forumNew topic

Audit demands cybersecurity under TRBS 1115 Part 1 — what applies to us in Germany?

AArifMember
Job title
Civil engineer
Joined
Jun 2024
Message
62
#1

We are a precision machining shop with 22 employees in Baden-Württemberg, Germany. We operate six 5-axis CNC machines and an adjoining local parts transfer line. Last week, our employers' liability insurance association and the occupational safety inspectorate conducted a routine operational audit. Citing the network connections of machine control units and emergency stop systems, the draft report demanded that we submit a hazard assessment and cybersecurity measures under TRBS 1115 Part 1.

Until now, we thoroughly carried out our mechanical and electrical periodic inspections under standard occupational safety regulations (BetrSichV). But cybersecurity for industrial automation is completely uncharted territory for us. We got a quote from an external consultancy, and they wanted 6.500 EUR just for an initial assessment. Which machines does this rule actually apply to, what documentation are we required to prepare as a small business, and what will they look for during periodic inspections?

İİlker C***MemberCommunity member
Joined
May 2023
Message
29
Most Helpful#2

Short answer: TRBS 1115 Part 1 aims to prevent cyberattacks or software tampering from causing physical harm to workers. If a safety function on a CNC machine or transfer line (such as an emergency stop, light curtain or speed limiter) is managed via a networked PLC or controller, that system falls squarely within the scope of the rule.

You need to incorporate the cyber risk dimension into your existing hazard assessment (Gefährdungsbeurteilung) under the Industrial Safety Ordinance (BetrSichV). First, inventory all controllers industrial switches, and remote access points in your shop floor. Clarify which devices carry a safety function and how those devices connect to the plant network or the internet.

The minimum documentation you need for the audit includes: 1) An up-to-date network topology diagram showing safety-related measuring, control, and regulation components, 2) A revised hazard assessment addressing the likelihood of unauthorized machine access or malware causing a physical accident 3) Two-factor authentication and access control procedures for remote maintenance (Fernwartung) 4) A periodic testing plan verifying that cyber safeguards remain effective.

Periodic inspections do not mandate an independent IT auditor. A competent internal employee or service technician report documenting that you monitor unauthorized configuration changes default passwords, and security patches is accepted as sufficient by most auditors.

SSena Y***Member
Job title
Front office accounting
Sector
Healthcare services
Organization type
chain store
Joined
May 2023
Message
205
#3

The first place they'll check is the remote maintenance modules. Does the VPN or cellular modem the machine tool manufacturer uses for maintenance directly reach the machine's safety network? If your corporate office network and the shop floor (OT) are on the same VLAN, separate them physically or logically right away.

HHilal B***ExpertCommunity member
Joined
Feb 2026
Message
66
#4

We got a similar warning at our 18-machine mold shop in Bavaria. We paid an external consultant 4.200 EUR, and he prepared our network diagram and risk assessment in two days. The auditor just checked the report confirming the remote access key switch is kept off and that the e-stop cannot be overridden via software, and closed the case.

MMert Y***Member
Job title
Purchasing manager
Sector
Accounting & advisory
Organization type
two-branch business
Joined
Mar 2023
Message
3

Doki · Log management setup · 2024

#5

Don't jump straight into paying 6.500 EUR. Write to your machine manufacturers and request the safety architecture and cyber risk declaration from the CE compliance file for each model. You can start by simply attaching the manufacturer's technical data sheet to your existing risk assessment.

BBurcu Ö***New member
Job title
Store associate
Sector
Media and publishing
Organization type
40-person manufacturing company
Joined
Sep 2026
Message
2

Doki · Server maintenance contract · 2026

#6

Inspectors have been slapping TRBS 1115 onto every single report lately like a rubber stamp. If the safety relays on your machines are classic dry-contact hardwired setups and can't be overridden via the PLC over the network, you can push back and state the system falls out of scope.

ÖÖmer E***MemberCommunity member
Joined
Aug 2023
Message
71
#7

TRBS rules are technical standards, but under BetrSichV Section 3 they trigger a presumption of conformity (Vermutungswirkung). Once you document that you've implemented measures in line with this rule, you're legally covered; otherwise, you could face fault-based liability in the event of an industrial accident.

PPerihan K***MemberCommunity member
Joined
Jan 2023
Message
152
#8

There are three concrete documents an inspector will want on their desk: 1) A password management matrix and proof that default factory passwords were changed, 2) Temporary service tickets logged to grant remote access to machine vendors, 3) A maintenance logbook showing cybersecurity checks performed at least once a year.

SSenaMember
Job title
Graphic Designer
Organization type
two-branch business
Joined
Jul 2024
Message
86
#9

in our shop we put silicone dust caps over the usb ports behind the cnc screens and banned staff from charging phones there. once the inspector saw that he figured we took it seriously and didnt even dig too deep.

AAycan U***MemberCommunity member
Joined
Jul 2023
Message
2
#10

don't let it intimidate you they're not expecting bank-grade cybersecurity. the whole point is to keep ransomware from pushing a spindle past its RPM limits and throwing a workpiece into the operator.. and once you get the logic behind it, gathering the ppaerwork only takes a couple of days.

LLale T***MemberCommunity member
Joined
Nov 2023
Message
7
#11

ive been down this road, let me tell you. if 2FA is on a stolen password alone is useless.

the answer varies greatly by industry; there is no one-size-fits-all rule.

HHazalMember
Job title
UX Researcher
Joined
May 2024
Message
118
#12

Three different views emerged, they all complement each other. Don't rely on a single measure; go layer by layer.

Correct me if I'm wrong.

AAli T***MemberCommunity member
Joined
Sep 2023
Message
37
#13

I'd say don't rush. If it's your first time, start small; scaling comes later.

When making a decision, first look at what data you have on hand. I'm also curious if anyone does it differently.

BBarış B***Member
Job title
Project manager
Sector
Cosmetics
Organization type
regional distributor
Joined
Aug 2024
Message
77
#14

Great work. Everything goes well for the first three months; problems arise in the fourth.

Hope this helps.

YYasemin T***VeteranCommunity member
Joined
Apr 2026
Message
274
#15

i agree with this and just because everyone does it doesn't mean it's right.

that's all, sorry if I went on too long.

MMustafa U***Member
Job title
Social media manager
Sector
Real estate
Organization type
8-person team
Joined
Aug 2023
Message
65
#16

I went through the same thing.

SSelim K***MemberCommunity member
Joined
Jan 2023
Message
147
#17

The discussion got scattered, let me summarize. If you get three different answers on a topic, the question was asked wrong.

Of course, it varies if your situation is different.

PPolat S***MemberCommunity member
Joined
Mar 2024
Message
110
#18

I agree.

PPolat S***VeteranCommunity member
Joined
Sep 2024
Message
9
#19

This is exactly what we experienced. Trying to do this alone is the most expensive way.

If you post the result here, it will help others too.

EEbru Y***Expert
Job title
Content strategist
Joined
Nov 2023
Message
186
#20

I'm curious too.

Reply