DAkkS and BSI extend their cooperation to the Cyber Resilience Act: bodies assessing product cybersecurity in Germany need DAkkS accreditation and BSI notification
On 24 September 2026 the German accreditation body DAkkS and the Federal Office for Information Security (BSI) renewed and extended their administrative agreement. Besides the Cybersecurity Act (CSA), it now covers the Cyber Resilience Act (CRA) and may cover further EU regulations.
- Among other things, the agreement governs the deployment of BSI technical assessors in DAkkS accreditation procedures in certain legal areas and BSI’s participation in the accreditation committee (AKA). DAkkS and BSI have cooperated under the Cybersecurity Act since September 2022.
- According to BSI, from the end of 2027 products with digital elements must meet the CRA cybersecurity requirements or they may no longer be placed on the EU market. For some products listed in the CRA, conformity must be demonstrated through third-party assessment by a conformity assessment body.
- In Germany such a body needs a valid DAkkS accreditation and, in a second step, notification by BSI. The BSI notification procedure for the CRA started on 11 June 2026, before the German implementing act, which is still in the legislative process; DAkkS already accepts applications for accreditation in the CRA scope.
- According to DAkkS, involving BSI expertise is meant to make assessments of the bodies practical and technically sound, and the agreement provides a basis for cooperation in future accreditation areas as well.
Source: DAkkS — DAkkS und BSI erweitern Zusammenarbeit bei Cybersicherheit (25.09.2026)