BSI and DAkkS build up certification capacity for the Cyber Resilience Act
From the end of 2027, products with digital elements must meet the Cyber Resilience Act's requirements. BSI and DAkkS are now settling who may verify conformity in Germany.

The Federal Office for Information Security (BSI) and the German Accreditation Body (DAkkS) have updated an existing administrative agreement. In a joint announcement on 25 September 2026, the two bodies said the agreement now covers further areas in which the BSI is named as the authority that grants powers.
What the agreement covers
The agreement centres on cooperation in the accreditation of conformity assessment bodies (CABs) that carry out cybersecurity testing. It states in particular that the BSI provides technical assessors for DAkkS accreditation procedures in information security.
BSI President Claudia Plattner explained the reasoning. Manufacturers and service providers should find it easy to bring products with high cybersecurity to market, she said. The cooperation is meant to put that process on a secure footing.
What applies from the end of 2027
From the end of 2027, products with digital elements must meet the cybersecurity requirements of the Cyber Resilience Act (CRA). If they do not, they may no longer be placed on the European market. For some of the product groups listed in the CRA, manufacturers must show conformity through a third-party assessment by a CAB. In Germany, such bodies need a valid DAkkS accreditation. They then need notification by the BSI.
The BSI says its notification procedure for the CRA started on 11 June 2026, before the CRA implementing act was published. That act is still working its way through the legislative process. The DAkkS already accepts applications from CABs for the CRA scope.
The second pillar: AI security
The BSI is positioning itself in parallel as a testing authority for AI. On its specialist page, the office describes three points of contact between AI and IT security: the security of AI systems themselves, the benefit of AI for defence, and new attacks that AI methods make possible. The BSI says it conducts basic research for this and develops requirements, test criteria and test methodologies. These range from a criteria catalogue for integrating externally provided generative AI models, through a guide on AI coding assistants and "SBOM for AI", to quality criteria for training data (QUAIDAL) and a checklist on evasion attacks against LLMs.
Manufacturers and testing houses therefore face pressure on two fronts. Notified bodies must be built up while the test criteria for AI-supported products mature in parallel across several documents.
Who is allowed to certify conformity decides how quickly CRA-compliant products actually reach the market.
Sources
2- 01BSI: CRA-Konformität – BSI und DAkkS schaffen Prüfkompetenz für die CybersicherheitDE
- 02BSI: Schwerpunkt Künstliche IntelligenzDE
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.