← All industries

Food Industry

Traceability is a legal duty — even when the IT goes down.

Food businesses in wholesale and in industrial production and processing are important entities under the law. Batch tracking, cold chains, and traceability all depend on systems nobody can afford to lose for a day.

Does this apply to you?

Annex 2 · Sector 4

Sector: Production, processing and distribution of food

Food businesses within the meaning of Article 3(2) of Regulation (EC) No 178/2002 that are active in wholesale and in industrial production and processing.

Entity of essential importance

at least 250 employees — or annual turnover above €50 million and an annual balance sheet total above €43 million

Applies to entity types under Annex 1 · Section 28(1), (2) BSIG

Important entity

at least 50 employees — or annual turnover and balance sheet total above €10 million

Applies to entity types under Annexes 1 and 2 · Section 28(1), (2) BSIG

Important for you: The scope is narrower than many assume: it targets wholesale and industrial production — not restaurants or an individual retail location.

Covered regardless of size: operators of critical facilities, qualified trust service providers, top-level domain registries, and DNS service providers (Section 28(1) Nos. 1, 2 BSIG); trust service providers always count as an important entity (Section 28(2) No. 1 BSIG). Employee count and financial figures are alternative thresholds (either one triggers coverage); for the financial figures, both values must be exceeded. Whether your specific company is covered is a case-by-case question — that's what lawyers are for.

What's typically in the register in this sector

ERP & batch managementProduction control systemsCold chain monitoringQuality and lab systemsWarehousing & order pickingLabeling

These obligations decide it for you.

Section 30(2) No. 3 BSIG

Maintain operations — perishable goods don't wait

Backup management, recovery, and crisis management run against a clock here that nobody can pause.

Section 30(2) No. 9 BSIG

Keep production IT properly separated

Concepts for personnel security, access control, and managing your ICT systems — so an incident in the office never reaches the filling line.

Section 30(2) No. 6 BSIG

Test effectiveness, don't just claim it

An annual recovery test of your batch data tells you more about your actual security than any concept paper.

Example (fictional): The dairy and the missing batch

A mid-sized processor loses access to its ERP system in an encryption attack. Production keeps running, but batch assignment for the last two days exists only on handwritten notes.

When a customer requests a traceability report shortly after, an IT incident becomes a food-safety matter. The company delivers the answer — three days late and at considerable cost. A tested recovery path would have avoided both.

A freely invented example for illustration — no real customer, no legal advice

Here's how Compliverse takes this off your plate.

  • 1

    Critical systems with recovery time objectives in the register — including proof of testing.

  • 2

    Measures with owners and deadlines, so network separation and restore tests become appointments, not intentions.

  • 3

    An evidence package that answers trading partners and auditors alike.

NIS2 in Food Industry: frequently asked questions

Is my Food Industry company in scope for NIS2?

Your sector is covered by Germany's BSI Act: Annex 2 · Sector 4, sector Production, processing and distribution of food. That does not put you in scope automatically — a size threshold has to be met as well (Section 28(1), (2) BSIG). And no official notice arrives: you assess the classification yourself and register if it applies (Section 33 BSIG). Your sector also has an exception — it is set out on this page under “Are you in scope?”. Judging your individual case is a lawyer's job.

From what size does NIS2 apply to us?

You count as an essential entity from at least 250 employees — or annual turnover above €50 million and an annual balance sheet total above €43 million; as an important entity from at least 50 employees — or annual turnover and balance sheet total above €10 million (Section 28(1), (2) BSIG). Headcount and financial figures are alternatives to each other — but where the financial figures are used, both have to be exceeded. Some entity types are in scope regardless of size, among them operators of critical facilities and qualified trust service providers.

Which authority is responsible for us in Germany?

Registration and supervision sit with the Bundesamt für Sicherheit in der Informationstechnik (BSI) — Germany's Federal Office for Information Security (Section 33 BSIG). Security incidents, however, do not go there: they go to the joint reporting office of the BSI and the Federal Office of Civil Protection and Disaster Assistance (BBK) — early warning within 24 hours, report within 72 hours, follow-up report a month later (Section 32 BSIG). This is the most common misreading of the act — the supervisory authority and the reporting office are not the same body.

What happens if we do not implement NIS2?

The obligations do not go away: registration stays due (Section 33 BSIG), so do the risk-management measures (Section 30(2) BSIG), and reporting deadlines start running with the first significant incident (Section 32 BSIG). On top of that, Section 38 BSIG puts management personally on the hook: they have to approve the measures, oversee their implementation, and undergo training themselves. “I didn't know” does not carry here.

Find out in thirty seconds what applies to you.

Four questions, an honest first estimate — then you'll know which module to start with and what it costs.

What becomes important next

More industries

Legal status checked on 01/09/2026 · Every statement with a source · No legal advice