In response to the shifting geopolitical environment, Germany has substantially increased its defense spending. In addition to the €100 billion special fund established following Russia’s full-scale invasion of Ukraine in 2022, the German government has significantly expanded its annual defense budget from €82.7 billion in 2026 to €136.5 billion in 2028, with the goal of reaching defense spending equivalent to 3.5% of GDP. The German government has also announced measures to strengthen the domestic defense sector. For example, Germany has recently enhanced the framework for private investment in defense through public funding initiatives, regulatory adjustments, and expanded development-bank (KfW) financing. The “Germany Fund” (Deutschlandfonds), coordinated by KfW, is designed to mobilize approximately €130 billion in investment by leveraging €30 billion in public funds and guarantees. The German government has also emphasized the need for better financing conditions for the security and defense industry, citing growing willingness among private investors, financial institutions, and development banks to support the sector. In addition, KfW has explicitly opened its financing programs to defense companies and their suppliers.
This historic shift in German defense policy is creating opportunities for financial investors. At the same time, investments in the sector are subject to an increasingly complex regulatory framework reflecting the strategic sensitivity of defense capabilities, critical technologies, and national security interests.
This client alert outlines the key regulatory considerations that investors have to take into account when investing in German defense companies: (i) foreign direct investment (FDI) rules; (ii) export control restrictions; (iii) industrial security and classified information requirements; and (iv) cybersecurity matters.
Foreign investments in German defense companies can trigger mandatory FDI filing requirements and require clearance from the German Federal Ministry for Economic Affairs and Energy (BMWE). An FDI filing can materially affect deal certainty and transaction timing. In deals where restrictive conditions are imposed, post-closing governance and business activities of both the acquirer and the target can be affected. Restrictive measures (such as side conditions, public law contracts, and administrative orders—typically behavioral conditions) remain rare in practice.
Germany operates a two-pillar FDI regime: the first pillar covers military and certain IT-security products (so-called ‘sector-specific regime’), and the second pillar extends also to other industries and covers, for example, critical infrastructure, emerging technologies, and certain dual-use goods (so-called ‘cross-sector regime’). Investments in German defense companies, i.e. where a target develops, manufactures, or otherwise handles military goods, are primarily subject to the German sector-specific FDI regime. In these cases, the BMWE coordinates with other ministries and agencies (in particular the Federal Ministry of Defense (BMVg)) to assess whether the –direct or indirect– acquisition of the target entity by a non-German investor is likely to impair “essential security interests” of the Federal Republic of Germany.
Defense-related transactions may also trigger a parallel filing obligation under the broader cross-sector FDI regime, particularly where they involve key strategic technologies such as AI, unmanned aerial vehicles, robotics, and other emerging technologies. Under the cross-sector regime, a different test applies: whether the transaction is likely to affect “public order or security” in Germany, in other EU Member States, or in relation to EU projects or programs.
Where both FDI regimes apply, the filing obligations can be satisfied through a single filing, and review timelines are aligned. Phase I of the review process generally lasts up to two months; an in-depth Phase II review may add up to a further four months, subject to extensions and the application of stop-the-clock mechanisms. Closing prior to clearance is prohibited, and completion of a transaction in breach of the standstill obligation will render any closing measures provisionally void (schwebend unwirksam) until clearance has been granted and may even lead to criminal sanctions.
Defense-sector transactions are subject to heightened scrutiny. Regulators pay particular attention to whether the target: (i) has direct or indirect supply relationships with the German Armed Forces (Bundeswehr); (ii) has unique selling points that distinguish it from global competitors; or (iii) offers products of high military relevance, or products that could become highly relevant. Any potential technology or know-how transfer to a non-allied state is of particular concern.
Where the BMWE identifies serious security concerns, it may prohibit a proposed transaction in whole or in part. Where concerns are addressable, the BMWE may impose behavioral conditions—typically supply commitments and/or know-how protection mechanisms. These mechanisms are designed to prevent uncontrolled outflows of proprietary technology, intellectual property, and patents, and may include adherence to the “need-to-know” principle, retention of data servers exclusively within the EU/EEA, robust data security measures, or other commitments.
Acquiring assets or shares in a defense business does not generally trigger an export control license requirement. Export controls nevertheless remain highly relevant for investors because they determine a target’s ability to commercialize and export its products, transfer technology, and expand internationally.
Germany’s export control framework is shaped by EU regulations and national legislation. The applicable rules differ significantly depending on whether a product is classified as a military or dual-use product—that is, a product with both civilian and military applications. Military goods and technologies are primarily regulated under German law.
- “War weapons”—such as combat aircraft, tanks, warships, certain artillery systems, firearms, and ammunition—are subject to the German War Weapons Control Act. Unlike the dual-use export control regime, this framework requires governmental authorization for the production of covered weapons, not only for their export. The scope of this regime continues to evolve. Other military goods are primarily regulated under the Foreign Trade and Payments Act and the related Ordinance (AWG/AWV).
- Dual-use goods, software, and technology are primarily governed by the EU Dual-Use Regulation (Regulation (EU) 2021/821), which establishes a harmonized export control regime across the EU. Germany also maintains national controls over certain products, software, and technologies not covered by the EU regime but considered relevant to German national security interests.
In their due diligence process, investors should assess whether the target’s products are subject to export control restrictions, the necessary licenses have been obtained, and exports and technology transfers have been conducted in compliance with applicable laws in the past. In case the target is still in the development phase, the future export control treatment of the technology needs to be analyzed, including, where appropriate, by reaching out to the competent authorities to seek practical guidance, if possible.
Financial investors should also consider whether a defense target is involved in projects or activities requiring access to sensitive classified information. Defense companies participating in German defense programs are often subject to strict security clearance and industrial security requirements, including rules for handling classified information and security vetting of key personnel under the German Security Clearance Act (SÜG). These requirements can significantly affect the due diligence process and transaction structure, including the need to retain key personnel holding relevant security clearances.
Cybersecurity has become a key factor for defense-sector investors. Companies operating in this sector must comply with a layered framework of EU and national cybersecurity rules to protect sensitive government information, critical infrastructure, and defense-related intellectual property.
Recent EU-level reforms have significantly expanded cybersecurity requirements. In Germany, implementation of the NIS 2 Directive has led to substantial amendments to the Act on the Federal Office for Information Security (BSIG). The new BSIG introduces additional obligations for “important entities”; in particular, these entities must: (i) implement appropriate, proportionate, and effective technical and organizational measures; (ii) ensure management oversight of such measures and management participation in training; (iii) report significant security incidents; and (iv) register with the Federal Office for Information Security (BSI). Entities that operate critical infrastructure and qualify as “very important entities” are subject to even stricter security and resilience requirements.
The BSIG does not impose direct liability on a shareholder for BSIG breaches by a company’s management—that is, the limitation of liability of the legal entity generally remains intact, which is an important factor for investors. However, under case law relating to antitrust breaches, a parent shareholder can be held liable for breaches by its subsidiary if both companies form part of a “single undertaking.” It remains to be seen whether authorities and courts will apply this concept to BSIG liability.