We are a precision machining shop with 22 employees in Baden-Württemberg, Germany. We operate six 5-axis CNC machines and an adjoining local parts transfer line. Last week, our employers' liability insurance association and the occupational safety inspectorate conducted a routine operational audit. Citing the network connections of machine control units and emergency stop systems, the draft report demanded that we submit a hazard assessment and cybersecurity measures under TRBS 1115 Part 1.
Until now, we thoroughly carried out our mechanical and electrical periodic inspections under standard occupational safety regulations (BetrSichV). But cybersecurity for industrial automation is completely uncharted territory for us. We got a quote from an external consultancy, and they wanted 6.500 EUR just for an initial assessment. Which machines does this rule actually apply to, what documentation are we required to prepare as a small business, and what will they look for during periodic inspections?