Important entity, not essential
Annex II means lower sanctions than Annex I, but the same obligations across the ten minimum measures per § 30 of the German BSI Act. Supervision is reactive rather than proactive, but it kicks in after an incident.
Whether the obligations apply depends on company size. For plants with OT installations, IEC 62443 and supplier requirements add up. OdySecure, the security platform by Cybervize, covers ISMS, OT assessment and supplier risk in one solution.
Book the NIS-2 risk checkStandard case under § 28 BSIG. Calculating the figures in annual work units, attributing partner and linked enterprises, special cases and the final classification all require a case-by-case legal review.
A machine builder holds two roles at once: it runs its own production and ships products with digital elements. Different requirements follow from that, and in practice they overlap. In OdySecure they sit in one catalogue and share a data foundation.
NIS-2 is added where the thresholds of § 28 BSIG apply. That classification is set out below.
Four consequences arising from the classification above. Sector alone is not enough: classification as important or essential entity depends additionally on size thresholds and concrete activity. The legally binding evaluation of NIS-2 status remains a matter for specialised counsel.
Annex II means lower sanctions than Annex I, but the same obligations across the ten minimum measures per § 30 of the German BSI Act. Supervision is reactive rather than proactive, but it kicks in after an incident.
Plant controllers, SCADA systems and engineering workstations are part of the cybersecurity scope, not just office IT. IEC 62443 becomes the natural anchor standard.
If you supply OEMs under Annex I, you receive their supplier audits via contract. NIS-2 turns supplier compliance into a contractual matter.
Initial report within 24 hours, follow-up within 72 hours, final report within one month. Hard to maintain with an Excel-based ISMS.
Five of the ten minimum measures per §30, translated into mechanical engineering practice.
In practice: a risk register that separates office IT and plant OT but ties them together. Plant controllers carry their own assessment because the risks (production stoppage) differ from office risks (data loss).
Supplier inventory with criticality ratings, documented security requirements in contracts, concentration risk for single-source OT suppliers. TISAX requirements can dock here for automotive customers.
Patch management for plant equipment, secure procurement of new controllers, documented remote-maintenance access for machine vendors.
Incident response plan that distinguishes office IT incidents from plant downtime. Escalation paths to the BSI with documented 24- and 72-hour deadlines.
BCM plan for production outages, RTO and RPO per critical machine, restart sequence documented. Beyond office backup, because plant downtime costs six-figure daily rates.
OdySecure covers ISMS, BCM, Third-Party Risk Management and Assessment in one solution. Especially relevant for mechanical engineering: multi-site assessment, OT modules and supplier risk.
Free 30-minute initial call with an indicative NIS-2 classification, top-5 gaps and a path recommendation.
Learn moreISMS, compliance and evidence from a single platform. Multi-entity, multi-country, AI-supported.
Learn moreThe platform, permanent CISO function bookable as an add-on. For organisations without an in-house CISO.
Learn moreGap assessment, roadmap, implementation via the platform. Fixed price from 4,500 euros.
Learn moreSelf-check available
Free, no signup, around 5 minutes. Detailed evaluation by email if desired.
Not a customer story, but recurring patterns from conversations with OT and security leads, alongside how the platform handles them.
A manufacturer with four plants in three countries needs to know the security posture of every plant, not just headquarters. The review should run on a fixed rhythm, for example a three-year cycle along IEC 62443-2-1, and it must be comparable. Four plants assessing on their own produce four truths and no group-level picture.
The cycle runs as a campaign across all plants, using the same question catalogue and the same scoring scale. Each plant sees its own progress, the group level sees all plants side by side. The released snapshot is what matters: it freezes the state at the moment of release. In the next audit you can evidence not only where you stand today, but where you stood two years ago and what changed since.
As soon as a machine is being specified, it must be clear what it brings security-wise and what it does not. Retrofitting is expensive and, for OT equipment running ten years or more, often impossible. The usual flow has two stages: first clarify internally which requirements apply, then walk through with the equipment supplier what they can meet. The interesting part is the remainder, because no supplier meets everything.
Both stages run as separate assessments with phase and section status, the questionnaires attach as documents. Internal clarification has to be complete before the supplier stage starts, otherwise you negotiate over requirements you have not defined yet. Whatever the supplier cannot meet stays on record as a finding and becomes a compensating measure of your own, with an owner. That answers the audit question of why a machine runs despite a known gap.
Day-to-day OT security consists of recurring duties: a daily patch check, a weekly vulnerability review, the annual health check due per plant. Many organisations have built themselves a ticketing solution on a low-code platform. It works until the colleague who built it moves on, and it has no link to the ISMS.
The rhythm is held as recurring tasks with status, severity, due date and ownership, per plant. Deliberately modelled as tasks and not as measures, because operational routine is not evidence of security. It therefore does not appear in the security structure and does not inflate the measure graph. Mixing the two makes it impossible to show later which measure actually addresses a risk.
Industry experience in manufacturing and KRITIS operators from 25 years of ISMS leadership at PwC, Deloitte and KPMG. The platform methodology was built under the BMFTR StartupSecure programme with the CISPA incubator.
Most likely yes. Annex 2 of the German BSIG (NIS-2 Annex II) covers manufacturing as an important entity, from 50 employees or once annual turnover and balance sheet total each exceed 10 million euros. Mechanical engineering is in the NACE categories explicitly named. The legally binding evaluation remains a matter for counsel. We provide the expert pre-assessment in the 30-minute risk check.
IEC 62443 is not legally mandatory but it is the relevant standard for plant OT. NIS-2 requires the minimum measures without explicitly naming IEC 62443. In practice IEC 62443 docks cleanly onto the risk-analysis obligation in §30. OdySecure maps both control sets together.
Legacy OT without update capability is reality in almost every plant. NIS-2 does not require all measures to be technically identical; it requires appropriate measures at the state of the art. Compensating controls (network segmentation, monitoring, physical access controls) are accepted. Documented risk acceptance instead of swept under the rug.
TISAX covers many minimum measures, but not all NIS-2 obligations. In particular the BSI reporting obligations (24- and 72-hour deadlines), management accountability and the specific supply chain logic under NIS-2 are not part of TISAX. OdySecure maps TISAX and NIS-2 from a single control set.
NIS-2 gap assessment as a fixed price from 4,500 euros. Audit-ready NIS-2 readiness typically in 8 to 12 weeks for one- to three-site firms, implementation from 18,000 euros. Holdings with multiple plants need 16 to 20 weeks. The exact cost estimate comes from the risk check.
Free risk check with indicative NIS-2 classification, top-5 gaps, path recommendation and cost estimate. Ideally with plant management or IT leadership plus management board present.
Book the NIS-2 risk checkIf the classification above fits your organisation, the path starts by determining where you stand, not with a project: once it is clear which obligations apply and where the gaps are, the modules that close them follow.
See the journey in five stationsMany companies treat NIS2 as a tick-box exercise. But compliance is not the same as resilience. The Cross-Border Cybersecurity Tour #2 in Saarbrücken made it clear: a functioning security operation outweighs any tool collection.
The cyber security market is full of promises. What separates substance from marketing is a track record you cannot fake. Why we turned 25 years of audit and implementation practice into a platform, not the other way around.
At Germany's industry summit, one line landed: security, innovation and competitiveness belong together. It sounds like consensus. It is actually an invoice. Nobody settles it in Berlin. You settle it on Monday, in your leadership meeting. One question reveals whether the line holds in your company.
Structured NIS-2 compliance: gap assessment, roadmap, and implementation in 12 weeks.
Learn moreFree self-check: where do you stand on the ten §30 BSIG measures? 30 questions, instant traffic light.
Learn moreThe ten regulated sectors OdySecure runs in.
Learn more