CRA implementation law makes BSI central market surveillance authority

The CRA Implementation Act names the BSI as the market surveillance and notifying authority for the Cyber Resilience Regulation in Germany.

Exactly this point is often overlooked: according to the draft, the administrative burden for businesses and citizens caused by the implementation law itself is zero. The obligations for secure product development, vulnerability management, CE marking and reporting apply anyway because the regulation is directly applicable. The law only answers the question of which German authority manufacturers, notified bodies and consumers should turn to in future.

Which roles does the BSI take on?

With Article 1 the draft assigns four functions to the BSI under the CRA:

  • Market surveillance authority: monitors the conformity of products with digital elements, in particular compliance with the fundamental cybersecurity requirements in Annex I of the regulation.
  • Notifying authority: assesses and notifies conformity assessment bodies. The assessment itself is generally carried out by the national accreditation body (DAkkS) under Regulation (EC) No. 765/2008.
  • CSIRT coordinator and reporting office: receives reports of actively exploited vulnerabilities and serious security incidents that manufacturers must report under Article 14 of the regulation. The draft expects around 2,000 reports per year.
  • Support for economic operators: awareness-raising and training offers as well as the operation of a real-world testing lab for cyber resilience in which manufacturers can test innovative products before placing them on the market in a controlled test environment.

One limitation is relevant in practice: if a product falls both under the CRA and as a high-risk AI system under the AI Act or the AI Regulation (EU) 2024/1689, Article 52(14) CRA says the market surveillance authority designated for AI supervision is responsible — in Germany likely the Federal Network Agency. In these cases, market surveillance is therefore not conducted by the BSI.

What deadlines apply?

The draft staggers entry into force in three stages that follow the regulation:

  • 11. June 2026: provisions on notification enter into force so that notified bodies can be accredited in time.
  • 11. September 2026: the BSI becomes the CSIRT and reporting office for vulnerabilities and security incidents.
  • 11. December 2027: the remainder of the law enters into force, at the same time as the full effectiveness of the substantive CRA requirements.

For manufacturers the middle deadline is particularly tangible: from 11 September 2026 manufacturers must report actively exploited vulnerabilities and serious security incidents via the Single Reporting Platform; from there they go to the BSI as coordinating CSIRT and to ENISA. This is the first CRA obligation with an immediate organizational consequence, because it requires functioning internal processes for detection, assessment and timely reporting.

What does this mean for manufacturers in practice?

Anyone bringing a networked machine controller with remote maintenance access to market now has clear addressees thanks to the implementation law: the BSI is the contact point for market surveillance, for vulnerability reports and for support services. Does this change the actual requirements? No. The obligation to demonstrate a secure product development process, to manage vulnerabilities during the support period and to document conformity exists independently of the national law. The implementation law only makes clear which authority will enforce and receive these obligations in Germany.

Two points deserve a closer look:

  • Reporting process: Those who have not established a reliable internal chain from vulnerability detection to timely reporting by September 2026 risk missing deadlines in the event of an actively exploited incident.
  • Conformity assessment: The National Regulatory Control Council welcomes the consolidation at the BSI but explicitly points out that success depends on sufficient staffing capacities at the conformity assessment bodies. For important and critical products in Annexes III and IV that require third-party assessment, a bottleneck in notified bodies can become a market access risk. Those who rely on external assessment should plan for the availability of notified bodies early.

After the first reading the draft will be referred to the committees, primarily to the Committee on Internal Affairs. Changes in the further process are possible, but the basic authority architecture is unlikely to change much. The question of which authority is responsible is largely settled by the draft; operational preparation for the reporting obligation and conformity assessment remains the manufacturers’ responsibility.

The chain up to reporting remains your responsibility

From 11 September 2026 manufacturers will submit their reports via the Single Reporting Platform; from there they go to the responsible CSIRT and to ENISA. What happens before that is set out in the templates: who receives the notice, who assesses it, who approves it and who monitors the deadline.

Vorlagen kostenlos herunterladen