# Is a Penetration Test Legal in Germany? § 202c Explained

Penetration testing is legal in Germany with written authorisation. What the Hackerparagraf (§ 202c StGB) says, why permission matters, and the planned reform.

Source: https://zyberum.com/insights/pentest-legality-germany-202c · Updated: 2026-10-07

Penetration testing is legal in Germany, with one condition that is not negotiable: a **written authorisation** from the owner of the systems, given before the test starts. That permission is what turns an activity that would otherwise meet the elements of a criminal offence into a commissioned, lawful security test. This article explains the law behind that, in particular the so-called Hackerparagraf, what the authorisation has to cover, and the reform that is currently being discussed.

## The offences that frame it

Three sections of the German Criminal Code (StGB) are relevant:

- **§ 202a (Ausspähen von Daten).** Gaining unauthorised access to data that is specially protected against access. The key word is *unauthorised*: with the owner's authorisation, the access is not unauthorised.
- **§ 202b (Abfangen von Daten).** Unauthorised interception of data, for example sniffing traffic.
- **§ 202c (Vorbereiten des Ausspähens und Abfangens von Daten).** The Hackerparagraf. It criminalises *preparing* those offences, including producing, obtaining or distributing tools whose purpose is to commit them.

The thread through all three is authorisation. A penetration test accesses and often intercepts data, and uses exactly the kind of tools § 202c mentions. Written authorisation from the party entitled to give it removes the "unauthorised" element and places the work on the right side of § 202a and § 202b.

## The Hackerparagraf and the 2009 decision

When § 202c was introduced, the security community worried that owning or writing standard testing tools (port scanners, exploit frameworks, password crackers) would itself be a crime, since those tools can be used for attacks. In **2009 the Federal Constitutional Court** (2 BvR 2233/07 and others) settled the point: § 202c covers only programs whose *purpose* is committing a § 202a or § 202b offence. Ordinary **dual-use tools**, which serve a legitimate security purpose as well as a possible illegitimate one, are not caught, because they are not designed for the purpose of committing a crime. That is why professional penetration testing with standard tools is lawful in Germany.

## What the authorisation must cover

The permission to test is the single most important document in a professional engagement. A solid authorisation states, at a minimum:

- **Who gives it**, and that they are entitled to (the system owner, or an operator with the owner's consent).
- **Which systems** are in scope, by address, domain or physical location, and which are explicitly out.
- **What may be done**: the test methods, and any limits (no denial-of-service, no changes to production data, and so on).
- **When**: the time window, and an emergency contact on both sides.
- **Third parties.** If the target is hosted by a cloud provider, their rules and any required notice are respected.

This is also the first thing we agree before any test. Zyberum does not test a system without a written authorisation from the party entitled to give it, and we scope that authorisation together with the client so it matches the real target.

## The planned reform

The German Federal Ministry of Justice (BMJ) published a draft bill in November 2024 to modernise computer criminal law. One aim is to make legitimate IT security research legally secure, by adding to § 202a an explicit statement that acting to find and close a security vulnerability, under responsible conditions, is not "unauthorised" in the sense of the offence. As of 2026 this is still a legislative project, not law. It does not change the practical rule today: you test with written authorisation. For good-faith research outside a commissioned test, coordinated disclosure remains the safer path until the reform is in force.

## The practical takeaway

- **Commissioned pentest:** lawful, with written authorisation that matches the scope. This is the normal case and the one we work in.
- **Standard testing tools:** lawful to possess and use for legitimate work, per the 2009 ruling.
- **Testing without authorisation:** can meet the elements of §§ 202a, 202b and 202c. Do not do it, even with good intentions.

For guidance on scoping an engagement and drawing up the authorisation, see our [pentest scoping checklist](/insights/pentest-scoping-checklist), the [penetration testing](/penetration-testing) service, or book a [free call](/contact?meeting=intro).

## FAQ

**Is penetration testing legal in Germany?**

Yes, when the owner of the systems gives written authorisation before the test. The authorisation is what separates a commissioned security test from an unauthorised access offence. Zyberum never tests without it.

**What is the Hackerparagraf?**

It is the common name for § 202c StGB, which criminalises preparing the spying out or interception of data, for example by producing or distributing tools whose purpose is committing such offences. In 2009 the Federal Constitutional Court clarified that ordinary dual-use security tools are not caught by it, because they are not designed for the purpose of committing a crime.

**Does the permission to test need to be in writing?**

In practice, yes. A written authorisation from someone entitled to give it records the scope, the systems, the time window and the contact people. It protects both sides and is the document a tester relies on. A verbal "go ahead" is not enough.

## Sources

- [§ 202c StGB (Vorbereiten des Ausspähens und Abfangens von Daten), gesetze-im-internet.de](https://www.gesetze-im-internet.de/stgb/__202c.html)
- [§ 202a StGB (Ausspähen von Daten), gesetze-im-internet.de](https://www.gesetze-im-internet.de/stgb/__202a.html)
- [BVerfG, Beschluss vom 18. Mai 2009, 2 BvR 2233/07 u.a. (§ 202c StGB)](https://www.bundesverfassungsgericht.de/SharedDocs/Entscheidungen/DE/2009/05/rk20090518_2bvr223307.html)
- [BSI: Ein Praxis-Leitfaden für IS-Penetrationstests](https://www.bsi.bund.de/DE/Themen/Oeffentliche-Verwaltung/Sicherheitspruefungen/Pen_Test_und_IS_Webcheck/pen-tests-und-is-webcheck_node.html)

## Related

- [Penetration test](https://zyberum.com/glossary/penetration-test)
- [Pentest Scoping Checklist: What to Clarify Before the Test](https://zyberum.com/insights/pentest-scoping-checklist)
- [Responsible Disclosure](https://zyberum.com/glossary/responsible-disclosure)
- [Is a Penetration Test Mandatory? What the Law Actually Requires](https://zyberum.com/insights/is-a-pentest-mandatory)
- [We break in. You get the proof and the fix.](https://zyberum.com/penetration-testing)
- [Let’s talk about your security.](https://zyberum.com/contact)

---
Zyberum GmbH. Canonical page: https://zyberum.com/insights/pentest-legality-germany-202c
