An Edge Built on Knowledge and Experience
NIS2 / BSIG § 30 (2) No. 4

NIS2 Supply Chain Security: Effectively Assessing Service Providers

Attackers deliberately exploit security gaps at service providers. NIS2 requires systematic supply chain review — we explain what that means in practice.

Technical & Legal Expertise Experience From Numerous NIS2 Projects Based in Sindelfingen
§ 30 (2) No. 4 BSIG

What NIS2 Requires for Supply Chain Security

§ 30 (2) No. 4 BSIG explicitly obligates affected entities to ensure the security of the supply chain, including security-related aspects of relationships with direct suppliers and service providers. Responsibility does not end at your own company's boundary.

Practical risk: Many successful cyberattacks deliberately exploit security gaps at service providers as an entry point. Anyone who does not review their supply chain imports someone else's risk into their own infrastructure — and remains liable regardless.

Assessment Process

How Service Providers Are Assessed Under NIS2

Step 1: Inventory

Record all service providers and suppliers who have access to your systems or provide services your NIS2 services depend on.

  • IT service providers & managed services
  • Cloud and SaaS providers
  • Software suppliers (patch paths)
  • Physical service providers with IT access

Step 2: Risk Classification

Not all service providers are equally critical. Prioritise by dependency and access level.

  • Critical: full access to core systems
  • High: partial access or critical data
  • Medium: supporting services
  • Low: no IT contact

Step 3: Contract Adjustment

Review existing contracts and add NIS2-compliant cybersecurity clauses.

  • Define minimum security requirements
  • Grant audit and information rights
  • Establish incident reporting obligations
  • Define consequences for breach of duty
Difficult Cases

What to Do If a Service Provider Doesn't Cooperate?

A service provider refuses to disclose security information — what now?
If a provider gives no information about its security measures and won't accept cybersecurity clauses, that's a risk signal. You have two options: increased monitoring of data flow and access, or switching providers. The decision must be documented and justified on a risk basis.
Do all suppliers need to demonstrate ISO 27001 or comparable certifications?
No — but for critical service providers, certification is the simplest form of evidence. Alternatives include completed security questionnaires, contractual assurances with audit rights, or results of external security audits. The scrutiny applied should match the provider's risk level.
Does the supply chain obligation also apply to open-source software?
Yes, to the extent open-source software is embedded in security-relevant systems. There is no contracting party for OSS — the obligation shifts to internal processes: vulnerability monitoring, regular updates, and use of Software Composition Analysis (SCA) tools.
Related Topics

Further NIS2 Topics

Build Structured Supply Chain Risk Management

We create your service provider inventory, develop assessment frameworks, and draft NIS2-compliant contract clauses.

Request Consultation Now
Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com