Abstract network security visualisation over an industrial manufacturing production line

Germany’s NIS2 Ceiling for Manufacturers: Why BSIG Keeps Annex II Companies at ‘Wichtige Einrichtung’ — and What Section 30 Requires on the Factory Floor

Germany’s revised BSI Act — BSIG 2.0, the national law implementing NIS2 — entered into force on 6 December 2025 with no transition period. For a manufacturing company in electronics, machinery, motor vehicles, or medical devices, the obligations started that day, not on some future compliance deadline. The question compliance teams keep getting wrong isn’t whether NIS2 applies — it’s which of Germany’s two regulatory tiers they land in, and what that tier actually requires on a production floor full of equipment nobody designed with cybersecurity in mind.

This guide answers both questions using the BSIG’s own text, not the EU directive’s. Most manufacturing compliance content stops at Article 21 of the NIS2 Directive — useful for EU-wide scoping, covered in depth in our EU-wide manufacturing compliance guide, but insufficient for a German entity, whose actual legal obligation runs through Section 30 BSIG, not the directive directly. We’ll also show, using the statute’s own classification criteria, why manufacturing companies structurally cannot reach Germany’s highest regulatory tier through size alone — a distinction that changes your penalty exposure and your supervisory relationship with the BSI.

Does BSIG Apply to Your Manufacturing Company?

Plain-language summary: if your company makes medical devices, electronics, electrical equipment, machinery, motor vehicles, or other transport equipment, employs 50+ people or clears €10 million in both annual turnover and balance sheet total, and operates in Germany, you are a “wichtige Einrichtung” (important entity) under BSIG as of today — not a future date.

Three conditions determine scope, and all three must be met:

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Test Threshold
Sector Your activity falls within Anlage 2, Section 5 of the BSIG — the German transposition of NIS2 Annex II’s manufacturing category
Size 50+ employees, OR annual turnover AND balance sheet total both exceeding €10 million
Jurisdiction The entity operates in Germany — BSIG has applied with no phase-in since 6 December 2025

Anlage 2 Section 5 lists six manufacturing categories, numbered identically to how German auditors will reference them in a BSI inquiry [1]:

BSIG Anlage 2 Sector NACE Rev. 2
5.1 Medical devices and in-vitro diagnostic medical devices (per Art. 2 No. 1, Reg. (EU) 2017/745)
5.2 Computer, electronic and optical products Division 26
5.3 Electrical equipment Division 27
5.4 Machinery and equipment n.e.c. Division 28
5.5 Motor vehicles, trailers and semi-trailers Division 29
5.6 Other transport equipment Division 30

Note what’s absent: chemicals and food production sit in separate Anlage 2 categories with their own thresholds, not covered here. If your primary NACE classification sits outside Divisions 26–30 and outside the medical-device definition, run the sector test again using our general NIS2 scope test before assuming this guide applies.

The Classification Ceiling: Why Manufacturing Stays “Wichtige Einrichtung”

Here’s what most manufacturing compliance content misses entirely: BSIG doesn’t apply one classification ladder to every sector. Section 28 BSIG sets two distinct paths to the higher tier — “besonders wichtige Einrichtung” (particularly important entity) — and only one of them is available to a manufacturer [1].

The first path is critical-infrastructure (KRITIS) designation: any operator formally classified as a KRITIS critical facility is automatically besonders wichtig, regardless of sector or size. The second path is a size escalation — but Section 28 restricts it explicitly to entities in Anlage 1 categories (energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, and similar high-criticality sectors). An Anlage 1 entity with 250+ employees, or turnover above €50 million combined with a balance sheet above €43 million, is bumped up to besonders wichtig on size alone.

Manufacturing sits in Anlage 2. Section 28’s size-escalation clause never mentions Anlage 2. Read literally — and this is our own structural reading of the statute’s text, not a settled interpretive position from BSI commentary — a manufacturing company with 10,000 employees and €2 billion in turnover is classified identically, on size grounds, to one with 60 employees and €12 million in turnover: both are “wichtige Einrichtung.” Scale doesn’t move an Annex II manufacturer up Germany’s regulatory ladder. Only a second, independent legal event does — KRITIS designation under the separate BSI-KritisV regulation.

Anlage 1 sectors (energy, transport, banking, health, digital infra) Anlage 2 sectors (incl. manufacturing)
Baseline at 50+ staff or €10M+€10M Wichtige Einrichtung Wichtige Einrichtung
Size-based path to besonders wichtig Yes — 250+ staff, or €50M turnover + €43M balance sheet Not provided in Section 28
Remaining path to besonders wichtig KRITIS designation KRITIS designation only
Fine ceiling if capped at wichtig up to €7M / 1.4% of turnover up to €7M / 1.4% of turnover
Supervisory model if capped at wichtig Article 33 — reactive, ex post Article 33 — reactive, ex post

KRITIS designation isn’t hypothetical for every Annex II sector — it’s just narrow and sector-specific. The food-production category, a different Anlage 2 sector, crosses into KRITIS at roughly 434,500 tonnes of food output per year, calculated to represent supply for 500,000 people [5]. That threshold illustrates the pattern: Germany’s KRITIS regulation defines its own industrial-scale criteria per sector, and none of the current BSI-KritisV categories map onto electronics, machinery, motor-vehicle, or general equipment manufacturing (Anlage 2 Sections 5.2–5.6). A medical-device manufacturer is the closest edge case, given the sector’s proximity to KRITIS’s health category — worth an explicit legal check if your device supply is regionally concentrated, but not the default outcome.

The practical upshot: unless you separately hold KRITIS status, your fine exposure caps at €7 million or 1.4% of worldwide turnover — not the €10 million / 2% ceiling that applies to besonders wichtige Einrichtungen — and the BSI supervises you reactively under Article 33, only after evidence of non-compliance surfaces, rather than through the unannounced inspections Article 32 permits for the higher tier [4]. For the full penalty mechanics and enforcement posture across both tiers, see our Germany BSI penalties guide.

Section 30 BSIG: The Ten Measures Your Audit Trail Must Cite

Plain-language summary: Section 30 is the actual German legal basis for your risk-management obligations — not Article 21 of the directive. The ten required measure categories are nearly identical to the EU baseline, but a BSI inspector will expect your documentation to reference Section 30, not the directive, because Section 30 is what a German court or regulator enforces.

Section 30(1) requires “appropriate, proportionate, and effective technical and organisational measures” to prevent disruption and limit the impact of security incidents, with proportionality judged against five factors: the scope of your risk exposure, your organisation’s size, implementation cost, the probability and severity of incidents, and the socioeconomic consequences of a failure [6]. Compliance must be documented — an unwritten policy, however well followed on the shop floor, does not satisfy Section 30.

Section 30(2) sets ten minimum measure categories, matching NIS2 Article 21(2) almost point for point [3][6]:

# Section 30 BSIG measure Article 21(2) equivalent
1 Risk analysis and IT security policy (a)
2 Incident handling (b)
3 Business continuity: backup, disaster recovery, crisis management (c)
4 Supply chain security (d)
5 Secure acquisition, development and maintenance, incl. vulnerability handling (e)
6 Effectiveness-assessment procedures (f)
7 Training and security awareness (g)
8 Cryptography and encryption policy (h)
9 Personnel security, access control, asset management (i)
10 Multi-factor or continuous authentication, secure communications, emergency systems (j)

One provision worth flagging for compliance officers: Section 30(5) lets EU Commission implementing acts override BSIG specifics for certain entity types where they exist — relevant mainly to digital-infrastructure entities, not manufacturing — and where no such act applies, Germany’s Interior Ministry can issue supplementary ordinances raising sector-specific expectations. Manufacturing has no such ordinance yet, which means the statutory text above is the current complete standard, not an interim placeholder [6].

OT Security Obligations: What Changes on the Factory Floor

Plain-language summary: Section 30 makes no legal distinction between IT and OT. There is no separate, lighter (or stricter) statutory standard for PLCs, SCADA servers, or production-line HMIs — the same ten measures and the same proportionality test apply. What changes is how you satisfy them, and, for most manufacturers, one obligation you will not face at all.

BSI’s own guidance on Section 30 confirms the measures apply broadly to “information technology systems, components, and processes” without an OT carve-out, while noting the cross-hazard approach the law demands explicitly includes physical security — protection against theft, fire, flooding, and unauthorised physical access [7]. That framing lands differently on a production floor than in a server room: a compromised badge reader on a loading dock or an unlocked cabinet housing a PLC is squarely inside Section 30’s scope, in a way a pure IT policy template rarely anticipates.

The obligation many manufacturing compliance teams brace for — and don’t actually have — is a mandatory attack-detection system (Systeme zur Angriffserkennung, SzA). That continuous-monitoring requirement is real, but it attaches specifically to KRITIS critical-facility operators, not to standard wichtige Einrichtungen. A manufacturer that hasn’t crossed into KRITIS status, per the classification analysis above, is not statutorily required to deploy SzA-grade continuous attack detection under Section 30 — though the effectiveness-assessment and risk-analysis measures (points 1 and 6 in the table above) will still expect you to justify, and document, whatever detection capability you do run.

Section 30’s text is architecture-agnostic by design, which is exactly why it under-specifies how to apply "risk analysis" or "access control" to a Purdue Level 1 PLC that can’t run a modern authentication agent. That translation work — mapping the ten measures onto specific OT network zones, legacy-device compensating controls, and segmentation architecture — is the actual compliance project for most manufacturers, and we’ve covered it at the technical depth it deserves in two dedicated guides: NIS2 OT and SCADA Security maps the Purdue Model to CIR 2024/2690’s Annex, and IT/OT Convergence under Article 21 covers legacy-PLC compensating controls in detail. Both apply directly under Section 30’s identical measure set — there’s no separate German technical standard to reconcile.

Compliance Checklist: What to Do Now

Action Status / trigger Effort
Confirm Anlage 2 sector + size classification Ongoing obligation — not a one-time check; reassess after any acquisition, divestment, or headcount change Low
Register with the BSI entity register National deadline was 6 March 2026; if not yet registered, treat as overdue and register immediately — late registration does not exempt you from Section 30 Low
Document Section 30(2) measures 1–10 with proportionality justification Required now — no transition period since 6 December 2025 High
Extend documentation to OT/production assets explicitly Required now — Section 30 has no IT/OT carve-out Medium–High
Check KRITIS exposure via a separate legal review Only if your output scale, product category, or regional supply concentration resembles a KRITIS threshold pattern Low (review only)

Frequently Asked Questions

Does Section 30 apply differently to a manufacturing subsidiary of a larger multinational? Classification runs off the German entity’s own headcount, turnover, and balance sheet under Section 28 — group-wide figures matter mainly for the turnover component of any eventual fine calculation, not for the wichtig/besonders-wichtig determination itself.

If we’re ISO 27001 certified, does that satisfy Section 30? ISO 27001 controls can support several of the ten measure categories, but certification alone does not constitute Section 30 compliance — the BSI expects documentation that maps specifically to Section 30’s own structure, and generic certification evidence is generally treated as supporting material, not a substitute.

Can a manufacturer become besonders wichtig later even without KRITIS status? Not under the size-based path described above — that route is textually limited to Anlage 1 sectors. A change would require either a future KRITIS designation or a legislative amendment to Section 28 itself.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  • [1] § 28 BSIG – Besonders wichtige Einrichtungen und wichtige Einrichtungen, gesetze-im-internet.de
  • [2] Anlage 2 BSIG, gesetze-im-internet.de
  • [3] Article 21, NIS 2 Directive (EU) 2022/2555, via nis-2-directive.com
  • [4] Article 34, NIS 2 Directive (EU) 2022/2555, via nis-2-directive.com
  • [5] “Sektor Ernährung in NIS2 und KRITIS,” OpenKRITIS
  • [6] § 30 BSIG – Risikomanagementmaßnahmen besonders wichtiger Einrichtungen und wichtiger Einrichtungen, gesetze-im-internet.de
  • [7] “#nis2know: NIS-2 Risikomanagementmaßnahmen,” Bundesamt für Sicherheit in der Informationstechnik (BSI)
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: