Important entity with reactive supervision
Annex II means lower sanctions than Annex I, but the same ten minimum measures per § 30 of the German BSI Act. Supervision is reactive but kicks in on incidents or audit findings.
Automotive is covered through the NACE category vehicles and components. TISAX is not a law but a contractual requirement OEMs place on their suppliers; UN R155 and R156 are type-approval obligations that bind vehicle manufacturers first, not automatically every tier-1 or tier-2 supplier. OdySecure, the security platform by Cybervize, maps NIS-2 and TISAX from a single control set, plus OT modules for plant IT.
Book the NIS-2 risk checkStandard case under § 28 BSIG. Calculating the figures in annual work units, attributing partner and linked enterprises, special cases and the final classification all require a case-by-case legal review.
Few suppliers face a single requirement. TISAX comes from customer contracts, IEC 62443 from plant OT, UN R155 and ISO/SAE 21434 from the vehicle, NIS-2 from law, each with its own system. In OdySecure they sit in one catalogue and share a data foundation instead of producing five separate evidence trails.
Catalogue depth: “full” means a complete control catalogue, “reference” the structure with mapping onto your own measures. NIS-2 is added where the thresholds of § 28 BSIG apply. That classification is set out below.
On top of the classification above, OEMs and Tier-1/Tier-2 suppliers carry contractual TISAX requirements from the automotive supply chain. Four consequences of this dual regulation for OEM suppliers and plant operators. Sector alone is not enough: NIS-2 Annex II classification depends on size thresholds and concrete activity; TISAX remains a contractual requirement, not statute. The legally binding evaluation remains a matter for specialised counsel.
Annex II means lower sanctions than Annex I, but the same ten minimum measures per § 30 of the German BSI Act. Supervision is reactive but kicks in on incidents or audit findings.
TISAX (Trusted Information Security Assessment Exchange) is the industry standard for OEM suppliers. Audit levels 1 to 3 depending on protection needs. NIS-2 covers many TISAX requirements but not all, and vice versa.
Production plants with OT (robotics, presses, paint shops) and engineering centres with CAD and product data have different risk landscapes. Both belong in the NIS-2 scope.
OEMs pass TISAX and NIS-2 requirements down to suppliers. Tier-1 suppliers pass them down to Tier-2 suppliers. Whoever sits in a supply chain receives the requirements contractually, even without being directly NIS-2-affected.
Five NIS-2 minimum measures translated into automotive practice (with TISAX cross-reference).
Risk register with plant OT (robotics, presses), engineering IT (CAD data, product IP) and office IT. Protection goals differ: production = availability, engineering = confidentiality, office = integrity.
Supplier inventory with tier classification and criticality. TISAX status of suppliers documented, alternative suppliers for single-source components identified.
Procurement process with security requirements for new production assets, patch management with maintenance windows, remote-maintenance access for machine vendors documented.
CAD data and product IP encrypted at rest and in transit, key management documented, data classification aligned with TISAX protection levels.
MFA for engineering workstations, cloud CAD platforms and supplier portals. Privileged accounts separated. Access rights recertified regularly.
OdySecure covers ISMS, assessment (NIS-2 plus TISAX), TPRM and BCM in one solution. Especially relevant for automotive: TISAX mapping, multi-plant assessment, supplier tier logic.
Free 30-minute initial call with an indicative NIS-2 classification, top-5 gaps and a path recommendation.
Learn moreISMS, compliance and evidence from a single platform. Multi-entity, multi-country, AI-supported.
Learn moreThe platform, permanent CISO function bookable as an add-on. For organisations without an in-house CISO.
Learn moreGap assessment, roadmap, implementation via the platform. Fixed price from 4,500 euros.
Learn moreSelf-check available
Free, no signup, around 5 minutes. Detailed evaluation by email if desired.
Not a customer story, but recurring patterns from conversations with OT and security leads, alongside how the platform handles them.
Manufacturing across several sites means knowing the security posture of every plant, not just headquarters. Customer audits and OEM requirements ask about the site where the part is made. The review therefore has to exist per plant, on a fixed rhythm and against the same scale. Four plants assessing on their own produce four truths.
The cycle runs as a campaign across all sites, using the same question catalogue and scoring scale, for example along IEC 62443-2-1. Each plant sees its progress, the group level sees all of them side by side. The released snapshot freezes the state at the moment of release. In a customer audit you can evidence not only where you stand today, but where you stood two years ago and what changed since.
Production equipment runs ten years and more. Whatever was not required at specification time often cannot be retrofitted later. The usual flow has two stages: first clarify internally which security requirements apply to this machine, then walk through with the equipment supplier what they can meet. No supplier meets everything, and the remainder is what decides.
Both stages run as separate assessments with phase and section status, the questionnaires attach as documents. Internal clarification has to be complete before the supplier stage starts. Whatever the supplier cannot meet stays on record as a finding and becomes a compensating measure of your own, with an owner. That makes it possible to show why a machine runs despite a known gap and what was secured instead.
Security metrics rarely fail at measurement and almost always at translation. The board wants three numbers and a direction, ISMS management wants the structure behind them, the operational level wants to know which plant is stuck on what. On top of that, every organisation has its own vocabulary, and a tool that does not speak it will not be used.
Metrics are modelled canonically along ISO/IEC 27004, with the distinction between performance and effectiveness measurement and the chain from base measure to objective. Outward facing, the terms can be renamed per tenant: a terminology table maps the standard vocabulary onto the wording of the organisation. On the same data, three views are available, for the board, for ISMS management and for operations, per plant with a traffic light and a group rollup.
Industry experience in automotive and manufacturing from 25 years of ISMS practice at PwC, Deloitte and KPMG. TISAX experience from OEM and Tier-1 mandates. Platform covers TISAX and NIS-2 from a single control set.
TISAX covers many NIS-2 minimum measures, but not all. In particular BSI reporting obligations (24/72 hours), management accountability and the NIS-2-specific supply chain logic are not part of TISAX. OdySecure maps both from a single control set so duplicate work falls away.
Tier-2 suppliers receive NIS-2 and TISAX requirements contractually from Tier-1 suppliers or OEMs. In practice that means supplier questionnaires with similar depth to NIS-2 obligations, without being directly NIS-2-affected. Structured answers are a competitive matter.
Product IP and CAD data are engineering assets with the highest confidentiality classification. NIS-2 requires encryption, access control and documented data flows. TISAX has its own protection levels for "high" and "very high" confidentiality that map directly.
No. The platform allows differentiated maturity levels per plant. Older plants with legacy OT and greenfield plants with modern equipment have different risk landscapes and compensating controls. Important is documentation of the differentiation, not one-size-fits-all.
Platform licence scales by headcount and site count. Multi-plant rollout typically 16 to 20 weeks for three to five plants in Germany, longer for international subsidiaries. Exact indication comes from the risk check.
Free risk check with indicative NIS-2 classification, TISAX status indicator and path recommendation. Ideally with IT leadership or TISAX owner plus management board present.
Book the NIS-2 risk checkIf the classification above fits your organisation, the path starts by determining where you stand, not with a project: once it is clear which obligations apply and where the gaps are, the modules that close them follow.
See the journey in five stationsMany companies treat NIS2 as a tick-box exercise. But compliance is not the same as resilience. The Cross-Border Cybersecurity Tour #2 in Saarbrücken made it clear: a functioning security operation outweighs any tool collection.
70% of SMEs treat NIS2 as a compliance checkbox. But organizations that see it as a strategic lever can turn regulatory requirements into operational excellence and genuine resilience.
Structured NIS-2 compliance: gap assessment, roadmap, and implementation in 12 weeks.
Learn moreFree self-check: where do you stand on the ten §30 BSIG measures? 30 questions, instant traffic light.
Learn moreThe ten regulated sectors OdySecure runs in.
Learn more