Important entity, same ten minimum measures
Annex II means lower sanctions than Annex I, but the same obligations across the ten minimum measures per § 30 of the German BSI Act. On incidents, the BSI supervision kicks in reactively.
Covered are the manufacture and trade of chemicals. Whether the obligations apply depends on company size. For operations with hazardous substances, the German major-accident regulation and SEVESO III directive also apply. Our vCISO leads the implementation of the information security obligations and works with OdySecure, the security platform by Cybervize.
Book the NIS-2 risk checkStandard case under § 28 BSIG. Calculating the figures in annual work units, attributing partner and linked enterprises, special cases and the final classification all require a case-by-case legal review.
Process control, plant safety and the protection of critical production interlock. In OdySecure the relevant catalogues sit side by side instead of in separate evidence trails.
The Seveso directive stays out: it governs plant safety, not information security. The classification under § 28 BSIG is set out below.
SEVESO, implemented in Germany as the major-accident regulation, also applies, but only to plants exceeding specific quantity thresholds for hazardous substances. Four consequences of this classification for chemical companies. Sector alone is not enough: classification depends on size thresholds and concrete activity as well. The legally binding evaluation remains a matter for specialised counsel.
Annex II means lower sanctions than Annex I, but the same obligations across the ten minimum measures per § 30 of the German BSI Act. On incidents, the BSI supervision kicks in reactively.
Process control systems, MES, batch controllers and lab automation are part of the cybersecurity scope. A cyber incident in process OT can become a safety incident under the major-accident regulation.
Whoever falls under the German major-accident regulation (12th BImSchV) or the SEVESO III directive has a safety management system (SMS) for hazardous substances. Cyber incidents that can lead to substance releases are double-reportable.
Chemical supply chains often have single-source risks for precursors, specialty gases, catalysts. NIS-2 mandates supply-chain risk assessment. Plus supplier audits by customers in the pharmaceutical sector.
Five NIS-2 minimum measures per §30, translated for chemical practice.
Risk register that separates process control systems, MES and lab IT but ties them together. Cyber risks with impact on substance safety classified separately.
Procurement process for new process control systems with security requirements, patch management with planned shutdown windows, remote maintenance documented and segmented.
Incident response plan with three escalation paths: NIS-2 cyber incident to the BSI, major accident to environmental and occupational safety authorities, possibly pharma authorities for pharmaceutical actives.
BCM for plant outages with chemical safety as the top priority (safe plant state before availability). RTO and RPO per production asset documented.
Recipes, batch data and process know-how encrypted at rest and in transit. Key management central. Access rights on a need-to-know basis.
Your vCISO works with OdySecure: ISMS, BCM, assessment and supplier risk on one data foundation. Especially relevant for chemicals: process OT in the risk register and supplier risk for single-source precursors.
Free 30-minute initial call with an indicative NIS-2 classification, top-5 gaps and a path recommendation.
Learn moreA senior CISO takes on the CISO function permanently, from €3,600/month. OdySecure is included in the mandate.
Learn moreISMS, compliance and evidence from a single platform. Multi-entity, multi-country, AI-supported.
Learn moreGap assessment, roadmap, implementation via the platform. Fixed price from 4,500 euros.
Learn moreSelf-check available
Free, no signup, around 5 minutes. Detailed evaluation by email if desired.
Methodology built for audit acceptance towards the BSI.
The safety management system under the 12th BImSchV covers substance safety, not cybersecurity. When a cyber attack can lead to uncontrolled process states, NIS-2 closes the gap. The major-accident regulation is not in the OdySecure catalogue, because it governs plant safety. In the ISMS you document cyber risks in relation to substance safety.
On a cyber incident with security impact: the BSI within 24 hours. On substance release or process anomaly: the competent environmental authority under the major-accident regulation. For pharmaceutical actives possibly BfArM. The reporting logic needs clear triage at the start of the incident.
Recipes and process IP are business-critical data with highest confidentiality. NIS-2 requires adequate encryption and access control. In practice: separate key sovereignty, need-to-know access, documented data flows to suppliers and customers.
Multi-country rollout typically 16 to 26 weeks, depending on plant count and sector-specific local obligations (e.g. NIS-2 vs national implementations in other EU states). The platform supports multi-country with consolidated group reporting.
No. Lab automation usually has lower protection needs than production-process OT. The platform supports differentiated protection assessment. Important is documentation of the assessment, not one-size-fits-all.
Free risk check with indicative NIS-2 classification, top-5 gaps and path recommendation. Ideally with IT security and production leadership present.
Book the NIS-2 risk checkIf the classification above fits your organisation, the first step is to establish where you stand. Once it is clear which obligations apply and where the gaps are, the question is who closes them: a vCISO working with OdySecure, or your own team with a platform licence.
Book a vCISO callSee the journey in five stationsMany companies treat NIS2 as a tick-box exercise. But compliance is not the same as resilience. The Cross-Border Cybersecurity Tour #2 in Saarbrücken made it clear: a functioning security operation outweighs any tool collection.
The cyber security market is full of promises. What separates substance from marketing is a track record you cannot fake. Why we turned 25 years of audit and implementation practice into a platform, not the other way around.
At Germany's industry summit, one line landed: security, innovation and competitiveness belong together. It sounds like consensus. It is actually an invoice. Nobody settles it in Berlin. You settle it on Monday, in your leadership meeting. One question reveals whether the line holds in your company.
Structured NIS-2 compliance: gap assessment, roadmap, and implementation in 12 weeks.
Learn moreFree self-check: where do you stand on the ten §30 BSIG measures? 30 questions, instant traffic light.
Learn moreThe ten regulated sectors in which we take on the CISO function.
Learn more