Cybervize
NIS-2 for chemicals

Chemicals are Annex II. Major-accident rules and SEVESO apply alongside.

Covered are the manufacture and trade of chemicals. Whether the obligations apply depends on company size. For operations with hazardous substances, the German major-accident regulation and SEVESO III directive also apply. Our vCISO leads the implementation of the information security obligations and works with OdySecure, the security platform by Cybervize.

Book the NIS-2 risk check

NIS-2 classification: chemicals

Classification
Annex 2 BSIG (Annex II), important entity
Size threshold
from 50 employees, or turnover and balance sheet each above €10M
Reporting deadlines
for a significant incident: 24 hours initial report, 72 hours follow-up, one month final report
Obligations
10 minimum measures under § 30 BSIG
On top
German major-accident regulation and SEVESO III from the quantity thresholds for hazardous substances

Standard case under § 28 BSIG. Calculating the figures in annual work units, attributing partner and linked enterprises, special cases and the final classification all require a case-by-case legal review.

Cybervize building blocks for the chemical industry

Your vCISO works with OdySecure: ISMS, BCM, assessment and supplier risk on one data foundation. Especially relevant for chemicals: process OT in the risk register and supplier risk for single-source precursors.

Self-check available

NIS-2 maturity check: 30 questions, 10 §30 BSIG measures, instant traffic light

Free, no signup, around 5 minutes. Detailed evaluation by email if desired.

Start the check
More about NIS-2 for chemicals

What NIS-2 means in practice for the chemical industry

SEVESO, implemented in Germany as the major-accident regulation, also applies, but only to plants exceeding specific quantity thresholds for hazardous substances. Four consequences of this classification for chemical companies. Sector alone is not enough: classification depends on size thresholds and concrete activity as well. The legally binding evaluation remains a matter for specialised counsel.

01

Important entity, same ten minimum measures

Annex II means lower sanctions than Annex I, but the same obligations across the ten minimum measures per § 30 of the German BSI Act. On incidents, the BSI supervision kicks in reactively.

02

OT process control systems in scope

Process control systems, MES, batch controllers and lab automation are part of the cybersecurity scope. A cyber incident in process OT can become a safety incident under the major-accident regulation.

03

Major-accident regulation and SEVESO as interface

Whoever falls under the German major-accident regulation (12th BImSchV) or the SEVESO III directive has a safety management system (SMS) for hazardous substances. Cyber incidents that can lead to substance releases are double-reportable.

04

Supply chain risk with concentration

Chemical supply chains often have single-source risks for precursors, specialty gases, catalysts. NIS-2 mandates supply-chain risk assessment. Plus supplier audits by customers in the pharmaceutical sector.

What applies in chemicals, and what sits in the catalogue

Process control, plant safety and the protection of critical production interlock. In OdySecure the relevant catalogues sit side by side instead of in separate evidence trails.

  • ISO/IEC 27001The shared language of the management system.123 records, reference
  • IEC 62443Security of process control: zones, conduits and security levels per plant.37 records, reference
  • ISO 22301Continuity of production, with BIA, RTO and RPO.26 records, reference
  • German BSI Act 2025The German implementation with operator duties.18 records, full catalogue
  • KRITIS umbrella actPhysical resilience of critical assets. Cybersecurity is governed alongside it by the BSIG.16 records, full catalogue
  • CER DirectiveResilience of critical entities, beyond IT.14 records, full catalogue

The Seveso directive stays out: it governs plant safety, not information security. The classification under § 28 BSIG is set out below.

Full catalogue with depth and type of assurance

Five minimum measures with chemical examples

Five NIS-2 minimum measures per §30, translated for chemical practice.

01

Risk analysis with process-OT focus

Risk register that separates process control systems, MES and lab IT but ties them together. Cyber risks with impact on substance safety classified separately.

02

Security in procurement and maintenance of process equipment

Procurement process for new process control systems with security requirements, patch management with planned shutdown windows, remote maintenance documented and segmented.

03

Multi-track incident response

Incident response plan with three escalation paths: NIS-2 cyber incident to the BSI, major accident to environmental and occupational safety authorities, possibly pharma authorities for pharmaceutical actives.

04

Business continuity for production outages

BCM for plant outages with chemical safety as the top priority (safe plant state before availability). RTO and RPO per production asset documented.

05

Cryptography for process recipes

Recipes, batch data and process know-how encrypted at rest and in transit. Key management central. Access rights on a need-to-know basis.

Why Cybervize fits the chemical industry

Methodology built for audit acceptance towards the BSI.

Process OT
control system and MES experience
Multi-site
group-wide rollout
NIS-2 + SEVESO
interface documented (no catalogue)
50
frameworks held as a catalogue

Frequently asked questions from the chemical industry

The safety management system under the 12th BImSchV covers substance safety, not cybersecurity. When a cyber attack can lead to uncontrolled process states, NIS-2 closes the gap. The major-accident regulation is not in the OdySecure catalogue, because it governs plant safety. In the ISMS you document cyber risks in relation to substance safety.

On a cyber incident with security impact: the BSI within 24 hours. On substance release or process anomaly: the competent environmental authority under the major-accident regulation. For pharmaceutical actives possibly BfArM. The reporting logic needs clear triage at the start of the incident.

Recipes and process IP are business-critical data with highest confidentiality. NIS-2 requires adequate encryption and access control. In practice: separate key sovereignty, need-to-know access, documented data flows to suppliers and customers.

Multi-country rollout typically 16 to 26 weeks, depending on plant count and sector-specific local obligations (e.g. NIS-2 vs national implementations in other EU states). The platform supports multi-country with consolidated group reporting.

No. Lab automation usually has lower protection needs than production-process OT. The platform supports differentiated protection assessment. Important is documentation of the assessment, not one-size-fits-all.

Classify NIS-2 for chemicals in 30 minutes

Free risk check with indicative NIS-2 classification, top-5 gaps and path recommendation. Ideally with IT security and production leadership present.

Book the NIS-2 risk check

In scope? How you get to a provable security posture

If the classification above fits your organisation, the first step is to establish where you stand. Once it is clear which obligations apply and where the gaps are, the question is who closes them: a vCISO working with OdySecure, or your own team with a platform licence.

Book a vCISO callSee the journey in five stations

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT