Enquirer Consulting Group

Reachable Buyer Map

Prepared for Prof. Dr. Jörn Hoffmann · bitaggregat · Germany · August 2026
Here is the map. German security buying has changed shape: a duty of care that used to apply to a short register of critical operators now reaches tens of thousands of companies, most of which have never bought security work of any kind and have nobody inside with the title to buy it. Below are the groups, who signs inside each, and roughly how many there are. It describes the market rather than your business, and there is nothing to buy at the end of it.
Companies newly inside the security duty of care
The single largest change in this market for a decade. These companies are in scope by size and sector rather than by designation, which means most of them have not been told, will not search for help, and will only act once someone explains that the rules moved. Unqualified in the usual sense, and reachable only by name.
Who signs: managing director, head of IT, information security officer where one exists, and across most of this group nobody holds the role yet.
28,000 to 30,000
German companies estimated to fall inside the widened network and information security rules, against a critical operator register that ran in the low thousands
Industrial Mittelstand manufacturers
Where production networks and office networks were never separated in the first place, so detection is an easier first sale than segmentation. Family ownership means the technical case has to survive a conversation with someone commercial, and works council consultation applies to anything that looks like monitoring.
Who signs: IT manager, head of production or plant IT, technical managing director, and the works council on anything touching monitoring.
20,000 to 25,000
German manufacturers above roughly fifty employees; the smaller layer beneath is far larger and is reached through the IT channel rather than directly
Municipal utilities and network operators
The group that has carried critical operator obligations the longest and is the most used to buying against them. Slow procurement, public tender rules on the larger contracts, and a strong internal peer network where a single reference travels between municipalities.
Who signs: IT lead, information security officer, control room and operational technology manager, managing director.
900 to 1,500
German municipal utilities and electricity network operators
Hospitals and healthcare providers
High consequence, thin budgets and a well-documented exposure. Buying is driven by funding rounds and audit dates rather than by conviction, so timing matters more here than argument. A larger layer of clinic groups, laboratories and care operators sits behind the hospital count.
Who signs: IT director, information security officer, data protection officer, commercial director.
1,700 to 1,900
German hospitals, plus clinic groups, laboratories and care operators behind them
Public administration
Districts and larger municipalities running their own IT, frequently through shared service bodies. Long cycles and framework agreements, but the same rules now apply to them, and a single shared service body can carry dozens of authorities behind it.
Who signs: head of IT, chief digital officer, information security officer, and the procurement office.
2,000 to 2,600
German districts and larger municipalities with their own IT budget, out of roughly eleven thousand municipalities in total
IT system houses and managed service providers
A distribution layer rather than a customer. These firms already hold the IT relationship with most of the companies in the first two segments, they are being asked security questions they cannot answer, and each one carries hundreds of accounts. A short list where one relationship is a market.
Who signs: managing director, technical director, portfolio or vendor manager, security practice lead.
3,000 to 4,000
German system houses and managed service providers; not enumerated in any public register, so this is the softest count here

Where the openings are

1
Two products, two buyers, and only one of them has a security title. A detection system is bought by someone technical who already knows what they cannot see. Consulting and certification work is bought by a managing director who has just learned the rules changed. Same company, different door, different sentence, and a single message aimed between them lands with neither.
2
The register grew by an order of magnitude and nobody told the companies. The old critical operator list was small enough that everyone on it knew they were on it, which made the market self-selecting. The widened scope pulled in tens of thousands of mid-size companies that do not know they qualify, have no security officer and will never search for one. That group cannot be reached by content or by inbound. It can only be reached by name.
3
Compliance is a date, not a mood. Audit windows, certification renewals and reporting deadlines put the same question in front of thousands of companies in the same quarter, and the budget is decided just before them. That rhythm is visible from outside across a whole market at once, and easy to miss from inside any pipeline built out of inbound requests.
4
The channel is the only economic route into the long tail. A few thousand system houses sit between the security vendors and the German Mittelstand, and they are short enough to work name by name. Direct sales reaches the top of this map. The channel reaches the rest of it, and building that reach is a repeatable job rather than a hiring plan.
Built from public market data on German companies, regulated operators and public bodies, with counts banded deliberately. Scope figures for the widened security rules are policy estimates rather than a published company list, and the register of designated critical operators is not public. Employee bands and sector codes are self-reported. System houses and managed service providers are not separately enumerated anywhere public and are described rather than counted.
ENQUIRER CONSULTING GROUP