Important entity, same ten minimum measures
Annex II means lower sanctions than Annex I, but the same obligations across the ten minimum measures per §30 of the German NIS-2 implementation act. On incidents, the BSI supervision kicks in reactively.
Annex II of the German NIS-2 implementation act covers chemicals as an important entity. From 50 employees and 10 million euros revenue, the obligations apply. For operations with hazardous substances, the German major-accident regulation and SEVESO III directive add up. The Cybervize platform covers ISMS, OT assessment and supplier risk in one solution.
Book the NIS-2 risk check
Chemical companies with significant production or distribution size fall under NIS-2 Annex II as „important entity"; SEVESO / major-accident regulation applies additionally only to plants exceeding specific quantity thresholds for hazardous substances. Four consequences of this classification for chemical companies. Sector alone is not enough: classification additionally depends on size thresholds and concrete activity. The legally binding evaluation remains a matter for specialised counsel.
Annex II means lower sanctions than Annex I, but the same obligations across the ten minimum measures per §30 of the German NIS-2 implementation act. On incidents, the BSI supervision kicks in reactively.
Process control systems, MES, batch controllers and lab automation are part of the cybersecurity scope. A cyber incident in process OT can become a safety incident under the major-accident regulation.
Whoever falls under the German major-accident regulation (12th BImSchV) or the SEVESO III directive has a safety management system (SMS) for hazardous substances. Cyber incidents that can lead to substance releases are double-reportable.
Chemical supply chains often have single-source risks for precursors, specialty gases, catalysts. NIS-2 mandates supply-chain risk assessment. Plus supplier audits by customers in the pharmaceutical sector.
Five NIS-2 minimum measures per §30, translated for chemical practice.
Risk register that separates process control systems, MES and lab IT but ties them together. Cyber risks with impact on substance safety classified separately.
Procurement process for new process control systems with security requirements, patch management with planned shutdown windows, remote maintenance documented and segmented.
Incident response plan with three escalation paths: NIS-2 cyber incident to the BSI, major accident to environmental and occupational safety authorities, possibly pharma authorities for pharmaceutical actives.
BCM for plant outages with chemical safety as the top priority (safe plant state before availability). RTO and RPO per production asset documented.
Recipes, batch data and process know-how encrypted at rest and in transit. Key management central. Access rights on a need-to-know basis.
The Cybervize platform covers ISMS, BCM, assessment and supplier risk in one solution. For chemicals, OT modules and interfaces to SEVESO requirements are additionally relevant.
Free 30-minute initial call with an indicative NIS-2 classification, top-5 gaps and a path recommendation.
Learn more Service 02ISMS, compliance and evidence from a single platform. Multi-entity, multi-country, AI-supported.
Learn more Service 03Platform plus permanent CISO function. For organisations without an in-house CISO.
Learn more Service 04Gap assessment, roadmap, implementation via the platform. Fixed price from 4,500 euros.
Learn moreSelf-check available
Free, no signup, around 5 minutes. Detailed evaluation by email if desired.
Industry experience in manufacturing including chemicals and pharma from 25 years of ISMS practice at PwC, Deloitte and KPMG. Methodology built for audit acceptance towards the BSI, occupational-safety authority and environmental regulators.
Free risk check with indicative NIS-2 classification, major-accident interface and path recommendation. Ideally with IT security and production leadership present.
Book the NIS-2 risk checkStructured NIS-2 compliance: gap assessment, roadmap, and implementation in 12 weeks.
Learn moreFree self-check: where do you stand on the ten §30 BSIG measures? 30 questions, instant traffic light.
Learn moreThe ten regulated sectors the Cybervize platform runs in.
Learn moreMany companies treat NIS2 as a tick-box exercise. But compliance is not the same as resilience. The Cross-Border Cybersecurity Tour #2 in Saarbrücken made it clear: a functioning security operation outweighs any tool collection.
Most security programs do not fail at launch. They fail when initiative must become routine. Five binding routines for sustainable governance.
Organizations that treat AI agents as magic will never control them. What an AI agent actually is and why that changes everything.