Important entity, same ten minimum measures
Annex II means lower sanctions than Annex I, but the same obligations across the ten minimum measures per § 30 of the German BSI Act. On incidents, the BSI supervision kicks in reactively.
Covered are the manufacture and trade of chemicals. Whether the obligations apply depends on company size. For operations with hazardous substances, the German major-accident regulation and SEVESO III directive add up. OdySecure, the security platform by Cybervize, covers ISMS, OT assessment and supplier risk in one solution.
Book the NIS-2 risk checkStandard case under § 28 BSIG. Calculating the figures in annual work units, attributing partner and linked enterprises, special cases and the final classification all require a case-by-case legal review.
Process control, plant safety and the protection of critical production interlock. In OdySecure the relevant catalogues sit side by side instead of in separate evidence trails.
The Seveso directive stays out: it governs plant safety, not information security. The classification under § 28 BSIG is set out below.
SEVESO, implemented in Germany as the major-accident regulation, applies additionally only to plants exceeding specific quantity thresholds for hazardous substances. Four consequences of this classification for chemical companies. Sector alone is not enough: classification additionally depends on size thresholds and concrete activity. The legally binding evaluation remains a matter for specialised counsel.
Annex II means lower sanctions than Annex I, but the same obligations across the ten minimum measures per § 30 of the German BSI Act. On incidents, the BSI supervision kicks in reactively.
Process control systems, MES, batch controllers and lab automation are part of the cybersecurity scope. A cyber incident in process OT can become a safety incident under the major-accident regulation.
Whoever falls under the German major-accident regulation (12th BImSchV) or the SEVESO III directive has a safety management system (SMS) for hazardous substances. Cyber incidents that can lead to substance releases are double-reportable.
Chemical supply chains often have single-source risks for precursors, specialty gases, catalysts. NIS-2 mandates supply-chain risk assessment. Plus supplier audits by customers in the pharmaceutical sector.
Five NIS-2 minimum measures per §30, translated for chemical practice.
Risk register that separates process control systems, MES and lab IT but ties them together. Cyber risks with impact on substance safety classified separately.
Procurement process for new process control systems with security requirements, patch management with planned shutdown windows, remote maintenance documented and segmented.
Incident response plan with three escalation paths: NIS-2 cyber incident to the BSI, major accident to environmental and occupational safety authorities, possibly pharma authorities for pharmaceutical actives.
BCM for plant outages with chemical safety as the top priority (safe plant state before availability). RTO and RPO per production asset documented.
Recipes, batch data and process know-how encrypted at rest and in transit. Key management central. Access rights on a need-to-know basis.
OdySecure covers ISMS, BCM, assessment and supplier risk in one solution. For chemicals, OT modules and interfaces to SEVESO requirements are additionally relevant.
Free 30-minute initial call with an indicative NIS-2 classification, top-5 gaps and a path recommendation.
Learn moreISMS, compliance and evidence from a single platform. Multi-entity, multi-country, AI-supported.
Learn moreThe platform, permanent CISO function bookable as an add-on. For organisations without an in-house CISO.
Learn moreGap assessment, roadmap, implementation via the platform. Fixed price from 4,500 euros.
Learn moreSelf-check available
Free, no signup, around 5 minutes. Detailed evaluation by email if desired.
Industry experience in manufacturing including chemicals and pharma from 25 years of ISMS practice at PwC, Deloitte and KPMG. Methodology built for audit acceptance towards the BSI, occupational-safety authority and environmental regulators.
The safety management system under the 12th BImSchV covers substance safety, not cybersecurity. When a cyber attack can lead to uncontrolled process states, NIS-2 closes the gap. The platform maps both systems together so cyber risks are documented in relation to substance safety.
On a cyber incident with security impact: the BSI within 24 hours. On substance release or process anomaly: the competent environmental authority under the major-accident regulation. For pharmaceutical actives possibly BfArM. The reporting logic needs clear triage at the start of the incident.
Recipes and process IP are business-critical data with highest confidentiality. NIS-2 requires adequate encryption and access control. In practice: separate key sovereignty, need-to-know access, documented data flows to suppliers and customers.
Multi-country rollout typically 16 to 26 weeks, depending on plant count and sector-specific local obligations (e.g. NIS-2 vs national implementations in other EU states). The platform supports multi-country with consolidated group reporting.
No. Lab automation usually has lower protection needs than production-process OT. The platform supports differentiated protection assessment. Important is documentation of the assessment, not one-size-fits-all.
Free risk check with indicative NIS-2 classification, major-accident interface and path recommendation. Ideally with IT security and production leadership present.
Book the NIS-2 risk checkIf the classification above fits your organisation, the path starts by determining where you stand, not with a project: once it is clear which obligations apply and where the gaps are, the modules that close them follow.
See the journey in five stationsMany companies treat NIS2 as a tick-box exercise. But compliance is not the same as resilience. The Cross-Border Cybersecurity Tour #2 in Saarbrücken made it clear: a functioning security operation outweighs any tool collection.
The cyber security market is full of promises. What separates substance from marketing is a track record you cannot fake. Why we turned 25 years of audit and implementation practice into a platform, not the other way around.
At Germany's industry summit, one line landed: security, innovation and competitiveness belong together. It sounds like consensus. It is actually an invoice. Nobody settles it in Berlin. You settle it on Monday, in your leadership meeting. One question reveals whether the line holds in your company.
Structured NIS-2 compliance: gap assessment, roadmap, and implementation in 12 weeks.
Learn moreFree self-check: where do you stand on the ten §30 BSIG measures? 30 questions, instant traffic light.
Learn moreThe ten regulated sectors OdySecure runs in.
Learn more