A Legally Sound Path to the Future of Infrastructure

Between Innovation and Regulation

In the industrial landscape of the DACH region, three trends are emerging as part of a smart infrastructure agenda for the future: First, the deep, data-driven interconnection of production, process, automation, building, and supply chain assets, including real-time data flows; second, the shift of data-intensive analysis and intelligence to the edge, with AI-powered controls and digital twins; third, the industrialization and professionalization of data-based services—from pay-per-use and remote monitoring to data-driven maintenance and repair strategies. These trends are shifting value creation, development strategies, dependencies, and business-critical processes further toward software, data, and operations (X-as-a-Service). Processes, services are—and will increasingly be—interconnected and transmitted to central systems via IoT platforms, where they are (ideally) analyzed using appropriately implemented big data analytics, machine learning, or AI applications to identify patterns, deviations, or trends that indicate necessary adjustments or actions. As a result, issues of data access, data provision, interoperability, and cyber resilience are becoming core requirements for manufacturers and users. At the same time, the EU and its member states are strengthening the regulatory framework already established by the 2020 Digitalization and Data Strategy: the Data Act (Regulation (EU) 2023/2854), the NIS-2 Directive (Directive (EU) 2022/2555) and the Cyber Resilience Act (Regulation (EU) 2024/2847) set binding standards for data use and security throughout the entire product and system lifecycle—both for the company itself and for its customers. For companies on both sides of the market, this means that design, organization, contracts, and documentation must be brought into line with current regulatory frameworks—not as a compliance exercise, but as a design principle and guiding decision for the security of smart infrastructures.

Lucas Prandi

Lucas Prandi is an attorney and partner at the law firm beyond Rechtsanwälte in Leipzig. Together with his team, he primarily advises medium-sized and large companies, as well as the public sector, on IT law, data protection law, and public procurement law—specifically regarding the design of digital business models, complex IT system procurements, IT outsourcing projects, and the drafting and negotiation of contracts.

Do you have any questions? Attorney
Lucas Prandi will be happy to assist you: 

Email

Data Use – Value Creation & Regulation

The Data Act, serving as the “constitution of the data economy” for networked products and connected services, has been largely directly applicable since September 12, 2025; certain additional obligations, particularly design requirements, take effect on September 12, 2026. For smart infrastructures, the Data Act is a milestone. Data is already being referred to as the “new gold.” The use of and access to data are becoming increasingly important in smart—and in some cases even business-critical—infrastructures. The Data Act thus regulates, for the first time, the determination of rights of access, provision, and use of data collected by IoT products or services associated with them. For manufacturers of connected products (machines, sensors, building automation) and providers of connected services, this means:

Product and service data from the provided products and associated services—such as operating systems—must be made available to users by default: structured, machine-readable, in real time and continuously whenever possible, and including relevant metadata. Data should become tradable and usable; this is indispensable for data-driven process and automation solutions—for both the manufacturer and the user.
 

This effectively makes technical and contractual “access-by-design” a fundamental product feature of networked infrastructure. For B2B scenarios, the Data Act also establishes FRAND terms (fair, reasonable, non-discriminatory) and a black/gray list of unfair clauses for the terms governing data provision; as a result, the drafting of terms and conditions and the design of data-driven service models must be reimagined, and established procurement strategies must be reevaluated. The practical and legal implications are wide-ranging. While manufacturers of products and services should, among other things, provide a data inventory, technical export pathways (APIs, edge exports), authentication and licensing logic, and protection mechanisms for trade secrets to meet the requirements and legal claims arising from the Data Act, it is the users, on the other hand, who—when procuring, design, and implementation of smart infrastructures, consider access, usage, and provisioning requirements early on, establish them contractually, define them clearly, and control data usage. Through structured contract drafting and the procurement of systems and products, the “foundation” for proprietary data-driven services can be laid, enabling internal process optimization. The Data Act is the foundation for successfully creating value from data—not only for sales but also for a company’s own use of data to identify untapped potential.

Cybersecurity

In addition to regulating the data economy, the NIS 2 Directive—which was implemented in Germany on December 6, 2025, through the new BSI Act—aims to establish a uniform and high level of cybersecurity protection across Europe. The regulations are aimed in particular at operators of critical infrastructure or facilities in key sectors—ranging from energy, transportation, and manufacturing to digital infrastructure and industrial service providers. The NIS-2 Directive will require risk-based technical and organizational measures (including vulnerability and patch management, access control, cryptography, and supply chain security), as well as additional reporting and information obligations to authorities; it also establishes direct management responsibility, extending to personal sanctions, to manage risks to “information technology systems” —of any kind—with regard to the established protection objectives of integrity, confidentiality, and availability; to prevent or minimize the impact of security incidents on recipients of their services and on other services; and thereby to enhance cyber resilience in all sectors defined as systemically important.

Even “network and information systems” that are traditionally operated in isolation or on a proprietary basis will be subject to a uniform risk management and reporting regime, which in the future will 

beyond Rechtsanwälte maintains a
regular partnership with the
law firm schlatter.law in Heidelberg. 

also extends to dedicated supply chain management, so that even companies that do not fall directly within the personal and material scope of the NIS 2 Directive  will be required to implement and demonstrate appropriate technical, operational, and organizational measures to prevent or mitigate risks to the security of the network and information systems used or provided for the delivery of services. For companies that either fall within the scope of the NIS 2 Directive themselves or provide services to companies that operate critical infrastructure or have been classified as important or particularly important facilities, this means that they must exercise particular care from the outset—both when selecting smart infrastructure, the design of operational models, and the engagement of service providers. In addition to legal issues regarding liability and contract drafting, this also entails, at the technical and operational level, ensuring “audit readiness,” early asset discovery across IT/OT systems and domains, and, among other things, documented security measures for the acquisition, development, and maintenance of control technology and segmentation, as well as robust and effective incident response management. General technical and organizational measures—which are already state-of-the-art today—for securing information technology systems, particularly those connected to the Internet, such as multi-factor authentication, access and entry control concepts, etc., are no longer just optional extras in data protection management but have become mandatory requirements for information technology security—to protect both the company itself and its customers.

Cybersecurity by Design

The Cyber Resilience Act (CRA) supplements the NIS 2 Directive with specific transitional provisions effective December 11, 2027, at the product level: It makes “Security by Design/Default” a prerequisite for market access for all products with digital elements—from IoT devices and connected industrial equipment to software, including remotely provided manufacturer cloud functions. In the future, “products with digital elements” must comply with basic cybersecurity requirements—which have been regulated and made mandatory for the first time—so that, where applicable to the respective product, basic functionalities are intended to ensure a minimum level of cybersecurity. 

In practical terms, the CRA also requires manufacturers, among other things, to implement documented vulnerability management throughout the entire product lifecycle, coordinated vulnerability disclosure (CVD) processes, and timely security updates—as well as—expected to be specified through harmonized standards – the maintenance of a “Software Bill of Materials” to facilitate the identification of security vulnerabilities or weaknesses in the future. The CRA therefore has direct implications, in the context of the NIS 2 Directive, for the selection of products and other services, as well as for internal cybersecurity hygiene. The transparent reporting of vulnerabilities or security gaps obligates the affected companies—particularly if they fall under the direct or indirect scope of the NIS 2 Directive and, where applicable, also due to other existing contractual obligations—to handle this information appropriately and take necessary measures.

Viewing Regulation as an Opportunity and a Mandate

These legal acts are interlinked and give rise to implementation tasks in the areas of technology, organization, and contracts. They thus establish additional compliance requirements that have implications for procurement, 

The further development and maintenance of smart infrastructures; however, these requirements present both opportunities and challenges—depending on which side of the market is responsible. Existing or planned smart infrastructures have never been purely technological projects. They are comprehensive compliance projects involving increasing regulatory requirements, growing criticality for business processes and corporate success, as well as geopolitical developments and their impact on the security of technological, software-based, and networked infrastructure—all of which must be taken into account.
Those who design data architectures to be legally compliant from the outset—not just in terms of contract law— understands security and compliance as product quality, and maintains audit-ready documentation, transforms regulation into opportunities and a competitive advantage: as a more resilient partner in the supply chain, as a reliable partner for critical infrastructure, and with robust services—whether as a manufacturing company or a service provider. Regulatory requirements set the framework for this. Technical, operational, and legal implementation will determine the pace and success of the digital industry in the DACH region.