
Industries in Focus
Last updated:
8 min.
Based on the research work of Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann
Sensitive research data worth billions. Highly automated production facilities whose failure can cause supply bottlenecks for vital medicines. A key role in the healthcare systems of entire nations. The pharmaceutical industry combines everything that makes it a prime target for cybercriminals and state-sponsored attackers. And since the NIS 2 Directive and the Cyber Resilience Act, it is fully regulated for the first time. Teichmann has systematically analyzed the concrete requirements for the pharmaceutical sector (Teichmann, Cybersecurity in the Pharmaceutical Sector – Requirements of the EU NIS 2 Directive and the Cyber Resilience Act, Pharma Recht 2025, pp. 590–595).
Why the Pharmaceutical Sector is Particularly at Risk
Pharmaceutical companies combine multiple risk factors. They possess high-value research data – active ingredient formulas, clinical study results, patent information – the theft of which enables industrial espionage on a grand scale. They operate highly automated production facilities, the manipulation or shutdown of which jeopardizes the supply of medicines. And they play a system-critical role, making them targets for blackmailers seeking maximum leverage (Teichmann, Pharma Recht 2025, pp. 590–595).
The European legislature has responded with two complementary frameworks: the NIS 2 Directive, which regulates the operations of pharmaceutical companies, and the Cyber Resilience Act, which addresses the security of the digital products they use and manufacture.
Pharmaceutical Companies as Critical Infrastructure
The most significant innovation of the NIS 2 Directive for the pharmaceutical sector is its explicit classification as critical infrastructure. Within the healthcare sector, NIS 2 covers not only hospitals and laboratories, but also explicitly medicine manufacturers and pharmaceutical research and development facilities. This is a fundamental shift: under the old German KRITIS regulation, hospitals were primarily considered critical infrastructure in the healthcare sector, while pharmaceutical producers were not covered (Teichmann, Pharma Recht 2025, pp. 590–595).
With NIS 2, this changes fundamentally. The Federal Office for Information Security (BSI) expects around 29,000 newly regulated entities in Germany overall – including numerous pharmaceutical companies that must comply with comprehensive cybersecurity requirements for the first time. As a rule of thumb, this applies to companies with more than 50 employees or an annual turnover exceeding 10 million euros.
The Specific NIS 2 Requirements
Affected pharmaceutical companies must implement appropriate technical, organizational, and operational security measures that correspond to the state of the art. This includes a comprehensive security strategy with continuous risk analysis considering sector-specific threats like industrial espionage, functioning incident response management, business continuity measures with backup management and emergency concepts, and the systematic securing of the supply chain (Teichmann, Pharma Recht 2025, pp. 590–595).
Supply chain security is particularly relevant for the pharmaceutical sector, as production facilities rely on a multitude of suppliers, software vendors, and IT service providers. The reporting obligations follow a three-stage model: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month.
The Cyber Resilience Act: A Special Case for Pharma
There is an important distinction when it comes to the Cyber Resilience Act. Medical devices themselves are exempt from the CRA because the Medical Device Regulation already provides sector-specific cybersecurity requirements for them. However, this does not mean that the CRA is irrelevant for pharmaceutical companies (Teichmann, Pharma Recht 2025, pp. 590–595).
This is because pharmaceutical companies use numerous connected products that are not classified as medical devices: industrial control systems, IoT sensors, laboratory equipment with network connectivity, general IT hardware, and software. All of these products must comply with CRA requirements starting in 2027. Furthermore, if pharmaceutical companies develop and place connected products on the market themselves, they will bear the full responsibilities of manufacturers under the CRA.
The Legal Consequences of Non-Compliance
The threat of sanctions under the NIS 2 Directive is substantial: essential entities face fines of up to 10 million euros or two percent of global annual turnover. In addition, there is the personal liability of senior management: NIS 2 requires corporate leadership to actively approve, monitor, and undergo training on cybersecurity measures. Breaches of duty can lead to personal internal liability (Teichmann, Pharma Recht 2025, pp. 590–595).
Conclusion: Cybersecurity Becomes Public Security of Supply
In the pharmaceutical sector, cybersecurity has a dimension that goes beyond the individual business: it is part of the security of supply. A successful attack on a major drug manufacturer can cause supply shortages of vital medicines. With NIS 2 and the CRA, the European legislature has made the pharmaceutical sector fully accountable for the first time. The effort required is considerable – but it is an investment in the resilience of a sector whose functioning is indispensable for the health of millions of people.
All source citations refer to published scientific papers by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in the publication index (as of May 2026).
Related Posts


