# IT regulatory radar: what applies, what is coming, what to do now

> NIS2, the AI Act, the Data Act, the Cyber Resilience Act, e-invoicing, accessibility, retention and data protection: the current state of IT regulation in Germany with deadlines and recommendations.

URL: https://techport.ai/en/it-beratung/regulatorik-radar

---

1.  [IT Consulting](/en/it-beratung)/
2.  IT regulatory radar

Knowledge · As of: 21 August 2026

# IT regulatory radar

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

IT regulation has changed more in three years than in the fifteen before. This page summarises what applies today, what has been announced and what you should do now. We update it whenever something relevant changes. It does not replace legal advice, it helps you ask the right questions in time.

[NIS2 and the new German BSI Act](#radar-0)[The AI Act and the Digital Omnibus](#radar-1)[EU Data Act](#radar-2)[E-invoicing in the B2B area](#radar-3)[Cyber Resilience Act](#radar-4)[German Accessibility Act](#radar-5)[Retention periods and process documentation](#radar-6)[Employee data protection and legal bases](#radar-7)[Codetermination for IT systems](#radar-8)

## NIS2 and the new German BSI Act

In force

Deadline

In force since 6 December 2025, registration to be caught up

Scope

Companies in the sectors of annexes 1 and 2 BSIG, generally from 50 employees or from 10 million euros in turnover and balance sheet total

The German NIS2 implementation act came into force on 6 December 2025. The duties have applied directly since then, irrespective of registration. The registration portal of the Federal Office for Information Security has been available since January 2026, the regular deadline of 6 March 2026 has passed, as has an extension set by the authority in July 2026. Anyone not yet registered who might be in scope should catch up without delay. Central are the risk management measures under Section 30 BSIG, the reporting duties under Section 32 BSIG with an initial report within twenty-four hours, and the registration duty under Section 33 BSIG. Management has to approve the measures, supervise their implementation and undergo training.

What to do now: check scope on the record, establish gaps against Section 30 BSIG, set up and rehearse the reporting route, produce evidence, add supplier requirements to contracts.

[Go to the topic page](/en/it-beratung/sicherheit-und-resilienz/nis2-und-cybersicherheit)[Source](https://www.bsi.bund.de/dok/nis-2-regulierung)

## The AI Act and the Digital Omnibus

In force, high-risk deadlines postponed

Deadline

High risk under Annex III from 2 December 2027, under Annex I from 2 August 2028

Scope

All companies providing or deploying AI systems

Regulation (EU) 2024/1689 has applied in general terms since 2 August 2026. The prohibitions on certain practices have applied since 2 February 2025, as has the AI literacy duty under Article 4. Obligations for general purpose AI models have applied since 2 August 2025. The Digital Omnibus Regulation (EU) 2026/1744 entered into force on 27 July 2026 and postponed the high-risk duties, for standalone systems under Annex III to 2 December 2027 and for systems embedded in products under Annex I to 2 August 2028. Market surveillance in Germany sits with the Federal Network Agency.

What to do now: take an AI inventory across all systems, clarify your role as provider or deployer, document the risk classification per application, implement transparency duties, evidence training for the staff concerned.

[Go to the topic page](/en/it-beratung/it-governance-und-recht/ki-verordnung)[Source](https://eur-lex.europa.eu/eli/reg/2024/1689/oj)

## EU Data Act

In force

Deadline

Applicable since 12 September 2025, switching charges removed from 12 January 2027

Scope

Users and providers of cloud services, manufacturers of connected products

Regulation (EU) 2023/2854 has applied since 12 September 2025. For users, the rules on changing provider matter most: cloud providers must enable the switch contractually and technically, with a notice period of no more than two months followed by a transition period of usually no more than thirty days. Charges for switching disappear entirely from 12 January 2027. For manufacturers of connected products, obligations on data access are added.

What to do now: review cloud contracts for switching clauses, export formats and deadlines, test the data export rather than merely agreeing it, and demand the new requirements in new contracts.

[Go to the topic page](/en/it-beratung/architektur-und-anwendungen/cloud-strategie)[Source](https://eur-lex.europa.eu/eli/reg/2023/2854/oj)

## E-invoicing in the B2B area

Applies in stages

Deadline

Obligation to send from 1 January 2027 above 800,000 euros turnover, from 1 January 2028 for everyone

Scope

All domestic companies with B2B transactions

Since 1 January 2025, domestic companies have had to be able to receive e-invoices. Until the end of 2026 other formats remain permissible with the recipient's consent. From 1 January 2027 the obligation to send applies to companies with more than 800,000 euros in total turnover in the previous year, and from 1 January 2028 in principle to all domestic B2B transactions. Only structured formats complying with EN 16931 count as an e-invoice, in Germany primarily XRechnung and ZUGFeRD.

What to do now: check whether your system can produce, send and archive structured invoices as originals, establish your turnover position for 2027, automate incoming processing, update the process documentation.

[Go to the topic page](/en/it-beratung/it-governance-und-recht/e-rechnung)[Source](https://www.gesetze-im-internet.de/ustg_1980/__14.html)

## Cyber Resilience Act

In force, duties staged

Deadline

Reporting duties from 11 September 2026, full application from 11 December 2027

Scope

Manufacturers, importers and distributors of products with digital elements

Regulation (EU) 2024/2847 introduces binding cyber security requirements for products with digital elements across their whole life cycle. From 11 September 2026 the reporting duties apply for actively exploited vulnerabilities and severe security incidents, with an early warning within twenty-four hours. From 11 December 2027 the regulation applies in full, and covered products then have to meet the essential requirements and undergo a conformity assessment. This is relevant for mechanical engineering and industry wherever products ship with software.

What to do now: check whether your products are covered, build vulnerability management and a reporting process, introduce a software bill of materials, define the support period and pass requirements on to suppliers.

[Go to the topic page](/en/it-beratung/entwickeln-und-beschaffen/individualentwicklung)[Source](https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html)

## German Accessibility Act

In force

Deadline

Since 28 June 2025

Scope

Providers of products and services to consumers, including online shops and customer portals

The act has applied since 28 June 2025 and obliges electronic commerce for consumers, among others, to be accessible. For services there is an exemption for micro-enterprises with fewer than ten employees and no more than two million euros in annual turnover, which does not apply to products. The benchmark is the European standard EN 301 549. Breaches can be fined, and warnings and complaints to the market surveillance body are additional risks.

What to do now: clarify scope on the record, have shops and customer portals assessed, fix the paths to contract conclusion first, add accessibility to requirements for new systems and set up the feedback procedure.

[Go to the topic page](/en/it-beratung/it-governance-und-recht/digitale-barrierefreiheit)[Source](https://www.gesetze-im-internet.de/bfsg/)

## Retention periods and process documentation

In force

Deadline

Shortened period for accounting vouchers since 1 January 2025

Scope

All companies subject to accounting obligations

The Fourth Bureaucracy Relief Act shortened the retention period for accounting vouchers and invoices from ten to eight years, applicable to records whose period had not yet expired on 1 January 2025. For commercial books, inventories, annual accounts and the associated work instructions and organisational documents it remains ten years, and for other business letters six years. Electronic records have to remain legible and machine readable throughout the period.

What to do now: adjust deletion rules in the archive to the new periods, produce or update the process documentation, describe substitute scanning, and secure access to retired legacy systems for the remaining period.

[Go to the topic page](/en/it-beratung/daten-und-information/dokumentenmanagement)[Source](https://www.gesetze-im-internet.de/ao_1977/__147.html)

## Employee data protection and legal bases

Open

Deadline

No date

Scope

All employers

In 2023 the Court of Justice of the European Union held a state law provision equivalent to Section 26 BDSG to be incompatible with Union law. Since then it has been unclear whether Section 26 BDSG carries as a legal basis for processing employee data. A dedicated employee data protection act has been discussed for years without a concluded legislative procedure. For IT this matters particularly for log data, device management, access analysis and security tools.

What to do now: base processing in the employment context on Articles 6 and 88 GDPR and document it, draft works agreements carefully where they serve as a legal basis, and set deletion periods for log data.

[Go to the topic page](/en/it-beratung/it-governance-und-recht/datenschutz-in-der-it)[Source](https://www.gesetze-im-internet.de/bdsg_2018/__26.html)

## Codetermination for IT systems

In force

Deadline

Ongoing

Scope

Companies with a works council

Technical systems objectively capable of monitoring employee behaviour or performance are subject to codetermination under Section 87 (1) no. 6 of the German Works Constitution Act. Whether monitoring is intended is irrelevant. In practice this covers device management, ticket systems, security tools, time recording, access logs and many AI features. Planning alone has to be discussed with the works council under Section 90.

What to do now: review the framework agreement on IT systems and extend it to cloud, mobile devices and AI features, involve the works council before vendor selection, and settle permitted analyses and deletion periods in the procedure.

[Go to the topic page](/en/it-beratung/betrieb-und-support/arbeitsplatz-und-endgeraete)[Source](https://www.gesetze-im-internet.de/betrvg/__87.html)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

This page reflects the position at the date given and does not replace legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
