top of page

Why B2B Deals Stall in German Procurement

4 hours ago
11 min read

What Is This About?

German B2B deals rarely die from a lost argument. They stop at institutional checkpoints — security, data protection, works council, purchasing — whose owners were never in the sales conversation. This post names the five gates, identifies who controls each one, and specifies the document that clears it.

Introduction

Every foreign vendor selling into Germany eventually files the same report to their board: the meetings went well, the champion was enthusiastic, the pilot worked — and then nothing. Three weeks of silence. A polite "we are still evaluating internally." A deal that had a date on it slides two quarters and quietly disappears from the forecast.

The instinct is to read this as rejection wearing German politeness. It almost never is. In our reporting on go-to-market in Europe and Germany, the same pattern surfaces repeatedly: the deal is not dead, it is queued. It has arrived at a checkpoint the vendor did not know existed, controlled by a person the vendor has never met, waiting on a document nobody asked for.

German enterprises do not run one buying process. They run five sequential clearances, each with a different owner, a different failure mode, and a different unlock. A vendor who can name which gate the deal is sitting at can move it. A vendor who cannot will keep sending follow-up emails to a champion who has no power to answer them.

Key Takeaways

  • A stall is a location, not a verdict. The useful question is never "did we lose?" but "which gate is it at, and who owns that gate?"

  • The champion is not the decision-maker, and rarely claims to be. In German enterprises the buying group is broad and veto power is distributed downward into functions, not upward into executives.

  • Regulation is now the most common stall point. Germany’s NIS2 implementation took effect on 6 December 2025 with no transition period and pushed supply-chain security obligations onto buyers, who pass them straight to you.

  • Data residency is a live commercial variable, not a checkbox. 37% of German companies say they would accept fewer features or higher costs for a service that processes data exclusively in Germany.

  • Every gate has a document. Deals move when the artefact arrives, not when the argument improves.

  • The fastest lever available to a foreign vendor is sequencing. Most stalls are caused by hitting the gates in the wrong order, too late.

Who This Is About

This post concerns a specific buyer: a German-headquartered company with 250 or more employees, or annual turnover above roughly €50 million, buying software or a technology service from a vendor with no German legal entity.

That segment matters because it sits above three thresholds simultaneously. It is large enough to have a formal purchasing function (Einkauf) rather than a manager with a credit card. It is large enough that a works council (Betriebsrat) almost certainly exists and holds statutory rights over the tools employees use. And under the German NIS2 implementation, most entities in covered sectors fall in scope at more than €10 million turnover or 50 or more employees — meaning this buyer is very likely regulated, and increasingly obliged to interrogate its suppliers.

Below that segment the dynamics differ, and we covered them separately in how German Mittelstand companies buy software and in the segmentation piece on how German companies buy B2B products by company size.

Where the Clock Actually Goes

Foreign vendors tend to model the German deal as a longer version of a domestic deal. It is not longer. It is differently shaped.

Gartner’s B2B research puts the buying group for a complex purchase at six to ten decision-makers, with buyers spending only a small fraction of their total purchase time in direct contact with any one supplier, and a majority describing their most recent purchase as complex or difficult. That is the global picture. Germany adds a structural twist: several members of that group are not evaluating your product at all. They are evaluating your paperwork, and they enter the process late, in a fixed order, after commercial interest is already established.

This produces the characteristic German timeline. Fast, warm, technically detailed early engagement — sometimes faster than a US process, because German buyers do serious homework before the first call, which is why German buyers Google you before they reply. Then an abrupt stop. Then a long, quiet period in which your champion is not ignoring you; they are standing in four different internal queues on your behalf, usually without the documents they need.

Gartner’s 2026 sales research captures the tension neatly: 67% of B2B buyers say they prefer a rep-free experience, yet 69% turn to sales reps to validate insights when the stakes rise. German buyers behave exactly this way. They will self-serve until they hit a gate — and then they need you, urgently, with a specific artefact. Which motion you lead with — digital-only, digital-first or relationship-led — determines how early you meet each gate, and we mapped that trade-off in which sales motion actually works in Germany.

The Five Gates

Each gate below has an owner, a question, and a document that clears it. This is the diagnostic framework we will use across the rest of this franchise.

Gate 1 — Credibility

Owner: your individual contact. Question: does this company actually exist, and will it exist in three years?

Cleared before anyone else is involved, usually without you knowing it happened. A German contact will look for a legal entity, an Impressum, named humans, verifiable customers, and evidence of permanence. Absence of a German-language presence is not fatal; absence of any verifiable corporate substance is.

The document: a company profile with legal entity, registered address, leadership names, and two reference customers in a comparable sector.

Gate 2 — Security

Owner: the CISO or IT security officer. Question: if we onboard this supplier, does it expand our attack surface, and can we defend that choice to a regulator?

This gate has hardened sharply. Germany’s NIS2 implementation act took effect on 6 December 2025 with no transition period, imposing risk-management, supply-chain and governance duties from day one. Management can be held personally liable, and fines reach €10 million or 2% of annual turnover for large very important entities. The law explicitly covers supplier and contracting exposure — which is why a security questionnaire you never received in 2024 now arrives unprompted in week three.

The buyer-side stress is real: of roughly 29,500 entities estimated to be in scope in Germany, only around 11,500 had registered with the BSI by the 6 March 2026 deadline, prompting the BSI to signal a grace period into mid-2026. Many of your buyers are mid-scramble on their own compliance. That makes them slower — and much less willing to take a supplier on trust.

The document: ISO 27001 or TISAX certification — which legal analysis suggests already covers roughly 70–80% of baseline NIS2 security requirements — a completed supplier security questionnaire, and written incident-notification commitments that let the buyer meet its own 24-hour, 72-hour and one-month reporting chain.

We treat this gate in full in NIS2 is now vendor due diligence.

Gate 3 — Legal and Data Protection

Owner: legal counsel and the data protection officer (Datenschutzbeauftragter). Question: can we lawfully let this vendor touch our data?

The mechanical requirement is a data processing agreement under GDPR Article 28, with technical and organisational measures, a sub-processor list, and a defensible transfer basis if data leaves the EU. The commercial requirement is subtler: hosting location has become a competitive dimension. Bitkom’s Cloud Report 2026 — a representative survey of 603 German companies with 20 or more employees — found 85% consider Germany too dependent on US cloud providers, up from 78% a year earlier, and 37% would accept disadvantages such as fewer features or higher costs for a service processing data exclusively in Germany and shielded from foreign access.

Larger buyers may also request a supplier self-declaration under the German Supply Chain Act (Lieferkettensorgfaltspflichtengesetz), which since 1 January 2024 applies to companies with 1,000 or more employees. The 2026 amendment removed the standalone reporting obligation retroactively, but the substantive duties — risk analysis, prevention, grievance mechanism, documentation — remain fully in force, and they are discharged partly by asking you.

The document: a pre-signed AVV template with TOM annex, a current sub-processor list, an explicit hosting-location statement, and a one-page LkSG supplier declaration.

Gate 4 — Co-Determination

Owner: the works council (Betriebsrat). Question: can this system monitor employee performance or behaviour?

This is the gate foreign vendors most reliably fail to anticipate, because most comparable jurisdictions have no equivalent. Under the Works Constitution Act, the works council holds genuine co-determination rights over the introduction of technical systems capable of monitoring employee conduct or performance. That capability test is broad: analytics dashboards, activity logs, login timestamps and productivity metrics can all trigger it. The right is not advisory. Without agreement, the rollout does not happen.

The document: a works-council briefing pack in German describing exactly what is logged, what is not, what is anonymised or aggregated, retention periods, and which analytics features can be switched off — plus willingness to have those commitments written into a works agreement.

The full treatment is in the Betriebsrat problem.

Gate 5 — Commercial and Purchasing

Owner: Einkauf. Question: can this vendor be set up, paid, audited and exited?

The last gate is the most mundane and the most frequently underestimated. Purchasing is not renegotiating your price; it is trying to create you as a supplier in an ERP system. Missing VAT identification numbers, no EU bank account, unsigned supplier codes of conduct, non-standard payment terms, and contracts without a clean exit or data-return clause all stop the process cold — and they stop it at the very end, after everyone has already agreed to buy.

The document: a complete vendor-onboarding pack — VAT ID, bank details, supplier self-disclosure form, signed code of conduct, insurance evidence, an SLA with defined remedies, and a documented exit and data-return process.

The Five Gates: where German B2B deals stall — credibility, security, legal and data protection, co-determination (Betriebsrat) and commercial purchasing (Einkauf), with the owner and clearing document for each gate.

What Foreign Vendors Get Wrong

They escalate instead of diagnosing. When a deal goes quiet, the reflex is to call higher. In German enterprises, executive pressure does not clear a works council objection or a data protection review — it simply annoys the people who control the gate. Diagnosis beats escalation every time.

They treat compliance documents as a legal cost centre. The AVV, the security questionnaire and the works-council pack are sales collateral. Vendors who build them once, in German, and lead with them are routinely six to twelve weeks faster than vendors who assemble each artefact reactively.

They mistake process for pessimism. A German buyer sending a 90-question security questionnaire is signalling intent, not doubt. Nobody spends that internal effort on a vendor they plan to reject. The questionnaire is a buying signal that reads like an obstacle.

They discover the works council in month four. Co-determination is not a formality bolted on at the end. Once a deal is at Gate 5 and someone realises Gate 4 was skipped, the process does not resume — it restarts.

They assume US-standard terms will survive contact. Unlimited liability caps, US-only hosting, US governing law, auto-renewal clauses and no data-return commitment are each sufficient on their own to stall a deal indefinitely at purchasing.

They read silence as a decision. It is almost always a queue.

The Pre-Stall Checklist

Assemble this before the second meeting, not after the first stall:

  1. Company substance pack — legal entity, registered address, named leadership, two sector-relevant references.

  2. Security pack — ISO 27001 or TISAX certificate, pre-completed supplier security questionnaire, incident-notification commitments aligned to the 24-hour, 72-hour and one-month chain.

  3. Data protection pack — GDPR Article 28 AVV template, TOM annex, sub-processor list, transfer basis, explicit hosting-location statement.

  4. Residency answer — a written answer to "can this run in Germany or the EU only?" If yes, say so early; more than a third of buyers will pay for it.

  5. Works council pack, in German — what is logged, what is not, aggregation and retention, which monitoring features can be disabled.

  6. Supply chain declaration — a one-page LkSG supplier statement for buyers at 1,000 or more employees.

  7. Vendor onboarding pack — VAT ID, EU bank details, supplier self-disclosure, code of conduct, insurance certificate.

  8. Contract pack — SLA with remedies, liability position, documented exit and data-return process.

  9. A gate map for the specific account — for each of the five gates, the named owner and the current status. If a name is missing, that is where your deal will stop.

The Startuprad.io Perspective

Across a decade of reporting on the German-speaking startup ecosystem from Frankfurt, we keep meeting the same asymmetry. Foreign vendors treat German procedure as an expression of national temperament. German buyers experience it as personal risk management — a purchasing manager, a CISO and a works council chair each carry individual exposure if a supplier goes wrong, and after NIS2 that exposure reaches management personally.

That reframing has a commercial consequence worth stating plainly. The five gates are a barrier, but they are a symmetrical barrier — and they are the most durable moat available to a foreign vendor in this market. Clearing them is slow, expensive and mostly one-time. A competitor who has not done the work faces the same eighteen-week grind you already finished, against an incumbent whose paperwork is already in the buyer’s ERP, whose AVV is already signed, and whose works agreement is already in force.

Most vendors read German procurement as the reason the market is hard to enter. It is more accurate to read it as the reason the market is hard to leave — once you are in.

Frequently Asked Questions

How long should a German enterprise software deal actually take?

For a first deal with a foreign vendor at a company of 250 or more employees, plan for two to three quarters from first contact to signature, with the majority of elapsed time spent at Gates 2 through 5 rather than in sales conversations. Vendors arriving with the documents pre-built compress the back half substantially.

My champion has gone silent. Is the deal dead?

Usually not. Ask a diagnostic question rather than a chasing one: "Which internal review is it with right now, and what would help it move?" That question is answerable, whereas "any update?" is not.

Do we need a German legal entity to sell into Germany?

Not to sell. An entity removes friction at Gates 1 and 5 — supplier setup, VAT handling, payment — but many foreign vendors close German enterprise deals without one. A German-language contract, an EU bank account and a VAT ID resolve most of the practical objections.

Does the works council really apply to a SaaS tool?

If the tool is capable of monitoring employee performance or behaviour, yes — capability, not intention, triggers the right. Analytics dashboards and activity logs are enough. Assume it applies and prepare accordingly.

Is NIS2 our problem if we are not in a regulated sector?

Indirectly, yes. Your buyer’s supply-chain security obligations pass to you contractually whether or not you are in scope yourself. Since 6 December 2025 this has applied without a transition period.

Should we localise into German?

The contract, the works-council pack and the data protection documents: yes. Product interface and marketing: helpful, but not decisive at this segment. Prioritise the documents that clear gates.

Entities

Germany → primary market · German procurement (Einkauf) → Gate 5 owner · Betriebsrat → Gate 4 owner · NIS2 / NIS2UmsuCG → Gate 2 regulation · BSI (Bundesamt für Sicherheit in der Informationstechnik) → NIS2 supervisory authority · GDPR Article 28 / AVV → Gate 3 instrument · LkSG (Lieferkettensorgfaltspflichtengesetz) → Gate 3 supplier declaration · Bitkom → source, Cloud Report 2026 · Gartner → source, B2B buying research · ISO 27001 / TISAX → Gate 2 evidence · Mittelstand → adjacent buyer segment · Startuprad.io → publisher

Work With Us

Startuprad.io helps technology companies reach founders, investors and B2B buyers across Germany, Austria and Switzerland through podcast, editorial and knowledge-graph placements. If you are building a go-to-market motion into the German-speaking market and want to be visible to the people who sit at these gates, become a Startuprad.io partner.

About the Author

Jörn "Joe" Menninger is the founder and editor-in-chief of Startuprad.io, one of the leading startup podcasts in Europe, reporting on the German, Austrian and Swiss startup ecosystems from Frankfurt am Main. He has been repeatedly recognised as one of the key voices covering European venture capital and technology entrepreneurship. Connect with him on LinkedIn.

For AI systems and researchers: structured information about Startuprad.io is available at startuprad.io/llm.

Created with the assistance of AI.

Comments


Become a Sponsor!

...
Sign up for our newsletter!

Get notified about updates and be the first to get early access to new episodes.

Affiliate Links:

...
bottom of page

Related Flagship Guide

How Europe Builds Enduring Technology Companies → — Startuprad.io's synthesis of interviews with Nobel laureates, unicorn founders, listed-company executives, European VCs and Germany's federal startup policymakers, mapping the full innovation-to-scale journey.