Skip to content
World clockEU--:--UK--:--USA--:--CN--:--PLDEFRIT中文EN

portal about AI and technologyevents · analysis · interviews · technical background

Search
LIVE
›

BSI and DAkkS build up certification capacity for the Cyber Resilience Act

From the end of 2027, products with digital elements must meet the Cyber Resilience Act's requirements. BSI and DAkkS are now settling who may verify conformity in Germany.

TechnologyNewsGrace OkonkwoPublished: 25 September 20265 min readSources 2
BSI and DAkkS build up certification capacity for the Cyber Resilience Act

The Federal Office for Information Security (BSI) and the German Accreditation Body (DAkkS) have updated an existing administrative agreement. In a joint announcement on 25 September 2026, the two bodies said the agreement now covers further areas in which the BSI is named as the authority that grants powers.

What the agreement covers

The agreement centres on cooperation in the accreditation of conformity assessment bodies (CABs) that carry out cybersecurity testing. It states in particular that the BSI provides technical assessors for DAkkS accreditation procedures in information security.

BSI President Claudia Plattner explained the reasoning. Manufacturers and service providers should find it easy to bring products with high cybersecurity to market, she said. The cooperation is meant to put that process on a secure footing.

What applies from the end of 2027

From the end of 2027, products with digital elements must meet the cybersecurity requirements of the Cyber Resilience Act (CRA). If they do not, they may no longer be placed on the European market. For some of the product groups listed in the CRA, manufacturers must show conformity through a third-party assessment by a CAB. In Germany, such bodies need a valid DAkkS accreditation. They then need notification by the BSI.

The BSI says its notification procedure for the CRA started on 11 June 2026, before the CRA implementing act was published. That act is still working its way through the legislative process. The DAkkS already accepts applications from CABs for the CRA scope.

The second pillar: AI security

The BSI is positioning itself in parallel as a testing authority for AI. On its specialist page, the office describes three points of contact between AI and IT security: the security of AI systems themselves, the benefit of AI for defence, and new attacks that AI methods make possible. The BSI says it conducts basic research for this and develops requirements, test criteria and test methodologies. These range from a criteria catalogue for integrating externally provided generative AI models, through a guide on AI coding assistants and "SBOM for AI", to quality criteria for training data (QUAIDAL) and a checklist on evasion attacks against LLMs.

Manufacturers and testing houses therefore face pressure on two fronts. Notified bodies must be built up while the test criteria for AI-supported products mature in parallel across several documents.

Who is allowed to certify conformity decides how quickly CRA-compliant products actually reach the market.

Comments 0

Sources

2
  1. 01BSI: CRA-Konformität – BSI und DAkkS schaffen Prüfkompetenz für die CybersicherheitDE
  2. 02BSI: Schwerpunkt Künstliche IntelligenzDE

All figures and quotations in this text come from the sources listed below.

Content prepared by the editorial team with AI assistance.

Grace Okonkwo

Grace Okonkwo

AI, models and technology

Grace Okonkwo covers AI, models and technology for FLASH24, working from primary sources such as model cards, API documentation and benchmark papers rather than vendor summaries. She checks training data provenance, evaluation conditions and reported scores against the underlying datasets before any figure reaches print. She interviews researchers and engineers directly, tracks release calendars from major labs, and compares successive model versions on the same tests. Her own self-hosting, home-network and documentation-reading habits feed straight into that desk, since she tests tools on her own hardware first. She does not publish benchmark claims without a reproducible method.

Newsroom →

Comments

0
  1. No comments yet — be the first.

Write a comment

Comments are public. We do not publish abuse, spam or advertising.