NIS2 ASSET DISCOVERY SOFTWARE FOR MUNICH MANUFACTURERS: KNOW BEFORE BSI ASKS

NIS2 Asset Discovery Software for Munich Manufacturers: Know Before BSI Asks

When a major manufacturer stops production after a cyber incident, the shock reaches every tier that feeds that plant. The Cyber Monitoring Centre statement on the Jaguar Land Rover incident estimated a United Kingdom financial impact of £1.9 billion across more than 5,000 organisations. The same statement notes that losses could climb higher if operational technology (OT) was significantly affected. That case sits in the United Kingdom. Public reporting frames a supply-chain shock from a primary site failure, separate from any claim that inventory tooling would have stopped the outage. It still shows how tightly linked industrial chains feel when a major plant goes dark.

Munich sits inside a dense automotive and industrial network. City business development materials describe a cluster that includes BMW innovation activity, Knorr-Bremse, Infineon, and a wide supplier base. When German law asks which information and communication technology (ICT) systems support production, answers have to travel from plant floors to management without three competing spreadsheets. NIS2 asset discovery software for Munich manufacturers exists to make that answer repeatable.

The Network and Information Security Directive 2 (NIS2) landed in German law through the revised BSI Act (BSIG). The Federal Office for Information Security (BSI) can request evidence of risk-management measures. The practical question for a plant is whether one maintained source can show what exists, who owns it, and when each record was last checked. IT asset management (ITAM) teams already feel that pressure every time finance, IT, and plant engineering disagree on the same host.

What German NIS2 Law Requires of Munich Manufacturers

Are You in Scope?

The revised BSIG has been in effect since 6 December 2025. DLA Piper reports no transition period and that the BSI figure for covered entities is about 29,500. Manufacturing sits among the newly covered sectors. That expansion is why many Bavarian plants that never lived under the older critical-infrastructure rules now face BSIG duties.

German law labels entities as particularly important (besonders wichtige Einrichtungen) or important (wichtige Einrichtungen). Under §28 BSIG, many commercial entities in listed sectors become particularly important at 250 employees, or when annual turnover exceeds €50 million, and the balance-sheet total exceeds €43 million. Important-entity thresholds for many listed sector types begin at 50 employees, or when annual turnover and balance-sheet total each exceed €10 million. Telecom and certain other categories use different rules. Negligible side activities can be left out of the calculation under §28(3), which still needs legal judgment. Typical manufacturing categories include motor vehicles and parts, machinery, and electrical equipment. Counsel and BSI self-assessment materials decide scope for each legal entity.

What §30 Says About Assets, and What It Leaves Unsaid

§30 BSIG requires suitable, proportionate, and effective technical and organisational measures that protect the availability, integrity, and confidentiality of the ICT systems, components, and processes used to deliver services. Entities must document that they meet that duty. Paragraph 2 lists ten measure areas. Item 9 covers concepts for personnel security, access control, and the administration of ICT systems, products, and processes. Supply-chain security, vulnerability handling, incident handling, and continuity appear in the same list. The statute does not use the English marketing phrase “asset inventory.” Precision matters here. Discovery and a configuration management database (CMDB) support administration and documentation duties without turning the statute into a product checklist.

BSIG topicWhat the record needsWhere discovery data feeds inWhat the record alone does not do
§30(1) documentationDated, traceable evidence of measuresSource tags, last-verified times, change historyLegal judgement that measures are adequate
Administration of ICT systemsNamed owner, status, location, last checkPopulated CI records from scheduled scansAssigning human accountability
Supply-chain securityWhich systems a supplier touchesService and dependency maps once services are definedSupplier risk scores or contract clauses
Vulnerability handlingKnown assets matched to findingsAsset baseline for scanners and overlaysFull multi-OS vulnerability management
ContinuityDependencies of critical production servicesRelationship maps for restore planningRestore tests and crisis drills

Documentation, and What the BSI Can Ask to See

The BSI’s NIS2 guidance on risk management measures states that entities must be able to hand over the authority evidence documents when it requests them under §61(3) BSIG. That request can come after registration, whether or not an incident has occurred. §30(1) BSIG adds a related duty: the measures themselves must be documented. For a plant, that raises a practical question. If the BSI asked today which systems support production, who owns them, and when each record was last checked, could your team answer from one source? The wording is “can ask.” Neither the guidance nor the statute promises a routine asset-file inspection on a fixed calendar.

§61 BSIG still gives the BSI clear powers to order proof for particularly important entities, including underlying documentation used in audits. Boards and plant leads plan for that possibility.

Registration Was the First Step

Entities already in scope had three months from 6 December 2025 to register, which lands on 6 March 2026 under the statutory clock. Trade associations later heard about a practical tolerance into summer 2026. ITMR describes that later summer date as association-communicated tolerance while the statutory registration clock stayed on the March deadline. Registration opens the compliance process and still leaves §30 measures and the documentation duty fully in force.

For the wider EU framing of audit-day readiness, Virima’s NIS2 compliance checklist covers the directive-level view. German plants still need the BSIG wording and local ownership model on top of that checklist.

Four Places a Plant Inventory Breaks Down

Three disconnected finance IT and plant asset islands with incomplete discovery links on a light background

Munich business development materials place vehicle engineering, industrial suppliers, and semiconductor-related manufacturing in the same metro cluster. Inside one plant group, inventories still fail in four recurring ways.

Three Inventories, Three Owners

Finance holds an enterprise resource planning (ERP) asset book for depreciation and purchase orders. IT holds a discovery or ITAM list for servers, endpoints, and cloud instances. Plant engineering holds line controllers, gateways, and machine interfaces in maintenance systems. Those three lists diverge on hostnames, serials, locations, and status. When the BSI question arrives, no single owner can certify the full picture. The CMDB owner becomes the person who reconciles the conflict after the fact. A durable join key such as a serial number or cloud instance identifier beats a hostname that changes during a rebuild.

Devices Outside Scan Reach

Some OT and Internet of Things (IoT) devices sit on segmented networks, use vendor protocols discovery does not speak, or stay offline except during maintenance windows. Those devices remain invisible to a pure network scan until someone scopes them and chooses another method such as a controlled walk-down, vendor export, or engineering database import. Blind spots stay unrecorded when projects treat scanner reach as identical to plant coverage.

Supplier Paths Nobody Documented

Bitkom’s 2026 Wirtschaftsschutz study reports that impact reaches partners for a material share of affected firms, including a 21 percent figure tied to partner effects in the study narrative. §30 already names supply-chain security, including security aspects of relationships with immediate providers. If the plant cannot show which ICT systems a supplier remote path touches, the answer becomes a workshop memory exercise. Memory does not age well across shift handovers.

Retired Systems With No Named Decider

Decommissioning requires a deliberate decision from IT operations or plant engineering, and that decision needs a named owner and a recorded date. Without a named decider and a closed workflow, retired hosts remain in the register and still appear in licence, vulnerability, and access reviews. Peak-season instances and decommissioned hosts should land on the next discovery cycle with an owner on every exception.

The same Bitkom study lists weak incident detection at 59 percent and misconfiguration at 57 percent among leading reasons attacks succeed, and it treats knowing the IT landscape as an early ransomware-oriented measure. Flexera’s 2026 State of ITAM press summary states that complete IT asset visibility fell to 36 percent in a global sample that skews large. Reporting on PwC’s Global Industrial Manufacturing Sector Outlook cites highly automated key processes rising from 18 percent to 50 percent by 2030, which enlarges the estate that still needs owners and verification dates.

What NIS2 Asset Discovery Software Should Do, and Where Virima Fits

Munich manufacturers need software that turns plant segments into dated, sampleable records with owners, timestamps, and history. Virima addresses that gap with scheduled discovery into a CMDB and service maps once services are defined.

What Virima Records for Every Asset

Every discovered asset carries a source tag and a last-verified timestamp. When sources disagree, an authority rule decides the winning value and the resolution is logged. Change history shows which attributes moved between discovery cycles. That pattern is the backbone of a discovery-sourced CMDB. Teams export or report from those records when they build the evidence file for §30 documentation. The entity still owns the legal conclusion that measures are suitable and effective.

See how Trusted Runtime Truth frames live, explainable operational records for management and regulator questions from the same ground truth.

Reaching Plant-Floor Systems, and Where Coverage Stops

Virima discovery combines agent-based collection with agentless methods such as SNMP, WMI, and SSH across a large probe library, plus API collection for Amazon Web Services and Microsoft Azure. Credentials remain on infrastructure the customer controls. High-frequency scheduled discovery refreshes the estate on a plant-operable cycle, with method chosen per segment risk and access model.

OT and IoT coverage applies where devices are network-accessible and speak supported protocols. Everything else becomes an explicit scoping step with plant engineering before go-live so coverage limits stay visible in the project plan.

Evidence Each Role Can Use

  • For the CIO and Geschäftsleitung. §38 BSIG places implementation and oversight of §30 measures on management, with training duties and civil liability pathways under company law. A dated, sampleable record is what a board can point to if the BSI asks for proof under the powers described earlier. Strategy conversations stay on risk posture and evidence quality rather than probe lists.
  • For the SecOps lead. Scanner coverage depends on the inventory beneath it. Unknown hosts never enter patch or detection scope on time. A baseline discovery scan on one plant segment is a low-drama way to measure that gap. CMDB-backed inventory supports security workflows while discovery stays upstream of the full security information and event management stack.
  • For the CMDB owner and ITAM manager. Stale rows between cycles, exceptions without owners, and hardware lifecycle drift are daily work. Virima IT asset management capabilities sit beside discovery so lifecycle status and ownership travel with the CI. Operators can review the discovery-sourced CMDB, discovery, and ViVID™ path in product walkthroughs without rewriting the plant model on slides.
BSIG topicWhat the record needsVirima capabilityBoundary
§30(1) documentationDated, traceable recordsSource tags, timestamps, change historyDocumentation duty stays with the entity
Management of ICT systemsOwner, status, last verifiedCMDB with ownership dataPeople assign accountability
Supply chain securityWhich systems a supplier touchesViVID™ service mapping once service definitions existSupplier risk scoring runs elsewhere
Vulnerability handlingFlags against known assetsNVD overlay on supported Windows Server findings weighted by service contextNVD is a United States database; BSI advisories remain a separate feed
ContinuityDependencies of critical servicesDependency maps after services are definedRestore testing happens elsewhere

ViVID™ service mapping builds dependency maps after teams provide service definitions manually, by spreadsheet, or through enterprise-architecture inputs. Map automation follows those definitions and builds relationships from the infrastructure Virima already discovered.

Single plant pilot segment linked to a configuration hub and ownership pad on a light background

Start With One Plant, Not the Whole Estate

A single production segment gives the CIO a dated baseline, SecOps a known host list, and the CMDB owner a finite exception queue while counsel still owns legal scope.

  1. Classify each legal entity with counsel using BSI self-assessment material and §28 thresholds.
  2. Pick one plant or production line and list the ERP, IT, and engineering inventories that already exist.
  3. Run a high-frequency scheduled discovery baseline on that segment with clear credentials and change windows.
  4. Assign an owner to every exception, and name the decision-maker who closes decommissioning.
  5. Set a review cadence and keep an evidence file that supports the §30 documentation duty, including dated exports the compliance team can file with the §30 evidence pack.

When the first segment closes exceptions on schedule, copy the owner matrix and evidence folder to the next line. Keep service definitions for ViVID™ mapping on the same backlog. Hold scope expansion while decommission decisions still lack a named decider. A thin dated pack from one working plant beats a wide unfinished estate that still argues about serial numbers when someone asks for §30 documentation proof. Finance, IT, and plant engineering should agree the join keys for that pack before the second plant is added, so serials and cloud instance IDs stay durable across sites.

Test It on One Plant Segment

Run a scheduled baseline discovery on one Munich plant segment and review owners, last-verified dates, and exceptions with the people who run that line. When stakeholders want a guided walkthrough before credentials are issued, book a free demo with our team and scope the pilot to a single production segment.

Bring the CMDB owner, the SecOps lead, and one plant engineer to the same readout so exceptions get owners in the room. Capture the scan window, credential path, and decommission decision-maker in the §30 evidence folder on the same day as the baseline. That packet is what management can sample later when the BSI asks for documentation under the powers described earlier in this article. Extend the same packet structure when the next line joins the programme.

NIS2 Asset Discovery Software FAQs

What is NIS2 asset discovery software?

It is tooling that finds ICT assets on a schedule, writes them into a maintained register such as a CMDB, and supports ITAM processes with ownership and lifecycle fields. Discovery collects. The CMDB stores relationships. ITAM governs financial and lifecycle status beside those records.

Does the BSIG require an asset inventory?

§30 requires documented risk-management measures, including administration of ICT systems, products, and processes. Usable evidence typically shows owner, status, and last-verified date. Adequacy remains a judgement for the entity, its auditors, and the BSI in a concrete request.

Can discovery software scan OT devices in a factory?

Coverage holds where devices are reachable on the network and speak supported protocols under approved credentials. Segmented, proprietary, or offline controllers need a separate method agreed with plant engineering before anyone promises full line coverage.

Are suppliers below the NIS2 thresholds affected?

§30 supply-chain measures push security expectations into contracts and questionnaires even when a supplier sits outside direct BSIG scope. Customers still ask which systems remote support touches and how access is controlled on those paths.

Will scanning disrupt production networks?

Teams choose scan windows, credentials, and segment scope with production owners before the first full pass. Piloting on one line first keeps load and change risk visible while the operating model for exceptions is proven.

What sits outside NIS2 asset discovery software?

BSI incident reporting, supplier cyber scoring, policy enforcement, data classification, and full ISMS or GRC programmes stay with the entity. Virima feeds a discovery-sourced CMDB and complements ServiceNow, Jira Service Management, and Ivanti through ITSM integrations, while compliance owners still write the measure file the authority can request.

Move faster. Act safely.

Get live, explainable runtime truth across your entire estate — without platform lock-in.

Similar Posts