NIS2 cybersecurity compliance for chemical manufacturers — network security overlay on industrial chemical plant

How Chemical Manufacturers Satisfy Both Seveso III and NIS2 Annex II: A 12-Step Compliance Checklist

Chemical manufacturers face compliance from two directions at once. NIS2 Directive (EU) 2022/2555 brings mandatory cybersecurity obligations through Annex II. If any of your sites also hold dangerous substances above Seveso III thresholds, those obligations layer over a parallel process-safety reporting regime with its own notification chain, risk assessment requirements, and regulatory authority. Neither framework acknowledges the other, yet the obligations intersect at exactly the point where a cyber event could cause loss of process control.

This checklist maps all twelve steps a chemical manufacturer needs to satisfy NIS2 Annex II, structured around Article 21(2)(a)–(j) and the Seveso III Directive 2012/18/EU. Each step includes the relevant article reference, an effort estimate for medium-sized operations, and where the frameworks cross-reference each other.

Does NIS2 Apply to Your Chemical Operation?

Two gates determine NIS2 applicability for chemical companies. Pass both and you are an Important entity under Annex II. Fail either and you are outside direct scope — though national transpositions in some Member States extend obligations below the EU baseline.

Gate 1 — Sector scope: NIS2 Annex II defines the chemicals sector by cross-reference to REACH Regulation (EC) No 1907/2006. Covered entities are those “carrying out the manufacture of substances and the distribution of substances or mixtures, as referred to in Article 3, points (9) and (14)” of that regulation, and those involved in “production of articles… from substances or mixtures.” If your operation is REACH-registered for manufacturing, distribution, or article production, the chemicals entry applies.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Gate 2 — Size threshold: NIS2 Article 2 limits scope to entities meeting the EU’s medium-enterprise definition: at least 50 employees, or annual turnover and annual balance-sheet total both exceeding €10 million. Below both thresholds you are likely outside direct scope.

Criterion Threshold Result if Met
REACH-registered manufacturer or distributor Yes / No In sector scope
Employees 50 or more Size threshold met
Annual turnover OR balance-sheet total Over €10 million Size threshold met
Both gates passed Important entity, Annex II

Seveso III classification does not affect NIS2 applicability. A small mixing operation below the size thresholds but above Seveso substance quantities sits outside NIS2. A large petrochemical group above NIS2 thresholds is inside NIS2 regardless of Seveso status. The two frameworks use entirely different triggers.

If you sit close to the size threshold, apply it to each legal entity individually. A group structure with separate operating companies must assess each entity on its own employee count and turnover, not at group level.

What Changes When You Also Operate a Seveso III Site

Seveso III — Directive 2012/18/EU — classifies establishments by the quantity of dangerous substances held on site against Annex I thresholds. Lower-tier sites must maintain a Major Accident Prevention Policy (MAPP). Upper-tier sites must additionally produce a safety report, maintain a Safety Management System (SMS), and prepare an internal emergency plan.

Cybersecurity is not written into the Seveso III text, but the regulatory interpretation has converged: a cyber event that disrupts industrial automation control is a potential major accident precursor. Germany’s KAS-51 guideline from the Commission for Plant Safety formalised this position, treating cyber-induced loss of control as a hazard scenario within the Seveso framework. IEC 62443 — the industrial cybersecurity standard for automation and control systems — is now referenced in both NIS2 implementation guidance and Seveso III enforcement practice across multiple Member States.

Dual registration creates dual notification. A cyber incident at a Seveso III site that causes or could cause loss of control over a process involving hazardous substances is potentially double-reportable: as a significant incident to the NIS2 national competent authority under Article 23, and simultaneously to the authority responsible for major accident prevention under Seveso III national law. German implementation explicitly frames these as parallel obligations under separate legal bases, with no derogation for one that satisfies the other.

Three practical implications for compliance planning:

  1. Incident criteria must reference both frameworks simultaneously. Your internal escalation procedure must define the criteria that trigger Seveso III major-accident reporting alongside the NIS2 Article 23 thresholds. These criteria must be established before the first incident, not improvised during response, because the 24-hour NIS2 early-warning window leaves no time for that analysis.
  2. Asset registers and Safety Management System documentation must cross-reference each other. Maintaining two entirely separate asset inventories — one for NIS2, one for Seveso SMS — creates reconciliation risk and duplicates effort. A single OT asset register that satisfies both frameworks is more defensible to both sets of auditors.
  3. Risk assessments under Article 21(2)(a) must model process-safety consequences. At chemical plants, the impact of a cyber incident is not only data availability or service downtime. The risk analysis must address how a cyber event propagates through the DCS, SIS, or MES layer to a potential loss-of-containment or runaway-reaction scenario.

The 12-Step NIS2 Compliance Checklist for Chemical Manufacturers

Each step maps to one or more Article 21(2) obligations. Effort ratings reflect realistic implementation complexity for a medium-sized chemical entity with limited internal cybersecurity resources.

Step 1 — Confirm Annex II scope and Important entity status

Document your entity classification in writing: confirm REACH registration status, apply the size threshold test, and record the result. This documentation forms the basis of your national competent authority registration record and your audit-readiness file. Article: Annex II, Article 2 | Effort: Low

Step 2 — Determine Seveso III tier and map cross-framework obligations

Confirm whether any sites hold dangerous substances above lower-tier or upper-tier Seveso III thresholds under Directive 2012/18/EU Annex I. Sites above Seveso thresholds require Safety Management System integration with NIS2 cybersecurity governance from this point forward. Document which sites carry dual obligations and identify the competent authorities for each framework in your jurisdiction. Regulation: Directive 2012/18/EU | Effort: Low–Medium

Step 3 — Appoint a compliance lead and establish board-level accountability

NIS2 Article 20 requires management bodies to approve cybersecurity risk-management measures and oversee their implementation. Designate a named compliance lead (typically CISO, IT security manager, or compliance officer). Document the board resolution approving the NIS2 programme, which becomes audit evidence that governance obligations have been met. Article: 20, 21(1) | Effort: Low

Step 4 — Complete an initial gap analysis

Map your current controls against all ten Article 21(2) measures. For Seveso III sites, extend this analysis to include process-safety controls that could substitute for or reinforce cybersecurity requirements. The gap analysis output sequences subsequent steps by risk priority and gives you a defensible documented baseline if a competent authority requests evidence of due diligence. Article: 21(2)(f) | Effort: Medium

Step 5 — Build the DCS and SIS asset inventory

Identify and catalogue every Distributed Control System, Safety Instrumented System, batch controller, Manufacturing Execution System, historian server, and lab automation component. Classify each by criticality, network zone, ownership, firmware version, and patch status. This asset inventory is the foundation of Article 21(2)(i) compliance and the prerequisite for all subsequent technical controls. Article: 21(2)(i) | Effort: High

Step 6 — Apply NAMUR NE 153 secure-by-design principles to automation procurement

NAMUR Recommendation NE 153 — “Automation Security 2020 – Design, Implementation and Operation of Industrial Automation Systems” — establishes that IT security should be an integral function of automation components, not a layer added after deployment. For procurement, this means embedding security requirements (authentication, network segmentation compatibility, patching roadmap) into technical specifications before vendor selection. CIR 2024/2690 Annex Point 6 specifies the same secure-acquisition principle for entities formally within its scope; chemical manufacturers not covered by the CIR can use Point 6 as a voluntary technical benchmark when selecting and deploying process automation systems. Article: 21(2)(e) | NAMUR NE 153, CIR Annex Point 6 benchmark | Effort: Medium

Step 7 — Implement IEC 62443-based OT network zoning

Segment your process control network from corporate IT using IEC 62443 zone-and-conduit principles. DCS and SIS networks belong in separate zones with explicitly documented inter-zone traffic rules. Remote access to any process-control zone must be authenticated, session-logged, and restricted to defined functions. At Seveso III sites, remote access to process-control networks requires explicit safety-case justification documented in the Safety Management System. Article: 21(2)(e), 21(2)(j) | Effort: High

Step 8 — Conduct a risk assessment integrating process-safety risks

Article 21(2)(a) requires risk analysis and information system security policies. At chemical plants, this analysis must trace the path from initial cyber access through process control systems to potential safety consequences: loss of containment, runaway reactions, or hazardous substance release. Document scenarios with both cybersecurity impact scores and process-safety consequence severity. At upper-tier Seveso sites, this analysis informs the safety report. Article: 21(2)(a) | Effort: High

Step 9 — Establish a dual-reporting incident procedure

Design an incident notification workflow that handles NIS2 Article 23 timelines — 24-hour early warning, 72-hour detailed notification, 30-day final report — and the Seveso III major-accident notification requirement in the same escalation path. The decision criteria determining whether a cyber event triggers Seveso III reporting must be written down and tested before the first incident. A drill that involves both the IT security team and the EHS function is the only reliable way to validate the procedure. Article: 21(2)(b), 23 | Directive 2012/18/EU | Effort: Medium

Step 10 — Assess supply chain security for critical suppliers and service providers

Article 21(2)(d) requires supply chain security assessment of direct suppliers and service providers. For chemical manufacturers, this includes process automation vendors, remote-maintenance service providers, MES system suppliers, and SCADA integration partners. Contractual security clauses and supplier self-assessment questionnaires are the standard evidence outputs. At Seveso III sites, suppliers with remote access to process-control systems carry elevated risk and warrant enhanced assessment. Article: 21(2)(d), 21(3) | Effort: Medium–High

Step 11 — Build business continuity plans with safe-plant-state priority

Article 21(2)(c) covers backup management, disaster recovery, and crisis management. Chemical facilities sequence recovery priorities differently from IT-centric organisations: the first objective following a cyber incident is reaching a defined safe plant state, not restoring data or network availability. Document RTO and RPO targets per asset class — DCS, SIS, MES, batch systems — with their Seveso III-aligned safe-state shutdown procedures as the recovery baseline. This sequencing must be explicitly recorded; auditors will test whether your continuity plan actually knows what “recovered” means for a chemical process. Article: 21(2)(c) | Effort: Medium

Step 12 — Register with your national competent authority

NIS2 has been transposed into national law across Member States, with enforcement active from October 2024. Chemical manufacturers as Important entities must register with the designated national competent authority: Germany (BSI), Netherlands (NCSC-NL), France (ANSSI), Poland (CERT Polska), Italy (ACN). Provide entity name, sector classification, designated NIS2 point of contact, and contact details. Registration mechanisms vary by Member State — consult your national authority’s portal directly. Article: 3, national transposition law | Effort: Low

DCS and SIS Asset Inventory: The Foundation of Article 21(2)(i)

Article 21(2)(i) groups asset management with human resources security and access controls. For chemical manufacturers, the asset management component carries the greatest implementation risk because the asset class — process automation hardware — is rarely fully visible to IT security teams.

A complete chemical plant OT asset inventory must cover, at minimum:

  • Distributed Control Systems (DCS) — primary process control layer; typically legacy systems with 15–20 year lifecycles and limited patch support
  • Safety Instrumented Systems (SIS) — independent safety-function control; the independence of the SIS from the DCS must be explicitly documented and verified
  • Programmable Logic Controllers (PLCs) — batch control, reactor control, and utility systems
  • Manufacturing Execution Systems (MES) — production scheduling and batch records; typically bridging the IT/OT boundary
  • Historian servers and process data archives — often connected to both OT and corporate IT networks
  • Engineering workstations — configured with direct system access; represent high-risk entry points if unmanaged
  • Remote-access endpoints and VPN gateways into the OT network

Each asset requires: owner name, network zone assignment, criticality classification, last patch date, firmware version, patch management plan, and backup status. The SIS entry requires an additional field: documented independence verification confirming the SIS is not reachable from the DCS network through shared historians, shared credentials, or common remote-access paths.

The SIS independence requirement is the most audit-sensitive aspect of chemical plant OT asset management. A SIS connected to the same historian as the DCS is technically accessible from the DCS network. Regulators expect either evidence that this path cannot be exploited, or a documented risk-acceptance decision. An inventory that omits this verification will fail a competent authority on-site inspection.

CIR 2024/2690 Annex Point 12 — which formally applies to digital infrastructure providers, not chemical manufacturers — specifies accurate asset inventories with classification, secure asset lifecycle handling, and removable media management. Chemical manufacturers can use this framework as a voluntary technical benchmark for structuring their OT asset register, providing a documented technical basis for Article 21(2)(i) controls.

NAMUR NE 153 reinforces the same principle from the process industry side: IT security should be “an integral function of future automation components,” which in practice means security metadata — network zone, patch policy, access control matrix — should be part of the automation system’s engineering documentation from initial design. Where legacy DCS and SIS systems predate this approach, the inventory is a retrofit exercise. For new procurement, NAMUR NE 153 provides the design-phase framework for building security into the engineering specification before a vendor is selected.

Penalties and Management Accountability for Chemical Sector Entities

Chemical manufacturers as Important entities under NIS2 Annex II are subject to Article 34(5) administrative fines: a maximum of €7 000 000 or 1.4 % of total worldwide annual turnover, whichever is higher. Fines apply when entities violate Article 21 (cybersecurity risk-management measures) or Article 23 (incident notification). Member States may set higher penalties in national transposition law; Germany and the Netherlands have done so.

Entity type Maximum fine Alternative basis NIS2 article
Essential entity (Annex I) €10 000 000 2% of global annual turnover Article 34(4)
Important entity (Annex II) €7 000 000 1.4% of global annual turnover Article 34(5)

Beyond fines, NIS2 Article 20 establishes personal accountability at management level: management bodies must approve cybersecurity risk-management measures, oversee their implementation, and complete cybersecurity training. In several Member States’ transpositions — including Germany and the Netherlands — this accountability framework extends to personal liability for management personnel who fail to discharge these obligations.

The enforcement risk compounds at Seveso III sites. A cyber incident resulting in a process-safety event triggers simultaneous review by the NIS2 national competent authority, the Seveso III regulatory authority, and — depending on consequences — potentially prosecutors under environmental or industrial safety law. These are three separate enforcement chains, each with its own evidence requirements and timelines.

Enforcement is active. EU Member States began issuing formal compliance assessments to industrial sector entities in late 2025. Chemical manufacturers that have not completed gap analyses or registered with their national competent authority are at the highest immediate risk of supervisory attention under Article 33.

Role and Responsibility Matrix

At chemical plants, NIS2 compliance sits across functions that do not always communicate directly. The following matrix assigns primary and supporting responsibility for each compliance stream.

Responsibility CISO / IT Security EHS Manager Compliance Officer Board
Article 21 technical controls Lead Support Oversight Approve
Seveso III SMS cyber integration Support Lead Oversight Approve
DCS/SIS asset inventory Lead Input Review
Dual incident reporting procedure Lead Lead Oversight Notify
NCA registration Support Lead
Risk assessment (cyber + process safety) Lead Input Review Approve
Supply chain security assessment Lead Input Lead

At Seveso III dual-registration sites, the dual incident reporting row is the most operationally critical: both the CISO and the EHS manager must be in the escalation path simultaneously. Define the decision authority — who calls the Seveso III notification — before the first incident. Leaving this ambiguous until an incident is in progress is the single most common dual-compliance failure mode.

Frequently Asked Questions

Do chemical distributors — not only manufacturers — fall under NIS2 Annex II?

Yes. NIS2 Annex II covers both manufacturers and distributors of substances or mixtures as defined in REACH Regulation (EC) No 1907/2006, Article 3 points (9) and (14). Distribution operations meeting the 50-employee / €10 million size thresholds are in scope as Important entities.

Is CIR 2024/2690 legally binding for chemical manufacturers?

No. CIR 2024/2690 formally applies to DNS service providers, TLD registries, cloud computing service providers, CDN providers, managed service providers, and trust service providers. Chemical manufacturers are not within the CIR’s formal scope. However, its 13-point Annex is widely used as a voluntary technical benchmark for implementing Article 21 controls, particularly for asset management (Point 12) and secure acquisition (Point 6).

Does NAMUR NE 153 create legal obligations under NIS2?

No. NAMUR recommendations are industry guidance published by the user association for automation technology in process industries. NE 153 does not create legal obligations. Demonstrating alignment with its secure-by-design principles strengthens an Article 21 implementation case under the “state-of-the-art” standard in Article 21(1), particularly for the secure acquisition and development measures at Article 21(2)(e).

What is the priority action if we have not started NIS2 compliance yet?

Register with your national competent authority and complete a gap analysis. Registration demonstrates good-faith compliance and establishes contact with your regulator before an incident occurs. The gap analysis sequences all subsequent steps by risk priority and gives you a documented baseline that limits personal liability exposure under Article 20 governance obligations.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: