Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Heise DevSec 2026

Type Conference
Organization dpunkt.verlag
Event Format Physical
Size 101 - 300 approximate delegates
Registration Not Free
SPEAKING OPPORTUNITIES

Search for other Cybersecurity Conferences in Germany in 2026-2027.

Conference Description

Key Takeaways

  • German-language application security conference taking place in Marburg on 22–23 September 2026
  • Addresses software supply chain security, AI-generated code vulnerabilities, and post-quantum cryptography migration
  • Covers regulatory developments including the Cyber Resilience Act and legal responsibility in coding practices
  • Designed for software developers, architects, security professionals, and quality assurance teams
  • Workshop-led format with technical sessions focused on secure-by-design principles and early vulnerability prevention

Introduction

heise devSec 2026 is a German-language conference dedicated to software security, bringing together developers, architects, and security professionals to address the growing complexity of threats targeting modern software systems. Taking place in Marburg on 22–23 September 2026, the event focuses on securing the software supply chain, managing risks introduced by Generative AI, and preparing for regulatory requirements such as the Cyber Resilience Act. These topics have gained urgency as organisations face increasingly sophisticated attack vectors that exploit vulnerabilities across development pipelines, third-party dependencies, and AI-assisted coding workflows.

About heise devSec

Since its founding in 2017, heise devSec has established itself as a leading educational platform for German-speaking software professionals responsible for application security. The conference operates on the principle that secure software begins before the first line of code is written, emphasising proactive vulnerability identification rather than reactive patching. This approach reflects a broader industry shift toward integrating security considerations throughout the software development lifecycle rather than treating them as a final checkpoint before deployment.

The event combines technical lectures with hands-on workshops, catering to both practitioners who write and review code daily and decision-makers who shape security policies within their organisations. Evening networking sessions with themed discussion tables provide opportunities for attendees to exchange experiences and explore specific challenges in smaller groups.

Software Supply Chain Security and Pipeline Protection

Supply chain attacks have emerged as one of the most significant threats to software security, with attackers targeting build systems, package repositories, and third-party dependencies to compromise applications at scale. heise devSec 2026 dedicates substantial attention to pipeline security, examining how organisations can verify the integrity of components flowing through their development infrastructure. Sessions address practical defences against dependency confusion attacks, malicious package injection, and compromised build environments.

The conference also explores sandboxing technologies as a containment strategy, limiting the potential damage when vulnerabilities in external components are exploited. These technical measures complement broader secure-by-design approaches that treat untrusted inputs with appropriate caution throughout the development process.

Generative AI and Emerging Security Challenges

The rapid adoption of Generative AI in software development introduces novel security considerations that many organisations are only beginning to understand. AI-generated code can contain subtle vulnerabilities that escape detection during standard review processes, particularly when developers lack visibility into the training data and reasoning behind suggested implementations. heise devSec 2026 examines these risks alongside techniques for securing Model Context Protocol implementations and Retrieval-Augmented Generation systems, which have become common architectural patterns in AI-enhanced applications.

Beyond code generation, the conference addresses how attackers are leveraging AI to develop more sophisticated exploitation techniques, requiring defenders to adapt their detection and prevention strategies accordingly.

Regulatory Compliance and Post-Quantum Cryptography

The Cyber Resilience Act represents a significant regulatory development for software producers operating in European markets, imposing new obligations around vulnerability handling and security updates throughout a product’s lifecycle. heise devSec 2026 explores the practical implications of these requirements, particularly for organisations maintaining legacy codebases that were not designed with current compliance expectations in mind.

Sessions on post-quantum cryptography address the technical challenges of migrating existing systems to algorithms resistant to quantum computing attacks. While large-scale quantum computers capable of breaking current encryption remain years away, the complexity of cryptographic transitions means organisations must begin planning and testing migration strategies now to avoid future exposure.

Who Should Attend

heise devSec 2026 is designed for software developers and architects who bear direct responsibility for the security of their code, as well as security specialists who advise development teams on threat mitigation. Quality assurance professionals and testers will find relevant content on integrating security validation into testing workflows. Product managers and IT leaders seeking to understand the technical and regulatory landscape shaping secure software delivery will benefit from the strategic perspectives offered throughout the programme.

Sponsors

The conference is supported by sponsors including INOSOFT at the Platinum level, Cycode and SignPath at Gold, and BWI and INNOQ at Silver. Additional participating organisations include Blueflag Security, CipSoft, Contrast Security, Digital.ai, mgm security partners, inovex, Krones.digital, and Plusline.