Contributed By GvW Graf von Westphalen
Germany’s defence sector is primarily governed by the War Weapons Control Act (Kriegswaffenkontrollgesetz – KrWaffKontrG), which regulates the manufacture, acquisition, transfer, transport, import and export of war weapons and implements Article 26 of the German Basic Law (Grundgesetz– GG).
In addition, the Foreign Trade and Payments Act (Außenwirtschaftsgesetz – AWG) and the Foreign Trade and Payments Ordinance (Außenwirtschaftsverordnung – AWV) form the core export-control framework for military and dual-use items. The EU Dual-Use Regulation (EU) 2021/821 also applies directly in Germany and governs exports of dual-use goods and technologies.
Secondary legislation includes the Second Ordinance Implementing the War Weapons Control Act and the Ordinance on General Licences under the War Weapons Control Act, which establish licensing procedures and general authorisations.
Defence procurement is regulated through Germany’s public procurement framework, particularly the Act Against Restraints of Competition (Gesetz gegen Wettbewerbsbeschränkungen – GWB, or “Competition Act”) and related procurement regulations implementing EU defence procurement rules.
Key regulatory authorities are the Federal Ministry for Economic Affairs and Energy (BMWE, formerly BMWK) and the Federal Office for Economic Affairs and Export Control (BAFA).
In Germany, the Federal Ministry for Economic Affairs and Energy oversees defence export controls and foreign investment screening, while the Federal Office for Economic Affairs and Export Control acts as the main licensing and enforcement authority for exports of military and dual-use goods and sanctions-related trade restrictions.
The Federal Ministry of Defence (BMVg) is responsible for defence policy and military capability planning, and its procurement agencies, BAAINBw (responsible for services and goods) and BAIUDBw (responsible for infrastructure), manage defence procurement and equipment acquisition.
The Federal Foreign Office (AA) advises on foreign-policy and security considerations, while the German Customs Administration (Zoll) enforces export-control and sanctions rules at the border.
These bodies co-operate closely, particularly on export licensing, sanctions implementation and foreign investment reviews involving national security interests.
For German export-control and defence regulations, military (defence) goods are generally defined as the items listed in Part I, Section A of the Export List (Ausfuhrliste) and, for the most sensitive categories, as “war weapons” (Kriegswaffen) under the War Weapons Control Act. These include weapons, ammunition, military equipment, military software and technology, as well as related components and accessories.
Dual-use items are goods, software or technology that can be used for both civilian and military purposes. Examples include certain chemicals, electronics, machine tools, telecommunications equipment and related technology. Their regulation is primarily governed by the EU Dual-Use Regulation, which applies directly in Germany.
The key distinction is that military goods are specifically designed or listed for military use, whereas dual-use items have legitimate civilian applications but may also contribute to military capabilities or weapons programmes. Military items are generally controlled under the Export List and war-weapons legislation, while dual-use items are controlled under the EU Dual-Use Regulation and related provisions of the Foreign Trade and Payments Act and Foreign Trade and Payments Ordinance.
Germany’s defence regulatory framework is closely aligned with and implements a range of international and supranational obligations. Export-control rules under the Foreign Trade and Payments Act, the Foreign Trade and Payments Ordinance and the EU Dual-Use Regulation directly implement EU requirements and reflect commitments arising from international export-control regimes.
Germany also participates in the Wassenaar Arrangement. Its controls on military and dual-use goods are based on internationally agreed control lists and standards developed through that framework and other multilateral export-control regimes.
In addition, Germany implements UN Security Council sanctions and arms embargoes as well as EU sanctions measures through its national export-control system. The Federal Office for Economic Affairs and Export Control expressly notes that German export controls are designed to give effect to binding international obligations and decisions.
As an EU and NATO member, Germany’s defence procurement and security framework is also shaped by EU defence procurement legislation and broader NATO commitments, although NATO obligations are generally implemented through national policy and defence planning rather than specific export-control statutes.
Overall, German defence regulation is heavily influenced by international and European frameworks, with domestic legislation serving largely as the mechanism through which those obligations are implemented and enforced.
Germany maintains a dedicated procurement regime for defence and sensitive security contracts, principally governed by Part 4 of the Competition Act, the Ordinance on the Award of Public Contracts in the Defence and Security Sectors (VSVgV) and, for construction works, the Construction Contract Procedures for defence and security (VOB/A-VS) – implementing the relevant EU Directives. The regime covers military and classified equipment, related supplies, works and services across the full life cycle, from development and acquisition to maintenance, upgrades and in-service support.
The regime has now been supplemented by the Bundeswehr Procurement Acceleration Act (Bundeswehrbeschaffungsbeschleunigungsgesetz – BwBBG), which entered into force on 1 July 2026 and introduces temporary procedural flexibilities for the requirements of the German Armed Forces (Bundeswehr), including streamlined market consultations, innovation-oriented specifications and co-operative procurement.
Specific exemptions apply to intelligence activities, qualifying multinational programmes, certain government-to-government contracts and specified R&D services. Section 107(2) of the Competition Act, together with Article 346 of the Treaty on the Functioning of the European Union (TFEU), permits procurement rules to be disapplied where necessary to protect an essential security interest.
Article 346, TFEU is not a general defence exemption. It must be interpreted strictly: the contracting authority must identify the security interest at stake and demonstrate that restricting competition is necessary and proportionate. Equipment must fall within the 1958 Council list and, where dual-use applications exist, must have been specifically designed for military purposes (CJEU, Insinööritoimisto InsTiimi, C-615/10; Commission v Poland, C-601/21). Recent jurisprudence recognises that preserving security-relevant industrial core capabilities may constitute an essential security interest, provided a procurement-specific connection and the necessity of excluding competition are demonstrated (OLG Düsseldorf, VII-Verg 22/23; Finnish Supreme Administrative Court, KHO 4.2.2026/259).
Competition remains important, not merely as a procedural requirement but as an instrument for innovation, industrial capacity and best value for money.
The regime applies to all public contracting authorities and contracting entities within the meaning of Sections 99 and 100 of the Competition Act – not only the Federal Ministry of Defence and BAAINBw and BAIUDBw, but also other federal and state authorities, publicly controlled entities and central purchasing organisations. BAAINBw is responsible for the development, acquisition and in-service support of military equipment and IT; BAIUDBw handles infrastructure.
The Bundeswehr Procurement Acceleration Act extends to German Armed Forces requirements procured by the Federal Ministry of Defence, subordinate authorities and a broader group of federal, state and publicly controlled bodies, including procurement for the armed forces of other EU or EEA states.
Private defence companies are not themselves subject to procurement law as prime contractors. However, prime contracts may impose subcontracting, security, supply-chain or nationality requirements akin to a “procurement light procedure”.
In multinational programmes, procurement may be organised through a lead nation, the Organisation for Joint Armament Cooperation (OCCAR) or another international organisation. The governance structure should allocate responsibility for capability definition, security classification, procurement decisions, evaluation and contract management from the outset.
The specialised regime covers supply, service and works contracts. Supplies include weapon systems, platforms, ammunition, sensors, secure communications, military software and related components. Services encompass R&D, systems integration, testing, training, maintenance, logistics and in-service support. Works contracts may cover bases, airfields, secure data centres, ammunition storage and other military or classified infrastructure. The decisive factor is the subject matter, not merely the identity of the German Armed Forces as end user; general commercial products remain subject to the standard procurement regime.
For 2026/2027, the EU thresholds are EUR432,000 for defence and security supply and service contracts, and EUR5,404,000 for works contracts (excluding VAT). The estimated value must include foreseeable options, extensions, framework call-offs and life cycle elements. Requirements may not be divided to avoid thresholds.
Mixed contracts require an objective assessment of separability. Certain R&D services and qualifying multinational development programmes may be exempt; fully funded proprietary development for a single authority generally remains subject to procurement law unless another exemption applies.
Below the EU thresholds, federal or state budgetary procurement rules apply, subject to specific provisions of the Bundeswehr Procurement Acceleration Act. For long-term capability programmes, valuation should reflect the intended contract architecture, including development, production, training, spares, upgrades and in-service support.
Classification does not automatically remove a procurement from the Competition Act or the Ordinance on the Award of Public Contracts in the Defence and Security Sectors. Reliance on Article 346, TFEU requires a separate assessment of whether less restrictive measures can protect the relevant security interest.
Procurement documents must specify applicable security requirements. Depending on classification level, bidders and relevant subcontractors may need facility and personnel security clearances, secure premises, accredited IT systems and procedures for handling classified material. The Security Clearance Act, the Federal Classified Information Directive and the industrial security framework apply alongside procurement law; clearance timelines should be reflected in the procurement timetable.
A staged information model can preserve competition: authorities may publish an unclassified functional description, disclose detailed information only to pre-qualified and cleared candidates, and use secure data rooms or classified annexes. All remaining tenderers must receive equivalent information at equivalent stages.
Security obligations should extend to consortium members and critical subcontractors accessing protected information. Contracts should address personnel changes, cybersecurity incidents, foreign ownership changes and post-contract handling of classified material.
Over-classification may unnecessarily reduce the supplier base and reinforce incumbent dependency. Authorities should assess whether redaction, staged disclosure or contractual confidentiality can provide sufficient protection.
Under the Ordinance on the Award of Public Contracts in the Defence and Security Sectors, both the restricted procedure and the negotiated procedure with prior publication are available as standard procedures – unlike the general regime, no exceptional circumstances are required for a negotiated procedure with competition.
The negotiated procedure is particularly suited to complex defence acquisitions, allowing technical solutions, delivery models, security of supply, IP rights, life cycle support, risk allocation and pricing to be refined through structured negotiations. The authority must identify non-negotiable minimum requirements, disclose award criteria and ensure equal treatment throughout. A robust process typically includes an initial tender, defined negotiation rounds, equal information protocols and a clearly identified final-tender stage.
Competitive dialogue may be appropriate where the authority cannot objectively determine the technical, legal or financial solution. The Bundeswehr Procurement Acceleration Act also facilitates innovation partnerships, preliminary market consultations, functional specifications and design competitions.
Functional requirements can open the market to alternative solutions and dual-use technologies, but must be sufficiently precise to produce comparable tenders.
Early market engagement is critical in concentrated markets – testing available products, development needs, production capacity, IP constraints, export control dependencies and opportunities for non-traditional suppliers. Open interfaces and interoperability standards can reduce vendor lock-in.
The temporary relaxation of the lotting principle provides greater freedom for integrated capability contracts. A single overall award may accelerate delivery, but competing prototypes, separate capability increments or independently procurable interfaces may better preserve innovation and future competition.
Direct awards and negotiated procedures without prior publication are permissible only in defined exceptional circumstances, including unsuccessful prior competition, technical or IP exclusivity, crisis-related urgency, compatibility-dependent additional deliveries and specified R&D requirements. Government-to-government contracts, multinational programmes and Article 346, TFEU procurements may fall outside the ordinary regime where their statutory conditions are met.
The Bundeswehr Procurement Acceleration Act permits interim awards where competitive timelines cannot be observed for compelling reasons of urgency, limited to the indispensable bridging requirement pending a competitive procurement. Single-source justifications must be supported by a contemporaneous market analysis demonstrating why only one supplier can satisfy the requirement and why reasonable alternatives are unavailable. Interoperability with German or allied forces may justify technical exclusivity, but only where the relevant standard cannot reasonably be achieved through adaptation.
Public pricing law is particularly important where competition is absent. Regulation PR No 30/53 gives priority to market prices; cost-based pricing under the Principles for Determining Prices on the Basis of Costs is exceptional. Procurement law and pricing law perform different functions: a lawful direct award does not establish that the proposed price is permissible, and a compliant cost-based price does not validate an unlawful award.
For complex programmes, authorities should supplement the statutory framework with robust cost-transparency and incentive mechanisms. Pricing law is an important safeguard, but not a substitute for competition or effective contractual incentives.
Germany does not operate a general statutory offset regime. Requirements compelling foreign contractors to place orders, transfer technology or invest locally for economic-policy reasons may conflict with EU law. A distinction must be drawn between economic offsets and requirements necessary to protect an essential security interest – obligations concerning technical data, source code, maintenance capacity, critical spares or independent modification rights may be lawful where objectively required for operational autonomy or security of supply.
The Bundeswehr Procurement Acceleration Act permits participation to be restricted to qualifying EU, EEA or treaty-covered operators and allows requirements concerning EU origin. When weapons, ammunition and war material are procured, European technological sovereignty and production capacity must be considered. Separate government guidelines on compensation arrangements for armament purchases outside EU procurement law are expected in 2026.
Sovereign capability requirements should be expressed as verifiable operational criteria – functioning as minimum technical requirements, suitability criteria, award criteria or contractual performance conditions. Typical subjects include European maintenance capacity, access to technical data, control over cryptographic components, independent upgrade capability, surge production and protection against critical third-country dependencies.
European instruments increasingly incentivise co-operative procurement and investment in the European Defence Technological and Industrial Base. Joint programmes can aggregate demand, improve interoperability and reduce fragmented national procurement. Work-share arrangements should not, however, replace transparent capability-based allocation unless a specific legal exemption applies.
Security of supply is a central element of German defence procurement. The Ordinance on the Award of Public Contracts in the Defence and Security Sectors permits authorities to require information and commitments concerning export licences, supply chain organisation, production locations, crisis capacity and long-term support. The Bundeswehr Procurement Acceleration Act gives additional weight to production capacity for weapons, ammunition and war material in Germany, the EU and the NATO area.
Requirements should reflect actual failure scenarios, such as single-source dependency, export restrictions, raw-material shortages, cyber incidents, insolvency, geopolitical disruption or competing allied demand. Suitable measures include minimum stocks, reserved production slots, dual sourcing, defined replenishment periods, surge-capacity options, obsolescence management and transparency down to critical supply-chain tiers.
Authorities should distinguish between current suitability requirements, qualitative award advantages and future contractual obligations. Broad assurances of reliability provide little protection if they cannot be measured or enforced. A contractor cannot normally guarantee sovereign export-licence decisions, but the contract may require diligent licensing efforts, early risk notification and agreed mitigation measures.
Mission-critical contracts should include reporting, audit and change-control rights, continuity testing, transition assistance and, where appropriate, access to technical data, tooling or source code if the contractor can no longer provide support.
Security of supply must be assessed over the entire life cycle. A low acquisition price may represent poor value where it creates long-term operational dependency.
Defence contracts are awarded to the most economically advantageous tender on the basis of the best price-quality ratio. Permissible criteria include technical merit, operational fitness, interoperability, life cycle costs, delivery, technical support, security of supply and other capability-related factors.
The mandatory and discretionary exclusion grounds under Sections 123 and 124 of the Competition Act apply, covering criminal offences, tax violations, insolvency, professional misconduct, anti-competitive conduct and misrepresentation. Defence procurement adds a security-based ground: an undertaking may be excluded where it lacks the trustworthiness necessary to rule out risks to national security – a decision which must be evidence-based, project-specific and proportionate. Foreign ownership alone is not automatically sufficient, although it may be relevant to security clearance or export control.
EU sanctions and export control restrictions may independently prohibit an award or make performance legally impossible; these issues require separate analysis.
The Bundeswehr Procurement Acceleration Act permits participation to be restricted to qualifying EU, EEA or treaty-covered operators. Procurement documents should state clearly how these requirements apply to consortium members and key subcontractors.
Where self-cleaning is available, the authority must assess whether compensation, co-operation and compliance measures adequately address the misconduct. If classified information supports an exclusion, the authority should communicate the essential grounds without compromising security and maintain a complete confidential record for review proceedings.
Defence procurement remains subject to competition, equal treatment, transparency and documentation unless a specific exemption applies. Information may be withheld where disclosure would conflict with defence or security interests, harm legitimate commercial interests or prejudice fair competition – but exceptions should target the specific information concerned, not serve as a blanket restriction.
Unsuccessful tenderers must generally be informed of the intended contractor and the reasons for rejection. Security-sensitive details may be withheld, but the remaining explanation must enable the tenderer to understand the essential basis of the decision.
Commercial confidentiality must be protected alongside classified information. Technical solutions, cost structures, manufacturing methods and IP may constitute trade secrets. For highly sensitive projects, maintaining a complete classified procurement record alongside a separate disclosure version is advisable – the full record must still document the market assessment, security analysis, procedural choice, evaluation and pricing assessment.
A voluntary ex ante transparency notice may reduce the risk of contract ineffectiveness in a direct award, but only where the underlying legal justification is defensible. It is not a substitute for a lawful single-source decision.
Post-award modifications are governed by Section 132 of the Competition Act. A new procurement is required where a modification materially changes the original contract. Modifications without a new procedure are permissible where covered by clear review clauses, necessary additional requirements, unforeseeable circumstances, permitted contractor substitutions or applicable de minimis limits. The Bundeswehr Procurement Acceleration Act provides additional flexibility for defence-crisis-related circumstances.
Given long defence life cycles, the original contract should contain a robust change architecture – covering quantity options, capability increments, software releases, cybersecurity requirements, obsolescence, surge quantities and price adjustments. Scope, conditions and pricing mechanisms must be sufficiently clear for tenderers to assess their economic impact at the award stage.
German procurement law provides specific termination rights for serious procurement infringements, but no universal statutory right to terminate for convenience; such a right must arise from the contract or applicable general law. Mission-critical contracts should address transition support, handover of data and tooling, access to source code and continuity of spare-parts supply.
Above EU thresholds, an undertaking may seek review if it has an interest in the contract, alleges a procurement-law infringement and demonstrates actual or potential loss. Recognised infringements must be raised promptly; defects apparent from the notice or procurement documents must be challenged before the relevant deadline.
For procurements under the Bundeswehr Procurement Acceleration Act, the Federal Procurement Chamber has exclusive first-instance jurisdiction, with appeal to the competent Higher Regional Court. The Bundeswehr Procurement Acceleration Act and general rules of the Competition Act give substantial weight to defence and security interests when determining whether an award may proceed during review.
Pre-award remedies include correction of the procedure, repetition of an evaluation and prohibition of the intended award. Once a valid contract is concluded, review will generally not set it aside, although declaratory relief and damages may remain available. A contract may be declared ineffective following an unlawful direct award or breach of the standstill rules; the tribunal may preserve it where compelling defence or security interests justify doing so.
National security considerations do not remove procurement decisions from legal scrutiny. For authorities, the most effective protection is a contemporaneous, project-specific procurement record. For tenderers, objections must be prompt and precise. The 2026 reforms accelerate procurement partly by reducing the practical intensity of primary legal protection, making early legal risk assessment increasingly important.
German export controls are governed by the Foreign Trade and Payments Act, the Foreign Trade and Payments Ordinance, the EU Dual-Use Regulation and, for war weapons, the War Weapons Control Act.
Export restrictions may also arise from EU sanctions regulations and international obligations.
The Federal Office for Economic Affairs and Export Control is the competent licensing authority in Germany and is responsible for administering Germany’s export control regime. Customs authorities are primarily responsible for monitoring and enforcement.
Germany applies separate control lists for military and dual-use items. Military items are primarily listed in Part I Section A of the Export List annexed to the Foreign Trade and Payments Ordinance, while dual-use items are listed in Annex I to the EU Dual-Use Regulation.
The lists are regularly updated to reflect changes agreed within the major international export control regimes, including the Wassenaar Arrangement, the Missile Technology Control Regime, and those of the Australia Group and the Nuclear Suppliers Group. Germany also applies catch-all controls, under which non-listed items may become subject to licensing requirements depending on their end use, end user or destination.
Depending on the item, destination, end user and end use, exports may require an individual licence (including a maximum value licence), a global licence or the use of a general authorisation. A general authorisation is always applicable if the respective conditions are met. An application is not necessary. Individual licences remain the most common form of authorisation for sensitive military and dual-use exports that have to be applied for, whereas the global licence is rather rare due to its significant conditions that have to be fulfilled.
Licensing requirements may also apply to brokering services, technical assistance, transit activities and transfers of controlled technology, including intangible technology transfers.
Applications for export licences are generally submitted electronically to the Federal Office for Economic Affairs and Export Control, which is responsible for reviewing and deciding applications. The information required depends on the transaction but typically includes details of the goods, their classification, the end user, the destination country and the intended end use. Supporting documentation commonly includes technical product descriptions and end-user certificates.
Processing times vary considerably depending on the sensitivity of the goods, the destination and any interagency consultations required. Straightforward dual-use applications may be processed relatively quickly, whereas applications involving military equipment or sensitive destinations can take significantly longer.
For general authorisations, a formal application is not necessary. The authorisation is generally granted if the conditions are met.
The Federal Office for Economic Affairs and Export Control assesses licence applications on a case-by-case basis, taking into account Germany’s foreign policy, security and international commitments. Particular attention is paid to the end user, end use and destination country.
For military items, authorities consider factors such as regional stability, conflict risks and human rights concerns. For dual-use items, the assessment focuses on the risk of military diversion, proliferation activities or prohibited end uses. Applications may also be affected by applicable sanctions or arms embargoes.
For a global licence, the applicant usually has to establish a compliance system to be monitored by the Federal Office for Economic Affairs and Export Control.
Exporters are often required to obtain end-user certificates or comparable end-use assurances as part of the licensing process. Sample declarations are available from the Federal Office for Economic Affairs and Export Control. There are personal end-user certificates available, to be completed by the recipient, and international import certificates, completed by the state of the recipient. The level of documentation required depends on the goods, destination and risk profile of the transaction.
German authorities expect exporters to conduct appropriate due diligence regarding end users and intended end uses. While German authorities can participate in end-use verification measures and international monitoring arrangements, such as post-shipment controls, this is not expected from the exporters. The exporters remain responsible for identifying red flags and complying with licence conditions throughout the transaction.
Brokering activities involving certain military and dual-use items are subject to control under both the Foreign Trade and Payments Act/Foreign Trade and Payments Ordinance and the EU Dual-Use Regulation. Licensing requirements may apply even where the goods do not physically enter Germany.
The scope of control generally covers arranging or facilitating transactions between third countries involving controlled items. Whether authorisation is required depends on the type of goods, the parties involved and the destination.
Germany does not provide a general exemption for intra-group transfers. Transfers of controlled goods, software or technology within a corporate group must be assessed under the same export control rules as those applicable to third-party transactions.
Certain simplifications may be available through general or global licences, particularly within the EU. However, transfers of controlled technology to affiliated entities outside Germany frequently require a separate licensing assessment.
Violations of German export control laws may result in significant criminal and administrative penalties. Serious infringements can lead to substantial fines and imprisonment, particularly in cases involving intentional conduct or exports to embargoed destinations.
The Federal Office for Economic Affairs and Export Control, customs authorities and public prosecutors play key roles in enforcement.
Although German law does not provide a formal voluntary disclosure programme equivalent to certain US regimes, voluntary self-disclosures and co-operation with authorities may be taken into account in certain cases.
As an EU member state, Germany primarily implements sanctions through directly applicable EU regulations adopted under the Common Foreign and Security Policy. These measures are supplemented by the Foreign Trade and Payments Act and the Foreign Trade and Payments Ordinance, which provide the national framework for enforcement and penalties.
Germany also implements sanctions adopted by the UN through EU legislation.
US sanctions, including those administered by the Office of Foreign Assets Control, do not generally have direct legal effect in Germany but may create significant commercial and compliance risks for German companies with a US nexus.
The Federal Office for Economic Affairs and Export Control, customs authorities, the Federal Bank of Germany (Deutsche Bundesbank) and criminal enforcement authorities all play important roles in sanctions administration and enforcement.
Germany implements arms embargoes adopted by the UN and the EU. These measures are typically incorporated into EU sanctions regulations and are directly applicable in Germany.
A national arms embargo is also set out in Section 74 of the Foreign Trade and Payments Ordinance.
Arms embargoes generally prohibit the sale, export, transfer or brokering of military goods and related services involving designated countries, entities or persons. Certain exceptions may be available in limited circumstances, including humanitarian activities, international missions or other cases expressly authorised under the relevant sanctions regime.
There is no official single statutory screening methodology, but best practice (not only in the defence sector) is to screen customers, suppliers, intermediaries and other business partners including employees every 24 hours against all applicable sanctions lists.
Regulators expect companies to assess both direct counterparties and ownership and control structures to avoid the provision of benefits to sanctioned parties indirectly. In practice, ongoing screening and periodic re-screening form part of standard compliance expectations, particularly in higher-risk jurisdictions and sectors.
Many EU sanctions regulations contain licensing grounds, derogations and exceptions that allow specific activities which would otherwise be prohibited.
Where available, applications are generally submitted to the Federal Office for Economic Affairs and Export Control or another designated competent authority identified in the relevant sanctions regulation. Applicants must demonstrate that the conditions for the relevant derogation are met and provide supporting information regarding the transaction, counterparties and intended purpose.
With respect to payments, the Federal Bank of Germany is the competent authority.
Germany does not generally accept the direct application of foreign sanctions laws, including US secondary sanctions. Within the EU, the Blocking Regulation seeks to counter the extraterritorial application of certain US sanctions measures.
Nevertheless, US sanctions can have significant practical consequences for defence sector participants through financial, contractual and supply chain relationships. Companies with US business exposure and nexus should therefore assess secondary sanctions risks as part of broader compliance and risk management processes.
An effective sanctions compliance programme should be risk-based and tailored to the company’s business activities, products and geographic footprint.
Core elements typically include:
Although German authorities do not prescribe a single compliance model, the Federal Office for Economic Affairs and Export Control has published guidance promoting Internal Compliance Programmes and robust export control compliance structures.
Breaches of sanctions regulations may result in administrative fines or criminal penalties under the Foreign Trade and Payments Act. The severity of enforcement action depends on factors such as intent, the nature of the violation, the compliance measures in place and the degree of co-operation with authorities.
Investigations are typically conducted by customs authorities and public prosecutors, often in co-ordination with the Federal Office for Economic Affairs and Export Control. Voluntary disclosures are not governed by a dedicated sanctions disclosure regime. Whether a self-reporting and co-operation with authorities may be considered helpful has to be assessed on a case-by-case basis.
The most significant developments in recent years continue to relate to the extensive EU sanctions regimes targeting Russia and Belarus. These measures have increased compliance expectations for defence companies and have led to heightened enforcement activity focusing on circumvention, intermediary jurisdictions and export control evasion.
Businesses are facing increased scrutiny regarding supply chains, end users and the potential diversion of controlled goods and technologies. Consequently, sanctions and export control compliance remain a major enforcement priority for German authorities.
Germany’s defence sector is mainly regulated by the Foreign Trade and Payments Act, the Foreign Trade and Payments Ordinance, the War Weapons Control Act, foreign investment screening rules and cybersecurity legislation (Act on the Federal Office for Information Security (Gesetz über das Bundesamt für Sicherheit in der Informationstechnik – BSIG, or “BSI Act”)). These laws govern exports of military and dual-use goods, sanctions compliance, foreign acquisitions of defence businesses, cybersecurity obligations, and the manufacture, transfer and possession of war weapons.
Key authorities include the Federal Ministry for Economic Affairs and Energy, which oversees trade controls and investment screening; the Federal Office for Economic Affairs and Export Control, which issues export licences and enforces export control rules; the Federal Ministry of Defence; the Federal Office for Information Security (BSI), responsible for cybersecurity oversight; and the German Customs Administration, which enforces export-control and sanctions laws at the border.
Access to classified information in Germany’s defence sector is governed by the Security Clearance Act (Sicherheitsüberprüfungsgesetz – SÜG) and related regulations. Individuals, including employees and contractors, must undergo security vetting, with different clearance levels depending on the sensitivity of the information. Vetting may include background checks, criminal record reviews and reliability assessments.
Defence contractors involved in classified projects may also require facility security clearances, demonstrating adequate physical, organisational and information security measures.
Security clearances are granted by the competent federal authority, with assessments conducted by the Federal Office for the Protection of the Constitution (BfV) or, for military matters, the Military Counterintelligence Service (MAD). The process includes consent, security questionnaires, background investigations and periodic reviews. Clearances may be revoked if security concerns arise.
In Germany, classified information is regulated by the Security Clearance Act and the Classified Information Instructions (VSA). Access is granted only on a need-to-know basis and generally requires an appropriate security clearance.
Defence contractors working on classified projects must implement adequate physical, organisational and IT security measures. Their personnel may be required to undergo security vetting before accessing classified information.
The Federal Office for the Protection of the Constitution and the Military Counterintelligence Service support security assessments and oversight.
Unauthorised disclosure of classified information can lead to administrative, civil and criminal penalties.
Germany designates certain defence-related facilities, information systems and suppliers as part of its critical infrastructure (Kritische Infrastrukturen) framework, particularly where their disruption could affect national security, military readiness or essential government functions. The framework is primarily based on the BSI Act and related regulations.
Entities classified as critical infrastructure are subject to additional obligations, including:
In some cases, scrutiny under Germany’s foreign investment screening regime is heightened, particularly for defence and security-related companies.
Oversight is primarily exercised by the Federal Office for Information Security, while the Federal Ministry for Economic Affairs and Energy may review foreign acquisitions involving defence-related or other security-sensitive assets.
Germany has no defence-sector-wide cybersecurity certification equivalent to the US Cybersecurity Maturity Model Certification. Requirements instead depend on the contract, classification level and whether the contractor is subject to the BSI Act implementing NIS-2. Contractors handling classified information are subject to the applicable requirements under the Security Clearance Act, the Classified Information Instructions, the Manual on the Safeguarding of Classified Information (GHB) and relevant contractual security instructions. For VS-NfD, the lowest of the four classification levels, this generally entails contractual security instructions, need-to-know access, staff instruction and technical safeguards. The VS-Vertraulich classification or higher normally requires the contractor to participate in the federal industrial-security procedure, obtain the necessary personnel clearances and implement approved physical and IT security arrangements. Entities covered by the BSI Act must also implement proportionate cybersecurity risk-management and incident-reporting measures. Procurement authorities may impose additional requirements, including ISO/IEC 27001, BSI IT-Grundschutz, vulnerability reporting, audits and supply chain controls.
Germany has no single defence-sector-wide supply-chain security regime or general list of prohibited countries or suppliers. Requirements arise mainly from defence procurement law, classified-information rules, the BSI Act and contract-specific provisions. Under the Ordinance on the Award of Public Contracts in the Defence and Security Sectors, authorities may require evidence that a bidder’s supply chain ensures security of supply, including crisis capacity, maintenance and notification of material changes. Classified contracts require security obligations to be passed to subcontractors. Since 14 February 2026, the Bundeswehr Procurement Acceleration Act has also permitted certain procurements to restrict participation by bidders and subcontractors or require supplies to originate from the EU or equivalent states. Additional contractual measures may include supplier transparency, traceability, control of component changes, software updates, audits and continuity planning. Non-compliance can result in exclusion, contractual remedies, termination, loss of security clearance or regulatory action.
Germany imposes specific security obligations on defence companies and personnel to protect against espionage, sabotage and insider threats. These obligations arise primarily under the Security Clearance Act, classified information regulations, and cybersecurity laws applicable to defence contractors and critical infrastructure operators.
Defence contractors must:
Security assessments and counterintelligence functions are carried out principally by the Military Counterintelligence Service in the defence sector and the Federal Office for the Protection of the Constitution. These authorities may investigate security concerns and recommend suspension or revocation of clearances.
Where a security incident, attempted espionage, cybersecurity breach or compromise of classified information is suspected or detected, contractors are generally required to promptly report the incident to the relevant contracting authority and, where applicable, the competent security or cybersecurity authorities. Operators of critical infrastructure may also have mandatory cyber incident reporting obligations to the Federal Office for Information Security.
Germany addresses risks arising from foreign ownership, control or influence primarily through its foreign investment screening regime under the Foreign Trade and Payments Act and the Foreign Trade and Payments Ordinance. The Federal Government may review acquisitions of German defence companies by foreign investors and prohibit, restrict or approve transactions subject to conditions where national security concerns are identified.
Unlike some jurisdictions, Germany generally does not rely on mechanisms such as special security agreements, proxy boards or government-appointed security directors. Instead, risks are addressed through the investment review process itself.
In practice, the Federal Ministry for Economic Affairs and Energy may:
Accordingly, Germany’s approach focuses on government screening and intervention in foreign investments, rather than ongoing ownership-control arrangements such as proxy boards or security directors.
No information has been provided for this section.
Germany’s foreign direct investment (FDI) screening is governed by the Foreign Trade and Payments Act and the Foreign Trade and Payments Ordinance. The competent authority is the Federal Ministry for Economic Affairs and Energy, acting in consultation with other federal ministries.
Two regimes are relevant for defence-related transactions.
Both share deals and qualifying asset deals are in scope, covering direct and indirect acquisitions throughout the entire shareholder chain. The applicable voting rights thresholds are:
Incremental acquisitions crossing further statutory thresholds (varying by category, eg, 20/25/40/50/75% for Nos 1–7) and atypical acquisitions granting additional control also trigger notification.
Notification is mandatory for defence sector transactions under both the sector-specific and, where applicable, cross-sectoral regimes. In these cases, the transaction must not be closed prior to clearance.
Where notification is mandatory, the transaction is provisionally invalid until clearance is granted. Pending clearance, exercising acquired voting rights or exchanging sensitive information with the acquirer is prohibited. Violations of these prohibitions constitute criminal offences punishable by imprisonment of up to five years or substantial fines.
Where no listed sector is involved, filing is voluntary, but the Federal Ministry for Economic Affairs and Energy may review transaction ex officio within five years.
The review follows a two-phase structure. Phase 1 serves as an initial screening to determine whether the transaction raises concerns that warrant closer examination. If concerns are identified, the authority opens a Phase 2 in-depth investigation. The same timetable applies to both sector-specific and cross-sectoral proceedings. The information to be provided includes transaction and ownership details as well as information on the activities of the target. More in-depth information may be requested in Phase 2.
Until clearance has been granted by the Federal Ministry for Economic Affairs and Energy, the completion of the acquisition is provisionally invalid where a notification was mandatory.
The sector-specific test examines whether the investment is likely to affect the essential security interests of Germany. The cross-sectoral test asks whether the public order or security of Germany, another EU member state or projects of EU interest may be impaired.
Under both regimes, investor-related factors are also assessed, including whether the acquirer is directly or indirectly controlled by a foreign government, whether it has previously been involved in activities affecting security or public order, and whether there is a risk of involvement in criminal activities.
The Federal Ministry of Defence provides an advisory assessment in defence-related cases focusing on:
Where the Federal Ministry for Economic Affairs and Energy concludes that a transaction threatens Germany’s essential security interests or public order and security, it may issue directives or impose conditions on the acquisition. Conditions can include behavioural commitments such as continued supply obligations, know-how protection mechanisms or information security arrangements.
Prohibition is available as a last resort and requires the approval of the entire Federal Government, underscoring its exceptional character. Transactions that were completed without required clearance can also be unwound retroactively. The Ministry’s decisions are subject to judicial review before the Administrative Court of Berlin.
Germany does not generally employ “golden shares” or similar permanent special shareholder rights in defence companies. Unlike some jurisdictions, the German government does not typically retain special voting rights, veto rights or government-appointed directors simply by virtue of a state-held golden share.
Instead, Germany protects national security interests through its foreign investment screening regime under the Foreign Trade and Payments Act and the Foreign Trade and Payments Ordinance. The Federal Government may review acquisitions of defence and security-related companies by foreign investors and may prohibit transactions or approve them subject to conditions where national security concerns arise.
While Germany does not have a separate legal regime specifically governing defence joint ventures, transactions involving defence companies are subject to the foreign investment screening regime under the Foreign Trade and Payments Act and the Foreign Trade and Payments Ordinance. Joint ventures involving foreign partners may be reviewed where they could result in access to sensitive defence technologies, know-how or security-relevant capabilities. The Federal Government may impose conditions or prohibit a transaction if it poses a risk to public order or national security.
In addition, defence joint ventures must comply with:
Technology transfer and IP issues are typically addressed by contract.
Under German law, FDI/national security screening, administered by the Federal Ministry for Economic Affairs and Energy, and merger control, administered by the Federal Cartel Office (BKartA), are legally distinct, parallel regimes. Both may apply simultaneously to a defence sector transaction, and clearance under one does not substitute for clearance under the other. There is no formal statutory co-ordination mechanism between the two authorities, although informal co-ordination occurs in practice. In practice, the Federal Cartel Office has recently assessed several defence-related transactions and granted clearances factoring in the characteristics of the sector.
National security considerations can override competition law outcomes through a ministerial authorisation: where the Federal Cartel Office prohibits a merger, the Federal Minister may authorise it if the restraint of competition is outweighed by an overriding public interest, which may include defence and security interests. Conversely, an FDI prohibition can block a transaction that has been cleared on competition grounds. However, a ministerial authorisation is rare and does not override a separate FDI prohibition – it only applies to merger prohibitions by the Federal Cartel Office.
In Germany, responsibility for investigating potential breaches of defence-related regulations is shared among several authorities. The Federal Office for Economic Affairs and Export Control administers export controls, reviews licence applications, monitors compliance with licensing conditions, and investigates potential violations of export-control, sanctions and dual-use rules. The German Customs Administration enforces export-control and sanctions laws at the border and investigates suspected unauthorised exports, embargo breaches and related customs offences.
Where criminal or administrative misconduct is suspected, public prosecutors and law enforcement authorities may conduct formal investigations, including searches, seizures, interviews, and other measures available under German criminal procedure law.
In national-security-related foreign investment reviews, the Federal Ministry for Economic Affairs and Energy may investigate acquisitions of defence or security-sensitive businesses, request information, and impose conditions where concerns arise. In defence procurement, the Federal Ministry of Defence and its procurement agency, BAAINBw, oversee compliance and may refer suspected irregularities to the appropriate enforcement authorities.
Regulatory investigations in Germany’s defence sector are commonly triggered by suspected export-control, sanctions or procurement violations identified through customs checks, Federal Office for Economic Affairs and Export Control reviews, intelligence received from other authorities, licensing irregularities, internal reports, whistle-blower complaints, or referrals from domestic or foreign enforcement agencies. The Federal Office for Economic Affairs and Export Control works closely with customs and other investigative authorities as part of Germany’s export control enforcement system.
Investigations may also arise from routine compliance audits and inspections, as well as from information disclosed in the media or obtained during regulatory reviews.
German law imposes various mandatory reporting and record-keeping obligations on companies dealing with controlled military and dual-use goods, including licensing, notification and documentation requirements under export control legislation. Companies must provide accurate information to the authorities and comply with ongoing reporting obligations where applicable.
While voluntary self-disclosure is not generally required, companies often choose to report potential breaches proactively as part of their compliance and remediation efforts, particularly in the export control and sanctions context.
German authorities have broad investigative powers in defence and export-control matters. The Federal Office for Economic Affairs and Export Control, customs authorities and other agencies may require information and documents, inspect shipments, and investigate suspected export-control, sanctions or licensing violations.
Where administrative or criminal offences are suspected, prosecutors may compel document production, conduct interviews, search premises and seize evidence. In foreign-investment and national-security reviews, authorities may require detailed transaction information.
Asset-freezing measures are mainly imposed under EU and UN sanctions regimes. Classified information remains subject to strict security rules, with safeguards to protect sensitive data during investigations.
Under German law, defence sector entities may be subject to unannounced dawn raids by law enforcement authorities. In a criminal proceeding there must in general be a judicial warrant ordering the dawn-raid, but the requirements to obtain such judicial warrant are not very high. In practice, a judicial warrant is issued based on the suspicion that a crime was committed and if it is likely that the search will lead to the discovery of evidence. Natural as well as legal persons must tolerate the search. They have the right to contact and have a legal counsel present during the search. Companies should establish an internal procedure by which a legal counsel is informed immediately after a law enforcement authority has arrived.
Beyond criminal proceedings, some administrative authorities hold independent, preventive rights of entry into defence sector premises without a judicial warrant for purposes such as export control oversight, war-weapons inspections, weapons manufacturer supervision, general trade supervision and tax audits.
In addition, antitrust authorities (in particular, the Federal Cartel Office and the European Commission) can conduct dawn raids in case of suspected infringements of competition law, eg, price fixing or customer allocations. Overall, comparable principles as for criminal proceedings apply, but co-operation duties in competition proceedings are more extensive.
Germany recognises legal professional privilege and confidentiality through statutory secrecy obligations and procedural safeguards, which generally apply in defence sector investigations. Communications with external legal counsel are typically protected, and defence companies often involve lawyers in internal investigations and regulatory matters.
These protections are not absolute. Authorities may challenge privilege claims, particularly in cases involving espionage, unlawful arms exports, sanctions violations, terrorism or other national security concerns. Classified information also remains subject to applicable security rules, even when reviewed by legal advisers.
Accordingly, legal privilege is recognised in Germany but may be limited where criminal law or overriding national security interests are engaged.
Specified criminal convictions (including corruption, fraud, money laundering and terrorist financing) trigger mandatory exclusion under Section 123 of the Competition Act; regulatory breaches such as anti-competitive conduct or grave professional misconduct may trigger discretionary exclusion under Section 124. Germany does not maintain a centralised debarment register – each contracting authority assesses exclusion grounds on a project-specific basis. The exclusion period is generally up to five years for mandatory grounds and up to three years for discretionary grounds.
Self-cleaning is available under Section 125. The affected entity must demonstrate that it has paid or undertaken to pay compensation, co-operated with investigating authorities and implemented concrete organisational and personnel measures to prevent future misconduct. The contracting authority assesses the sufficiency of these measures in light of the gravity and circumstances of the offence. If self-cleaning is accepted, exclusion may not be imposed.
Defence-related disputes in Germany are generally resolved by civil courts (for contractual and commercial matters) or administrative courts (for government decisions, procurement awards, export licences and regulatory measures). Arbitration may be used where agreed by the parties, particularly in cross-border transactions, while mediation and other ADR mechanisms are less common.
Germany has no dedicated defence court system. Defence disputes are handled through the ordinary judicial system or arbitration. Where classified information or national security issues are involved, courts may apply special safeguards, such as restricted document access, confidentiality orders, closed hearings, and limits on disclosure of sensitive information. Government authorities may also refuse disclosure where national security interests are at risk.
The German Whistleblower Protection Act (HinSchG) provides a comprehensive framework for the protection of whistle-blowers; however, Section 5 of the Act (Vorrang von Sicherheitsinteressen sowie Verschwiegenheits- und Geheimhaltungspflichten) contains important exemptions for matters relating to defence and security. Protection is significantly restricted in the following areas.
For legal entities, Germany does not currently recognise corporate criminal liability as a separate concept. Instead, companies can be subject to substantial administrative fines under Sections 30 and 130 of the Administrative Offences Act (OWiG) where offences are committed by managers or where management fails to implement adequate supervisory measures.
The standard for corporate liability is therefore based on attribution: a company may be fined if a managerial person commits a criminal or regulatory offence that breaches the company’s duties or benefits the company, or if the offence was facilitated by inadequate compliance and supervision systems.
In the defence sector, this framework can apply to export control violations, sanctions breaches, bribery in procurement and related misconduct. Effective compliance programmes and remediation measures may be taken into account when determining the level of any corporate sanction.