Germany launches CyberGovSecure framework for federal cybersecurity
On 22 July 2026 the German federal cabinet approved a new cybersecurity governance programme for the entire federal administration, branded “CyberGovSecure”. The framework translates the EU NIS‑2 directive into a unified set of rules that will apply to all ministries, agencies and their IT devices.
A steering group comprising representatives of every ministry, chaired by the Federal Ministry for Digital Affairs, will set the overall course and work closely with the Federal Office for Information Security (BSI). The programme mandates uniform security standards for office computers, central servers, laptops and smartphones, introduces regular vulnerability scans, and requires multi‑factor authentication for sensitive systems. An annual budget of €500 million has been earmarked to fund the measures and to monitor progress.
Industry group Bitkom welcomed the move, with executive Susanne Dehmel stressing that the new governance is needed to close long‑standing security gaps and to make the federal IT landscape “actionable and accountable”. Digital Minister Karsten Wildberger and BSI President Claudia Plattner highlighted the rising threat environment and the need for coordinated, cross‑departmental protection.
The programme aims to strengthen the resilience of Germany’s public digital infrastructure against cybercrime and state‑sponsored attacks, and to restore confidence in democratic institutions.