Written by the NIS2Compass Team ·
Mechanical engineering and large parts of manufacturing fall under Annex 2 BSIG, typically as important entities with the full §30 duty catalog. Those with TISAX in place have already done a large part of the work. NIS2Compass structures the NIS2 duties such that you can map existing controls in a targeted way and close the gaps, instead of building parallel bureaucracy.
Sector
Annex 2 BSIG: mechanical engineering (NACE C28), motor vehicle manufacturing, medical devices, electronics/optics, electrical equipment.
Size
50+ employees or > €10M annual revenue. Classification as important entity with full §30 duty catalog.
Supply-chain special case
Suppliers below the threshold land in customer audits via §30 No. 4 BSIG: automotive OEMs, large machine builders, chemical industry.
PLCs, CNC and robot cells run for 10-15 years without manufacturer CVE processes. §30 No. 5 is technically unsolvable, compensating measures become mandatory.
Those with automotive customers already meet TISAX. The gaps to §30 BSIG must be identified without documenting everything twice.
No one wants industrial espionage incidents to become public. §32 BSIG enforces notification at significance. Where the threshold sits is not obvious.
A family-owned machine builder with 280 employees has had TISAX for three years. Now NIS2 comes on top, and no one wants parallel bureaucracy. NIS2Compass delivers the complete §30 BSIG implementation path in 124 substeps. For each substep, an existing TISAX record can be attached or the gap closed with a template. Typical gaps: notification per §32, management body training per §38, supplier documentation per §30 No. 4. No further €700/day consulting round: the user maps themselves, the platform provides the structure.
124 substeps structured
Map TISAX controls in a targeted way
Gap templates
§32 notification, §38 training, suppliers
Article A-18
NIS2 / ISO 27001 comparison (TISAX is based on it)
The core duty for the shopfloor. Where OT is not patchable: strict network segmentation, asset inventory with protection classification, monitoring for anomalies. Document compensating measures.
Automotive and larger buyers demand supplier audits. At the same time, the machine builder must assess its own suppliers. Software supply chains (PLC firmware, engineering tools) are particularly relevant.
24-h early warning, 72-h full notification, 1-month final report. The significance threshold (§2 No. 11 BSIG) is concretely relevant for production outages, IP loss and ransomware.
More in the blog: NIS2 vs. ISO 27001, Is ISO 27001 enough for NIS2 compliance?, NIS2 implementation step by step.
| Kriterium | NIS2Compass | Klassische Beratung | ISMS-Tool | Selbstumsetzung |
|---|---|---|---|---|
| Monthly cost | €29 | €700-1,200/day | €200-2,000/month | €0 |
| Mapping work | structure provided | consultant takes over (expensive) | for individual standards | build yourself |
| German templates | yes (45+) | tailored | mostly English | no |
| OT pain points addressed | yes (articles A-21, A-22) | depends on consultant | generic | build yourself |
| Onboarding | 10 minutes | days to weeks | days + setup | months |
| For 4-8-person IT teams | yes | too expensive | too complex | capacity-challenged |
124 substeps, 45+ templates, no parallel bureaucracy.