NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Weiterführende Seiten

  • Blog
  • FAQ
  • Glossar
  • Use Cases
  • Branchen
  • Preisgestaltung

Offizielle Quellen

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Ihr Navigator durch die NIS2-Compliance

Rechtliches

  • Datenschutzerklärung
  • Allgemeine Geschäftsbedingungen
  • Cookie-Richtlinie
  • Impressum

Ressourcen

  • Blog
  • Use Cases
  • Branchen
  • Preise
  • FAQ
  • Glossar

Kontakt

Kontakt

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. Alle Rechte vorbehalten.

Entwickelt in DeutschlandAllianz für Cyber-Sicherheit — Teilnehmer
HomeIndustriesMechanical Engineering & Manufacturing

NIS2 for Mechanical Engineering and Manufacturing

Written by the NIS2Compass Team · Last updated: April 2026

Mechanical engineering and large parts of manufacturing fall under Annex 2 BSIG, typically as important entities with the full §30 duty catalog. Those with TISAX in place have already done a large part of the work. NIS2Compass structures the NIS2 duties such that you can map existing controls in a targeted way and close the gaps, instead of building parallel bureaucracy.

  • Complete §30 substep structure for TISAX users
  • Templates for §32 notifications and §38 management body training
  • OT pain points (unpatchable PLCs, CNC) addressed in practice
  • For family-owned businesses with 4-8-person IT teams
Try Pro · €29/monthBlog: Am I affected by NIS2?
Hosted in Germany·GDPR-compliant·cancellable monthly

Are you as a mechanical engineering firm affected by NIS2?

Sector

Annex 2 BSIG: mechanical engineering (NACE C28), motor vehicle manufacturing, medical devices, electronics/optics, electrical equipment.

Size

50+ employees or > €10M annual revenue. Classification as important entity with full §30 duty catalog.

Supply-chain special case

Suppliers below the threshold land in customer audits via §30 No. 4 BSIG: automotive OEMs, large machine builders, chemical industry.

Supplier special case? „Am I affected by NIS2?" in the blog

Typical NIS2 challenges in mechanical engineering

OT shopfloor without patches

PLCs, CNC and robot cells run for 10-15 years without manufacturer CVE processes. §30 No. 5 is technically unsolvable, compensating measures become mandatory.

TISAX and NIS2 in parallel

Those with automotive customers already meet TISAX. The gaps to §30 BSIG must be identified without documenting everything twice.

IP protection vs. §32 notification

No one wants industrial espionage incidents to become public. §32 BSIG enforces notification at significance. Where the threshold sits is not obvious.

How NIS2Compass helps mechanical engineering firms

A family-owned machine builder with 280 employees has had TISAX for three years. Now NIS2 comes on top, and no one wants parallel bureaucracy. NIS2Compass delivers the complete §30 BSIG implementation path in 124 substeps. For each substep, an existing TISAX record can be attached or the gap closed with a template. Typical gaps: notification per §32, management body training per §38, supplier documentation per §30 No. 4. No further €700/day consulting round: the user maps themselves, the platform provides the structure.

124 substeps structured

Map TISAX controls in a targeted way

Gap templates

§32 notification, §38 training, suppliers

Article A-18

NIS2 / ISO 27001 comparison (TISAX is based on it)

Which §30 BSIG obligations apply to manufacturing?

§30 No. 5

Network security and vulnerability management

The core duty for the shopfloor. Where OT is not patchable: strict network segmentation, asset inventory with protection classification, monitoring for anomalies. Document compensating measures.

§30 No. 4

Supply chain security

Automotive and larger buyers demand supplier audits. At the same time, the machine builder must assess its own suppliers. Software supply chains (PLC firmware, engineering tools) are particularly relevant.

§32

Notification procedure on significant incidents

24-h early warning, 72-h full notification, 1-month final report. The significance threshold (§2 No. 11 BSIG) is concretely relevant for production outages, IP loss and ransomware.

More in the blog: NIS2 vs. ISO 27001, Is ISO 27001 enough for NIS2 compliance?, NIS2 implementation step by step.

NIS2Compass in comparison for mechanical engineering firms

Comparison NIS2Compass vs. TISAX / NIS2 consulting, ISMS tool and self-implementation for mechanical engineering firms
KriteriumNIS2CompassKlassische BeratungISMS-ToolSelbstumsetzung
Monthly cost€29€700-1,200/day€200-2,000/month€0
Mapping workstructure providedconsultant takes over (expensive)for individual standardsbuild yourself
German templatesyes (45+)tailoredmostly Englishno
OT pain points addressedyes (articles A-21, A-22)depends on consultantgenericbuild yourself
Onboarding10 minutesdays to weeksdays + setupmonths
For 4-8-person IT teamsyestoo expensivetoo complexcapacity-challenged

Frequently asked questions on NIS2 in mechanical engineering

Ready to implement NIS2 cleanly alongside TISAX?

124 substeps, 45+ templates, no parallel bureaucracy.

Try Pro · €29/monthBlog: Am I affected by NIS2?
cancellable monthly·no setup fee·Hosted in Germany

Official sources

  • BSIG Annex 2 (German)
  • BSI recommendation on OT security (German)
  • BSI guide on NIS2 regulation (German)
  • §2 No. 11 BSIG (significant incident definition) (German)