it-sa Expo&Congress 2026: When Cybersecurity Becomes a Core Business Task
Cyber attacks, new regulatory requirements, and the increasing use of Artificial Intelligence are changing the demands on IT security. Companies must not only protect individual systems but also make their entire digital infrastructure more resilient. From October 27 to 29, 2026, the it-sa Expo&Congress in Nuremberg will bring together IT security officers, technology providers, decision-makers, and experts. The accompanying Congress@it-sa starts already on October 26.
it-sa is considered Europe's largest trade fair for IT security. The range of products and services includes hardware and software, consulting, further education, and Security as a Service. Key topics include cloud and mobile security, data and network security, and the protection of critical infrastructures and industrial systems.
AI Changes Attack and Defense
By 2026, Artificial Intelligence will be a central topic in IT security. Companies can use AI to analyze large volumes of data more quickly, detect anomalies, or automate security processes. The same technologies are also available to attackers. This shifts the situation. IT departments must not only secure new AI applications but also deal with the fact that cyberattacks can become more automated and professional. Therefore, it-sa addresses Artificial Intelligence as its own thematic area. Cloud security, ransomware, hacking, and defense are also focuses. For medium-sized companies, it will be crucial which solutions can actually be integrated into existing IT structures. Because additional security should not lead to unmanageable complexity.
More than 400 Contributions on Current Security Issues
Beyond the exhibition stands, the forum program carries weight. For 2026, it-sa announces more than 400 curated contributions. This includes the it-sa insights with product-independent information and panel discussions. Trade visitors can inform themselves about current attack methods, security strategies, and regulatory changes, not just new products. It is now a consensus that technology alone is not sufficient. Cybersecurity is not decided by firewalls or security software alone. Access rights, employees, emergency plans, and the question of how a company can continue to operate after an attack are also part of a robust security strategy.
Regulation Increases the Pressure to Act
Legal requirements have also become an essential part of the IT security strategy. The theme platform of it-sa includes, among others, NIS-2, DORA, standards and compliance as central areas. In addition, there is the protection of Critical Infrastructures. Thus, cybersecurity is increasingly reaching the executive level. For affected companies, it is no longer just about voluntarily achieving the highest possible level of security. Security measures, risk management, and responsibilities are increasingly shaped by regulatory requirements. For visitors, it might be particularly interesting how providers and experts combine technical security with organizational and legal requirements.
Congress@it-sa starts a day earlier
Those who want to delve deeper into individual topics can come to Congress@it-sa in Nuremberg as early as October 26. The congress program runs until the end of the exhibition on October 29, and is organized by associations, industry groups, and IT security providers. According to the organizer, many of the thematic blocks are accessible free of charge. The congress is not a second exhibition program but offers technical presentations, discussions, and exchanges on specific security issues in a more concentrated format. The format is aimed at IT security officers and decision-makers who want to strategically work through concrete topics.
Cybersecurity start-ups compete against each other
Young companies also get their own stage in 2026. At the ATHENE Startup Award UP26@it-sa, cybersecurity and data protection solutions from Germany, Austria, and Switzerland are awarded. A panel of experts selects five finalists. On October 28, they will present their solutions at the final pitch on the trade fair stage in Nuremberg. Prize money is available for the three top teams; in total, prizes worth 15,000 euros are planned. The award will be given for the ninth time in 2026. For trade visitors, the format provides a look at technologies that are not yet part of the standard offerings of large security providers. Especially in cybersecurity, start-ups can quickly adopt new approaches because attack methods and technological conditions are constantly changing.
The industry continues to grow
The figures from the last event speak for themselves: in 2025, 28,267 trade visitors from 64 countries came to Nuremberg, 993 companies presented their solutions in five exhibition halls. Both were new records. The it-sa Expo&Congress 2026 takes place from October 27 to 29 at the Nuremberg Exhibition Center. The exhibition is open Tuesday and Wednesday from 9 am to 6 pm, Thursday from 9 am to 5 pm. The Congress@it-sa begins a day earlier, on Monday, October 26. For companies in Nuremberg, one question is likely to be of particular importance: How can IT security be organized in such a way that it keeps pace with new technologies and threats without slowing down business operations? AI, regulation, and increasingly complex digital infrastructures make it clear that cybersecurity is no longer just an IT issue but part of corporate risk management.