CYBER COLLECTIVE LAB · Edition 2
Third-party risk assessment (TPRM) in the strategic chemicals sector
Third-party risk in strategic chemicals: the edition on assessing the suppliers a process plant cannot pause.
Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm. Grimaldi Forum, a ten-minute pitch.
Book the workshopOur Assises workshopBY INDUSTRY · MANUFACTURING
The corporate CISO has no authority on the shop floor, the plant manager owns production, the group is an important entity under NIS2 and R&D ships products under the CRA. Mindlapse consolidates the picture without pretending to see the PLCs.
NIS2 important entity · CRA on shipped products · Plants as entities · Suppliers both ways
| Entity | Score | Risk Analysis | Third parties | Exceptions | Business Impact | Remediation |
|---|---|---|---|---|---|---|
| Lyon plant | 82 | 4.4 | 4.1 | 3.9 | 4.3 | 4.0 |
| Gdańsk plant | 74 | 4.0 | 3.7 | 3.3 | 3.9 | 3.6 |
| R&D centre | 69 | 3.7 | 3.4 | 3.2 | 3.5 | 3.4 |
| Monterrey plant | 61 | 3.4 | 3.1 | 2.4 | 3.3 | 2.9 |
| Recent acquisition | 43 | 2.8 | 1.2 | 2.1 | 2.6 | 2.3 |
| Group average | · | 3.7 | 3.1 | 3.0 | 3.5 | 3.2 |
Exceptions pile up on the plant with the oldest lines; the acquisition arrives with almost nothing in the third-party column.
THE SITUATION
The corporate CISO advises; the line stops when the plant manager says so, and not before.
MES, SCADA and HMIs on unsupported systems, vendor-controlled, under exceptions that outlive everyone who signed them.
A plant bought last year, three tools, no register, and the group’s auditor next month.
Vulnerability handling, support periods and an SBOM that engineering has never produced.
WHO IS IN SCOPE
Manufacturers of medical devices, electronics, electrical equipment, machinery, vehicles and other transport equipment, chemicals and food are NIS2 Annex II sectors, mostly as important entities. Makers of products with digital elements fall under the CRA, whose reporting duties come first and whose full obligations follow; machine makers also meet the Machinery Regulation. Some French groups are operators of vital importance under the Code de la défense, a regime the platform does not enter. The CRA page carries the dates; the NIS2 page, the entity test.
Written for
WHAT MINDLAPSE CHANGES
Surface: Organization Map
Each plant is an entity with its own register, scales and owners; the group reads the consolidated picture and drills down to the plant’s records, never to a site inventory.
Learn more
Surface: Value Chain Map
Production lines and the systems behind them are modelled as activities with their impact, and advisories match the systems you declare. Mindlapse does not see the PLCs and does not pretend to.
Learn more
Surface: Mindlapse Trust Grade
The tier-one with remote access and the integrator on the line carry a Trust Grade from their assessment, the business impact and external ratings, re-assessed on events.
Learn more
Surface: Security by Design
A new controller or a connected machine enters as an initiative with security requirements attached at design, routed by criticality; the CRA record grows from there.
Learn more
Surface: Derogation lane
The unpatchable HMI gets a derogation with compensating measures, an approver and an expiry that reopens the decision at the next shutdown.
Learn more
THE OBLIGATIONS MAP
EU rows first; every "verifies" cell is a product claim at ledger level, no cell carries a date, and the French sentence under the table is the site’s one dated source.
| Regulation | Obligation | What Mindlapse verifies | Surface |
|---|---|---|---|
| NIS2 | Art. 21(2)(d) · supply-chain security | Proportionate, context-aware supplier assessments, re-assessment on events, contradictions flagged with evidence | Supplier Hub |
| NIS2 | Art. 21(2)(e) · secure acquisition, development and vulnerability handling | Security requirements attached to initiatives at design; advisories matched to declared systems every morning | Security by Design |
| CRA | Art. 13 and Annex I · product risk assessment and essential requirements | Requirements carried into your control set with cross-framework mapping; the product risk assessment as living records | Control Atlas |
| CRA | Art. 14 · reporting duties | Actively exploited vulnerabilities and severe incidents recorded as risks and actions with owners; the notification file drafted by the cascade and logged; you file it | Risk Register |
| NIS2 | Art. 20 · accountability across plants | Consolidated posture by entity, plants as entities, the management body reading one picture | Organization Map |
| Machinery Regulation | Cybersecurity among the essential health and safety requirements | The machine’s digital elements assessed in the same product risk assessment; evidence dated | Risk Register |
NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026.
A QUARTER, THEN THE DAY THE CUSTOMER ASKS
Four moments of an ordinary quarter in a plant group, and what the platform had already done; then the day an OEM asks, in three steps.
A normal quarter
alert: WEEK 1
The acquisition joins the group view.
Its third-party maturity was flagged on the group view before anyone had opened its register.
Surface: Organization Map
WEEK 4
A tier-one integrator’s remote-access derogation expired.
The expiry reopened the decision with its compensating measures and its approver.
Surface: Derogation lane
WEEK 8
The new controller’s CRA risk assessment is updated.
As living records on the product, with the actions and their owners.
Surface: Risk Register
verified: WEEK 12
The OEM answer goes out.
The plant’s control narrative and the product record, sent from the atlas.
Surface: Control Atlas
The day the customer asks
THE REQUEST
An OEM sends its supplier questionnaire and asks for the evidence behind three answers.
The answers were read from the plant’s verified controls, not written for the occasion.
Surface: Control Atlas
WHAT OPENS
The plant’s verified Control Atlas, its derogations, the product record.
Each derogation with its compensating measures and its expiry; the product record with its risk assessment.
Surface: Derogation lane
WHAT IS EXPORTED
The control set, the evidence, the product file.
The plant’s control set with its evidence from Audit mode, and the CRA Article 13 file as living records.
Surface: Audit mode
Illustrative quarter: the moments are fictional, the surfaces are the product’s.
FROM THE FIELD
CYBER COLLECTIVE LAB · Edition 2
Third-party risk in strategic chemicals: the edition on assessing the suppliers a process plant cannot pause.
CYBER COLLECTIVE LAB · Edition 3
The Security by Design factory in automotive: field feedback on securing products at design, inside the OEM’s cadence.
Measured with our design-partner CISOs, figures under continuous validation.
UNDER THE HOOD
FAQ
No OT connector today. Lines and the systems behind them are modelled as activities with their impact, and the built-in feeds match advisories to the systems you declare; nothing is read from the PLCs.
Yes. IEC 62443 is in the catalog and maps to the same control set as NIS2 and the CRA, and TISAX is there for the automotive tiers; a control implemented once answers each of them.
The product record does: it carries the risk assessment and its actions with owners, and R&D, the plant and the corporate CISO read the same record at their own altitude.
Yes. Autonomy is a permission model: each plant runs its own register with scales per organization, inherited from the group where you decide, and the group reads the consolidated view without editing the plant’s records.
From the verified Control Atlas of the plant, with the evidence behind each answer, and, when the customer runs Mindlapse, through its portal, where answers and action plans synchronize on both sides.
Read it next
Also by outcome
PLANTS, CONSOLIDATED
A live session on your structure: plants, tiers, derogations, the group view.
Our host’s audience measurement (Vercel) uses no cookies and is not covered by this choice. Google Analytics and marketing trackers stay off until you say otherwise. Read the cookie policy