The regulation defines the term by reference to the Union's general market-surveillance law.

“a market surveillance authority as defined in Article 3, point (4), of Regulation (EU) 2019/1020”

The fines themselves are set nationally. Germany lays down its own penalty rules for infringements, so the exact amounts and procedures follow German law, not the regulation's ceilings alone.

“Member States shall lay down the rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented.”

What to do next

Not sure which bucket you are in? Run the free Cybiq check in six questions, read the evidence-checked FAQ, or see the timeline of what applies when.

Orientation, not legal advice, and not a statement of German administrative law. National designations and penalty procedures change; verify the BSI role and the applicable German penalties against the current official sources before relying on them.