Manufacturing & Chemicals
The line stops. So does every hour of revenue.
Manufacturers, chemical plants, and mechanical engineering firms run two worlds under one roof: office IT and production IT. Attackers take the path from one into the other — and downtime doesn't cost you data, it costs you days.
Does this apply to you?
Annex 2 · Sectors 3 and 5
Sector: Chemicals, and manufacturing / production of goods
Manufacturers and importers of chemical substances subject to REACH registration, plus — under NACE Rev. 2 — medical devices and in-vitro diagnostics, data-processing equipment and electronics (26), electrical equipment (27), machinery (28), motor vehicles and parts (29), and other transport equipment (30).
Entity of essential importance
at least 250 employees — or annual turnover above €50 million and an annual balance sheet total above €43 million
Applies to entity types under Annex 1 · Section 28(1), (2) BSIG
Important entity
at least 50 employees — or annual turnover and balance sheet total above €10 million
Applies to entity types under Annexes 1 and 2 · Section 28(1), (2) BSIG
Important for you: If you're listed in Annex 2, you count as an “important” entity — the lower threshold applies, but the obligations under Section 30 BSIG are the same ones.
Covered regardless of size: operators of critical facilities, qualified trust service providers, top-level domain registries, and DNS service providers (Section 28(1) Nos. 1, 2 BSIG); trust service providers always count as an important entity (Section 28(2) No. 1 BSIG). Employee count and financial figures are alternative thresholds (either one triggers coverage); for the financial figures, both values must be exceeded. Whether your specific company is covered is a case-by-case question — that's what lawyers are for.
What's typically in the register in this sector
These obligations decide it for you.
Section 30(2) No. 9 BSIG
Separate the office network from the shop floor
Concepts for personnel security, access control, and managing your ICT systems, products, and processes — this is where it's decided whether a click in the office ever reaches production.
Section 30(2) No. 6 BSIG
Prove effectiveness, don't just claim it
Concepts and procedures for evaluating effectiveness: a recovery test shows in two hours what ten pages of concept documents leave open.
Section 30(2) No. 8 BSIG
Cryptography where the know-how sits
Concepts and processes for cryptographic measures — design data on laptops and storage media is the core of your company's value.
Example (fictional): The supplier and the three lost days
An automotive supplier is hit through a phishing email in accounting. The attackers work their way further in until they reach the network that also carries production control. The line stops for three days.
Looking back, the most expensive part wasn't recovery — it was the missing separation between office and production, and the fact that nobody could say which systems were even affected. A well-maintained asset register would have answered that in minutes instead of days.
A freely invented example for illustration — no real customer, no legal advice
Here's how Compliverse takes this off your plate.
- 1
Measures with owners and deadlines — so network separation becomes a date on the calendar, not a good intention.
- 2
Risk scoring shows management which investment prevents which outage.
- 3
One completed item counts simultaneously toward NIS2, ISO 27001, and the GDPR evidence your customers ask for.
NIS2 in Manufacturing & Chemicals: frequently asked questions
Is my Manufacturing & Chemicals company in scope for NIS2?
Your sector is covered by Germany's BSI Act: Annex 2 · Sectors 3 and 5, sector Chemicals, and manufacturing / production of goods. That does not put you in scope automatically — a size threshold has to be met as well (Section 28(1), (2) BSIG). And no official notice arrives: you assess the classification yourself and register if it applies (Section 33 BSIG). Your sector also has an exception — it is set out on this page under “Are you in scope?”. Judging your individual case is a lawyer's job.
From what size does NIS2 apply to us?
You count as an essential entity from at least 250 employees — or annual turnover above €50 million and an annual balance sheet total above €43 million; as an important entity from at least 50 employees — or annual turnover and balance sheet total above €10 million (Section 28(1), (2) BSIG). Headcount and financial figures are alternatives to each other — but where the financial figures are used, both have to be exceeded. Some entity types are in scope regardless of size, among them operators of critical facilities and qualified trust service providers.
Which authority is responsible for us in Germany?
Registration and supervision sit with the Bundesamt für Sicherheit in der Informationstechnik (BSI) — Germany's Federal Office for Information Security (Section 33 BSIG). Security incidents, however, do not go there: they go to the joint reporting office of the BSI and the Federal Office of Civil Protection and Disaster Assistance (BBK) — early warning within 24 hours, report within 72 hours, follow-up report a month later (Section 32 BSIG). This is the most common misreading of the act — the supervisory authority and the reporting office are not the same body.
What happens if we do not implement NIS2?
The obligations do not go away: registration stays due (Section 33 BSIG), so do the risk-management measures (Section 30(2) BSIG), and reporting deadlines start running with the first significant incident (Section 32 BSIG). On top of that, Section 38 BSIG puts management personally on the hook: they have to approve the measures, oversee their implementation, and undergo training themselves. “I didn't know” does not carry here.
Find out in thirty seconds what applies to you.
Four questions, an honest first estimate — then you'll know which module to start with and what it costs.
What becomes important next
More industries
Legal status checked on 01/09/2026 · Every statement with a source · No legal advice