Cybervize
NIS-2 for mechanical engineering

NIS-2 hits mechanical engineering through the manufacturing annex.

Whether the obligations apply depends on company size. For plants with OT installations, IEC 62443 and supplier requirements also apply. Our vCISO leads the implementation of the information security obligations and works with OdySecure, the security platform by Cybervize.

Book the NIS-2 risk check

NIS-2 classification: mechanical engineering

Classification
Annex II, important entity
Size threshold
from 50 employees, or turnover and balance sheet each above €10M
Reporting deadlines
for a significant incident: 24 hours initial report, 72 hours follow-up, one month final report
Obligations
10 minimum measures under § 30 BSIG
Adjacent standard
IEC 62443 for plant OT

Standard case under § 28 BSIG. Calculating the figures in annual work units, attributing partner and linked enterprises, special cases and the final classification all require a case-by-case legal review.

Cybervize building blocks for mechanical engineering

Your vCISO works with OdySecure: ISMS, BCM, Third-Party Risk Management and Assessment on one data foundation. Especially relevant for mechanical engineering: multi-site assessment, IEC 62443 for plant OT and supplier risk.

Self-check available

NIS-2 maturity check: 30 questions, 10 §30 BSIG measures, instant traffic light

Free, no signup, around 5 minutes. Detailed evaluation by email if desired.

Start the check
More about NIS-2 for mechanical engineering

What NIS-2 means in practice for mechanical engineering companies

Sector alone is not enough: whether the obligations apply also depends on size thresholds and concrete activity. The legally binding evaluation of NIS-2 status remains a matter for specialised counsel.

01

Important entity, not essential

Annex II means lower sanctions than Annex I, but the same obligations across the ten minimum measures per § 30 of the German BSI Act. Supervision is reactive rather than proactive, but it kicks in after an incident.

02

OT and plant IT are in scope

Plant controllers, SCADA systems and engineering workstations are part of the cybersecurity scope, not just office IT. IEC 62443 becomes the natural anchor standard.

03

Supplier requirements flow downstream

If you supply customers that fall under NIS-2 themselves, their supplier audits are passed down to you. NIS-2 turns supplier compliance into a contractual matter.

04

BSI reporting obligations after an incident

Initial report within 24 hours, follow-up within 72 hours, final report within one month. Hard to maintain with an Excel-based ISMS.

What applies in mechanical engineering, and what sits in the catalogue

A machine builder holds two roles at once: it runs its own production and ships products with digital elements. Different requirements follow from that, and in practice they overlap. In OdySecure they sit in one catalogue and share a data foundation.

  • ISO/IEC 27001The shared language of the management system. The other catalogues map onto it where they overlap.123 records, reference
  • Cyber Resilience ActSecurity requirements for everything you ship with digital elements.44 records, full catalogue
  • IEC 62443Security of your production and of the plants you deliver: zones, conduits, security levels.37 records, reference
  • ISO 22301Continuity of production, with BIA, RTO and RPO.26 records, reference
  • ISO/IEC 27036-3Security of the hardware, software and services supply chain.12 records, reference
  • RED cybersecurityThe cyber article of the radio equipment directive, where your machines transmit.8 records, full catalogue

NIS-2 is added where the thresholds of § 28 BSIG apply. That classification is set out below.

Full catalogue with depth and type of assurance

Five NIS-2 minimum measures with mechanical engineering examples

Five of the ten minimum measures per §30, translated into mechanical engineering practice.

01

Risk analysis and information system security

In practice: a risk register that separates office IT and plant OT but ties them together. Plant controllers carry their own assessment because the risks (production stoppage) differ from office risks (data loss).

02

Supply chain security

Supplier inventory with criticality ratings, documented security requirements in contracts, concentration risk for single-source OT suppliers. TISAX requirements can dock here for automotive customers.

03

Security in procurement, development and maintenance

Patch management for plant equipment, secure procurement of new controllers, documented remote-maintenance access for machine vendors.

04

Incident response

Incident response plan that distinguishes office IT incidents from plant downtime. Escalation paths to the BSI with documented 24- and 72-hour deadlines.

05

Business continuity management

BCM plan for production outages, RTO and RPO per critical machine, restart sequence documented. Beyond office backup, because plant downtime costs six-figure daily rates.

Three requirements we keep meeting in mechanical engineering

Not a customer story, but recurring patterns from conversations with OT and security leads, alongside how the platform handles them.

One assessment cycle for every plant

The requirement

A manufacturer with four plants in three countries needs to know the security posture of every plant, not just headquarters. The review should run on a fixed rhythm, for example a three-year cycle along IEC 62443-2-1, and it must be comparable. Four plants assessing on their own produce four truths and no group-level picture.

How the platform handles it

The cycle runs as a campaign across all plants, using the same question catalogue and the same scoring scale. Each plant sees its own progress, the group level sees all plants side by side. The released snapshot is what matters: it freezes the state at the moment of release. In the next audit you can evidence not only where you stand today, but where you stood two years ago and what changed since.

View the assessment module

Security by design, before the machine is ordered

The requirement

As soon as a machine is being specified, it must be clear what it brings security-wise and what it does not. Retrofitting is expensive and, for OT equipment running ten years or more, often impossible. The usual flow has two stages: first clarify internally which requirements apply, then walk through with the equipment supplier what they can meet. The interesting part is the remainder, because no supplier meets everything.

How the platform handles it

Both stages run as separate assessments with phase and section status, the questionnaires attach as documents. Internal clarification has to be complete before the supplier stage starts, otherwise you negotiate over requirements you have not defined yet. Whatever the supplier cannot meet stays on record as a finding and becomes a compensating measure of your own, with an owner. That answers the audit question of why a machine runs despite a known gap.

View the TPRM module

An operating rhythm instead of a home-built ticket tool

The requirement

Day-to-day OT security consists of recurring duties: a daily patch check, a weekly vulnerability review, the annual health check due per plant. Many organisations have built themselves a ticketing solution on a low-code platform. It works until the colleague who built it moves on, and it has no link to the ISMS.

How the platform handles it

The rhythm is held as recurring tasks with status, severity, due date and ownership, per plant. Deliberately modelled as tasks and not as measures, because operational routine is not evidence of security. It therefore does not appear in the security structure and does not inflate the measure graph. Mixing the two makes it impossible to show later which measure actually addresses a risk.

View the ISMS module

Why Cybervize fits mechanical engineering

Reference: Carve-out as Interim CISO: building up information security at an international mechanical engineering company.

IEC 62443
OT assessment as standard
Multi-site
Group-wide rollout
NIS-2 + TISAX
from one control mapping
50
frameworks held as a catalogue

Frequently asked questions from mechanical engineering

Most likely yes. Annex 2 of the German BSIG (NIS-2 Annex II) covers manufacturing as an important entity, from 50 employees or once annual turnover and balance sheet total each exceed 10 million euros. Mechanical engineering is in the NACE categories explicitly named. The legally binding evaluation remains a matter for counsel. We provide the expert pre-assessment in the 30-minute risk check.

IEC 62443 is not legally mandatory but it is the relevant standard for plant OT. NIS-2 requires the minimum measures without explicitly naming IEC 62443. In practice IEC 62443 docks cleanly onto the risk-analysis obligation in §30. OdySecure maps both control sets together.

Legacy OT without update capability is reality in almost every plant. NIS-2 does not require all measures to be technically identical; it requires appropriate measures at the state of the art. Compensating controls (network segmentation, monitoring, physical access controls) are accepted. Documented risk acceptance instead of swept under the rug.

TISAX covers many minimum measures, but not all NIS-2 obligations. In particular the BSI reporting obligations (24- and 72-hour deadlines), management accountability and the specific supply chain logic under NIS-2 are not part of TISAX. OdySecure maps TISAX and NIS-2 from a single control set.

NIS-2 gap assessment as a fixed price from 4,500 euros. Audit-ready NIS-2 readiness typically in 8 to 12 weeks for one- to three-site firms, implementation from 18,000 euros. Holdings with multiple plants need 16 to 20 weeks. The exact cost estimate comes from the risk check.

Clarify your NIS-2 position as a mechanical engineering firm in 30 minutes

Free risk check with indicative NIS-2 classification, top-5 gaps, path recommendation and cost estimate. Ideally with plant management or IT leadership plus management board present.

Book the NIS-2 risk check

In scope? How you get to a provable security posture

If the classification above fits your organisation, the first step is to establish where you stand. Once it is clear which obligations apply and where the gaps are, the question is who closes them: a vCISO working with OdySecure, or your own team with a platform licence.

Book a vCISO callSee the journey in five stations

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT