• Weserland Interiors WLI
  • Contact Partners
  • +49 511 97 997 0
  • EN
    • DE
  • EN EN EN en
  • DE DE DE de
  • Our Expertise
  • Key Production Areas
    • Latex-Vulcanisation
    • Coatings
    • Agents / Auxiliaries
    • Toll Manufacturing
  • The Company
  • Sustainability
  • Useful Information
  • Menu Menu
Hinter dem Kürzel NIS2 (Network and Information Security) verbirgt sich die Generalüberholung der ersten EU-Cybersecurity-Richtlinie von 2016. The acronym NIS2 (Network and Information Security) refers to the comprehensive overhaul of the first EU Cybersecurity Directive from 2016.

NIS2 Directive: What Chemical Companies Need to Know

 3 min

Cybersecurity in the chemical industry is lagging behind reality. Whilst professional hacker groups have massively stepped up their attacks on chemical plants in recent years, a dangerous complacency still prevails in many production halls and boardrooms. As early as 2020, an industry review by the German Insurance Association (GDV) revealed glaring gaps: particularly among small and medium-sized enterprises, there was all too often a lack of clearly designated security officers and tried-and-tested emergency plans. With the European Union’s NIS2 Directive, the era of voluntary compliance is now definitively over. As chemical companies form the backbone of critical infrastructure, the legislator is now holding the sector strictly to account.

The End of the Grace Period: From EU Draft to Binding Law

The acronym NIS2 (Network and Information Security) refers to the comprehensive overhaul of the first EU Cybersecurity Directive from 2016. Following the official EU launch in early 2023, Member States were originally given until October 2024 to implement the directive at national level. Germany missed this deadline by a considerable margin – but then pulled off a sprint: the national implementation act (NIS2UmsuCG) passed the Bundestag and Bundesrat in November 2025 and came into force on 6 December 2025. What makes this remarkable is that there was no transition period. These obligations have applied from day one.

The implications for the German economy are enormous. And: the regulatory protection provided by the Federal Office for Information Security (BSI) has suddenly expanded from 4,500 to around 29,500 companies. Anyone who missed the initial statutory registration deadline is on thin ice: the standard deadline ended on 6 March 2026. Given the current grace period, which expired on 31 July 2026, time is running out fast for latecomers. Ignoring the requirements threatens the very existence of the business. Violations carry the risk of fines of up to ten million euros or two per cent of global annual turnover. Particularly critical: in the event of a serious breach, senior management is personally and unlimitedly liable with their private assets.

Who Must Act? The ‘Size Cap’ Rule Decides

Whether a chemical company falls under the new rules is determined by the so-called ‘Size Cap’ rule under Section 28 of the BSI Act (BSIG). As the chemical industry is classified as a sector of high criticality, strict thresholds apply here: the full-time equivalents from the most recent annual accounts are used for the calculation. Operators of facilities that are already classified as critical infrastructure (KRITIS) automatically fall into the highest category, regardless of their size. Even small subsidiaries within corporate structures may be covered via the overall economic entity. Only genuine micro-enterprises are excluded.

  • Particularly important facilities: Organisations with 250 or more employees, or with an annual turnover of more than 50 million euros and a balance sheet total of over 43 million euros.
  • Important facilities: Organisations with 50 or more employees, or with an annual turnover or balance sheet total of more than 10 million euros.

Risk Management and the 24-Hour Countdown

At its core, NIS2 requires a dynamic, certified risk management system. Organisations must systematically analyse cyber risks and put technical defences in place. These are ranging from multi-factor authentication and end-to-end encryption to resilient backup strategies.

In addition, the legislation requires an extremely rigorous, three-stage reporting system for security incidents:

  1. The initial report (within 24 hours): An initial alert to the BSI regarding the nature of the attack and the first emergency measures taken.
  2. The interim report (within 72 hours): A precise assessment of the situation, including an initial evaluation of the damage.
  3. The final report (within one month at the latest): A detailed documentation of the incident and the final resolution of the security vulnerability.

Practical Tools for the Chemical Industry’s IT

Implementing these bureaucratic requirements does not have to start from scratch. The chemical industry can draw on established industry standards. The international IEC 62443 series of standards provides the perfect guide for securing process control systems (OT) and places equal responsibility on plant operators as well as manufacturers. This is complemented by the KAS-51 guideline from the Commission for Plant Safety, which provides concrete defences against sabotage and digital extortion. And: those who integrate these industry standards with the legal NIS2 requirements not only protect their company from penalties, but also safeguard their production from shutdowns.

Source: Trade journal ‘PROCESS’

Photo: The KonG

27.07.2026/in General topics, News, News from the Industry
https://weserland.eu/wp-content/uploads/2026/07/AdobeStock_1712289710.jpeg 701 1247 Tom Ruthemann https://weserland.eu/wp-content/uploads/2022/08/wl-logo-1.svg Tom Ruthemann2026-07-27 15:10:012026-07-27 15:08:34NIS2 Directive: What Chemical Companies Need to Know

Overview

This may be of interest to you

  • NIS2 Directive: Cybersecurity Obligations for the Chemical Industry Digitalisation
  • Cyber Security For Production Companies: A Clear Must For The Future Digitalisation
  • New EU Guidelines for Sustainability Reports News
  • Digital Twins In The Chemical Industry: Process Optimisation Through Enhanced Reality Digitalisation
  • Decarbonisation in Companies: New Standards Require Concrete Strategies Sustainability

Weserland GmbH
Hansastraße 9-17
30419 Hannover

+49 511 97 997 0
info@weserland.eu

  • Our Expertise
  • The Company
  • Downloads
  • Apprenticeship
 
  • Latex-Vulcanisation
  • Coatings
  • Agents / Auxiliaries
  • Toll Manufacturing
  • Sustainability
  • General Terms and Conditions
  • General Terms and Conditions of Purchase
  • Code of Conduct
  • Public Information
  • Legal Information
  • Privacy Policy (GDPR)
Scroll to top