At a time of growing geopolitical tensions, rapid technological progress and hybrid threats, states are becoming increasingly concerned about protecting their economic security. To this end, various legal regimes are being created at the national and European levels. Measures in the area of economic security aim to ensure the security of supply of critical goods and services, protect critical infrastructure, prevent the outflow of critical technologies and reduce economic dependencies. We advise our clients on all matters relating to economic security. Due to our many years of cooperation with the competent authorities, we have an excellent understanding of the political framework.
The German Federal Ministry for Economic Affairs and Energy (BMWE) reserves the right to review and restrict foreign investors' acquisitions of German companies or stakes in German companies in order to safeguard public order or security or essential security interests of the Federal Republic of Germany. In the context of M&A transactions, it is therefore essential to assess whether the planned transaction is subject to a mandatory notification requirement or whether a voluntary notification is advisable.
Often, there is a close connection to sensitive items and critical infrastructure. In this regard, you benefit from our many years of experience with the classification of such items and the designation of infrastructure as critical within the meaning of the BSI-KritisV.
We support both investors and sellers in the foreign direct investment control review of planned M&A transactions and in contract drafting. Where notification is required or a certificate of non-objection is sought, we represent you before the BMWE throughout the entire review process, including any negotiations regarding contractual commitments and conditions. Should a notification obligation apply (also) in other jurisdictions, we will coordinate with specialized law firms from our network.
In the field of military security and defence, companies are subject to particularly strict regulatory requirements, such as the War Weapons Control Act (KrWaffKontrG), arms export controls and requirements relating to the protection of classified information and against sabotage.
The KrWaffKontrG provides the legal framework for the handling of warweapons in Germany. Numerous activities relating to weapons of war – from manufacture and acquisition through to transport, import and export – require an authorization and are subject to strict state control.
At the same time, the provisions of arms export control law must be observed, under which the transfer and export of military items, as well as the provision of certain services, are subject to authorization requirements. In addition to the provisions of German arms export control law, regulations under US arms export control law that have extraterritorial effect, as well as, where applicable, export controls relating to dual-use items, must often be taken into account.
We provide comprehensive advice to companies in the defence industry and their suppliers on all matters relating to the KrWaffKontrG, arms export controls, and regulation relating to the protection of classified information and against sabotage. Our services include the legal assessment of products and business transactions, support throughout licensing procedures, and assistance in the design and further development of internal compliance structures. Furthermore,we represent our clients before the relevant authorities and courts.
Entities whose functioning is essential for the state community are subject to increasing regulatory requirements. Relevant sectors are, for example, energy, water,food, information technology and telecommunications, healthcare, finance and insurance, transportation and traffic as well as municipal waste disposal. A failure or impairment of such facilities can result in supply bottlenecks or significant disruptions to public safety. Their operators are therefore obliged to take measures to protect their facilities against cybersecurity risks risks as well as physical risks. They are also subject to registration and reporting obligations.
Cybersecurity obligations were significantly expanded in December 2025 following the national implementation of the NIS2 Directive. Following amendments to the Act on the Federal Office for Information Security (BSIG),around 30,000 additional companies across various sectors in Germany were classified as “essential entities” and “important entities” and required tocomply with cybersecurity obligations.
The KRITIS Umbrella Act (KRITIS-DachG), enacted in 2026, establishes minimum requirements for the physical protection of critical infrastructure, thereby transposing the CER Directive into German law. Operators of critical facilities must prepare for further obligations in order to prevent disruptions to critical facilities caused by natural hazards, attacks or sabotage, and to limit their impact.
We support you in assessing whether your company is subjectto these regulations, as well as in developing strategies for the implementation of applicable obligations and the implementation of appropriate internal compliance measures.
In view of the increase in geopolitical tensions, the focus is increasingly on potential security risks in the area of research and development. In particular, there is a risk of transfer of sensitive know-how and technology, which could be misused for military purposes in third countries, as well as the danger of research being influenced by (critical) third countries.
Security aspects are therefore playing an increasingly important role in research institutions and universities. Like start-ups, they are increasingly confronted with the challenge of dealing with potential vulnerability to misuse of future technologies at an early stage and taking appropriate measures to minimize security risks, in addition to complying with existing export control restrictions.
We have many years of experience in developing and implementing compliance management systems for research and scientific institutions and companies that help to identify, assess and avoid risks.
The EU's so-called Critical Raw Materials Act (CRMA) is intended to secure the supply of strategic raw materials to the EU and reduce reliance on individual third countries. For this purpose, among other things, certain projects in the areas of extraction, processing and recycling are supported. Affected companies are subject in particular to risk management obligations in their supply chain as well as reporting obligations. The CRMA also indirectly affects companies in the supply chain, as the companies directly covered by the CRMA's scope require their information for risk analysis.
Many aspects of the CRMA are yet to be implemented in Germany. However, we are already supporting companies in assessing its potential impact on their value chains, drawing on our experience in advising on sustainability in the supply chain.
Discover more
We advise on sustainability in the supply chain – on human rights, CO2, biodiversity and resource conservation. Efficient strategies for companies.