Important entity with reactive supervision
Annex II means lower sanctions than Annex I, but the same ten minimum measures per §30 of the German NIS-2 implementation act. Supervision is reactive but kicks in on incidents or audit findings.
Annex II of the German NIS-2 implementation act covers automotive through the NACE category vehicles and components as an important entity. TISAX audits remain mandatory for OEM suppliers. The Cybervize platform maps NIS-2 and TISAX from a single control set, plus OT modules for plant IT.
Book the NIS-2 risk check
OEMs and Tier-1/Tier-2 suppliers typically fall under NIS-2 Annex II as „important entity" and additionally carry contractual TISAX requirements from the automotive supply chain. Four consequences of this dual regulation for OEM suppliers and plant operators. Sector alone is not enough: NIS-2 Annex II classification depends on size thresholds and concrete activity; TISAX remains a contractual requirement, not statute. The legally binding evaluation remains a matter for specialised counsel.
Annex II means lower sanctions than Annex I, but the same ten minimum measures per §30 of the German NIS-2 implementation act. Supervision is reactive but kicks in on incidents or audit findings.
TISAX (Trusted Information Security Assessment Exchange) is the industry standard for OEM suppliers. Audit levels 1 to 3 depending on protection needs. NIS-2 covers many TISAX requirements but not all, and vice versa.
Production plants with OT (robotics, presses, paint shops) and engineering centres with CAD and product data have different risk landscapes. Both belong in the NIS-2 scope.
OEMs pass TISAX and NIS-2 requirements down to suppliers. Tier-1 suppliers pass them down to Tier-2 suppliers. Whoever sits in a supply chain receives the requirements contractually, even without being directly NIS-2-affected.
Five NIS-2 minimum measures translated into automotive practice (with TISAX cross-reference).
Risk register with plant OT (robotics, presses), engineering IT (CAD data, product IP) and office IT. Protection goals differ: production = availability, engineering = confidentiality, office = integrity.
Supplier inventory with tier classification and criticality. TISAX status of suppliers documented, alternative suppliers for single-source components identified.
Procurement process with security requirements for new production assets, patch management with maintenance windows, remote-maintenance access for machine vendors documented.
CAD data and product IP encrypted at rest and in transit, key management documented, data classification aligned with TISAX protection levels.
MFA for engineering workstations, cloud CAD platforms and supplier portals. Privileged accounts separated. Access rights recertified regularly.
The Cybervize platform covers ISMS, assessment (NIS-2 plus TISAX), TPRM and BCM in one solution. Especially relevant for automotive: TISAX mapping, multi-plant assessment, supplier tier logic.
Free 30-minute initial call with an indicative NIS-2 classification, top-5 gaps and a path recommendation.
Learn more Service 02ISMS, compliance and evidence from a single platform. Multi-entity, multi-country, AI-supported.
Learn more Service 03Platform plus permanent CISO function. For organisations without an in-house CISO.
Learn more Service 04Gap assessment, roadmap, implementation via the platform. Fixed price from 4,500 euros.
Learn moreSelf-check available
Free, no signup, around 5 minutes. Detailed evaluation by email if desired.
Industry experience in automotive and manufacturing from 25 years of ISMS practice at PwC, Deloitte and KPMG. TISAX experience from OEM and Tier-1 mandates. Platform covers TISAX and NIS-2 from a single control set.
Free risk check with indicative NIS-2 classification, TISAX status indicator and path recommendation. Ideally with IT leadership or TISAX owner plus management board present.
Book the NIS-2 risk checkStructured NIS-2 compliance: gap assessment, roadmap, and implementation in 12 weeks.
Learn moreFree self-check: where do you stand on the ten §30 BSIG measures? 30 questions, instant traffic light.
Learn moreThe ten regulated sectors the Cybervize platform runs in.
Learn moreMany companies treat NIS2 as a tick-box exercise. But compliance is not the same as resilience. The Cross-Border Cybersecurity Tour #2 in Saarbrücken made it clear: a functioning security operation outweighs any tool collection.
70% of SMEs treat NIS2 as a compliance checkbox. But organizations that see it as a strategic lever can turn regulatory requirements into operational excellence and genuine resilience.