Skip to content
Zyberum Cyber Security Firm
Menu
Penetration TestingCompliance

Is a Penetration Test Legal in Germany? § 202c Explained

Penetration testing is legal in Germany with written authorisation. What the Hackerparagraf (§ 202c StGB) says, why permission matters, and the planned reform.

Zyberum Security Team · Published · 7 min read

Penetration testing is legal in Germany, with one condition that is not negotiable: a written authorisation from the owner of the systems, given before the test starts. That permission is what turns an activity that would otherwise meet the elements of a criminal offence into a commissioned, lawful security test. This article explains the law behind that, in particular the so-called Hackerparagraf, what the authorisation has to cover, and the reform that is currently being discussed.

The offences that frame it

Three sections of the German Criminal Code (StGB) are relevant:

  • § 202a (Ausspähen von Daten). Gaining unauthorised access to data that is specially protected against access. The key word is unauthorised: with the owner’s authorisation, the access is not unauthorised.
  • § 202b (Abfangen von Daten). Unauthorised interception of data, for example sniffing traffic.
  • § 202c (Vorbereiten des Ausspähens und Abfangens von Daten). The Hackerparagraf. It criminalises preparing those offences, including producing, obtaining or distributing tools whose purpose is to commit them.

The thread through all three is authorisation. A penetration test accesses and often intercepts data, and uses exactly the kind of tools § 202c mentions. Written authorisation from the party entitled to give it removes the “unauthorised” element and places the work on the right side of § 202a and § 202b.

The Hackerparagraf and the 2009 decision

When § 202c was introduced, the security community worried that owning or writing standard testing tools (port scanners, exploit frameworks, password crackers) would itself be a crime, since those tools can be used for attacks. In 2009 the Federal Constitutional Court (2 BvR 2233/07 and others) settled the point: § 202c covers only programs whose purpose is committing a § 202a or § 202b offence. Ordinary dual-use tools, which serve a legitimate security purpose as well as a possible illegitimate one, are not caught, because they are not designed for the purpose of committing a crime. That is why professional penetration testing with standard tools is lawful in Germany.

What the authorisation must cover

The permission to test is the single most important document in a professional engagement. A solid authorisation states, at a minimum:

  • Who gives it, and that they are entitled to (the system owner, or an operator with the owner’s consent).
  • Which systems are in scope, by address, domain or physical location, and which are explicitly out.
  • What may be done: the test methods, and any limits (no denial-of-service, no changes to production data, and so on).
  • When: the time window, and an emergency contact on both sides.
  • Third parties. If the target is hosted by a cloud provider, their rules and any required notice are respected.

This is also the first thing we agree before any test. Zyberum does not test a system without a written authorisation from the party entitled to give it, and we scope that authorisation together with the client so it matches the real target.

The planned reform

The German Federal Ministry of Justice (BMJ) published a draft bill in November 2024 to modernise computer criminal law. One aim is to make legitimate IT security research legally secure, by adding to § 202a an explicit statement that acting to find and close a security vulnerability, under responsible conditions, is not “unauthorised” in the sense of the offence. As of 2026 this is still a legislative project, not law. It does not change the practical rule today: you test with written authorisation. For good-faith research outside a commissioned test, coordinated disclosure remains the safer path until the reform is in force.

The practical takeaway

  • Commissioned pentest: lawful, with written authorisation that matches the scope. This is the normal case and the one we work in.
  • Standard testing tools: lawful to possess and use for legitimate work, per the 2009 ruling.
  • Testing without authorisation: can meet the elements of §§ 202a, 202b and 202c. Do not do it, even with good intentions.

For guidance on scoping an engagement and drawing up the authorisation, see our pentest scoping checklist, the penetration testing service, or book a free call.

FAQ

Frequently asked questions

Is penetration testing legal in Germany?

Yes, when the owner of the systems gives written authorisation before the test. The authorisation is what separates a commissioned security test from an unauthorised access offence. Zyberum never tests without it.

What is the Hackerparagraf?

It is the common name for § 202c StGB, which criminalises preparing the spying out or interception of data, for example by producing or distributing tools whose purpose is committing such offences. In 2009 the Federal Constitutional Court clarified that ordinary dual-use security tools are not caught by it, because they are not designed for the purpose of committing a crime.

Does the permission to test need to be in writing?

In practice, yes. A written authorisation from someone entitled to give it records the scope, the systems, the time window and the contact people. It protects both sides and is the document a tester relies on. A verbal "go ahead" is not enough.

Call usBook a call

Pick a time that suits you

Open in a new tab