Supply Chain Security

Supply chain security means securing information security along an organisation's own procurement relationships. As a risk-management measure, § 30(2) sentence 2 no. 4 BSIG requires the security of the supply chain, including the security-related aspects of relationships with direct suppliers or service providers. The duty stays with the entity in scope.

NIS2Last reviewed:

There are two ways to arrive at this subject, and they need different answers.

Either you are the entity in scope and have to secure your own procurement relationships. Or a German customer has sent you a security annex citing § 30(2) no. 4 BSIG, and you are working out how much of it you actually have to accept. For a great many companies outside Germany, the second is how NIS2 first turns up at all.

Both readings start in the same place.

What the provision says

The catalogue in § 30(2) sentence 2 BSIG names, at no. 4, "Sicherheit der Lieferkette einschließlich sicherheitsbezogener Aspekte der Beziehungen zu unmittelbaren Anbietern oder Diensteanbietern": security of the supply chain, including security-related aspects of the relationships with direct suppliers or service providers. The European reference text, Article 21(2)(d) of Directive (EU) 2022/2555, is to the same effect.

This is one of the few places where the German transposition does not diverge from the directive at all. If you have already implemented this control for another Member State, the substance carries over; only the citation changes.

Both texts direct attention at direct suppliers and service providers. A duty to examine the entire multi-tier chain, down to your supplier's supplier, cannot be derived from the provision. That does not remove the risk — a critical subcontractor remains a critical subcontractor — but it puts the centre of gravity of the examination where a contractual relationship exists.

It is also the answer to the fourth-party questionnaire that occasionally arrives: the statutory requirement does not reach that far, whatever a template may say.

Why the supply chain is in the catalogue at all

An organisation's attack surface does not end at its firewall. Managed service providers, software vendors, data centre and maintenance contractors often hold far-reaching access, and an attack routed through a service provider bypasses perimeter control entirely. The legislative conclusion is straightforward: whoever answers for the availability, integrity and confidentiality of a service has to assess the security quality of those who help deliver it.

If you are the entity in scope

A register that holds up. Without a complete view of suppliers, services procured, types of access and data processed, everything downstream is guesswork. What is usually missing is precisely the small specialist applications and maintenance access paths that nobody ever filed as "IT service provider".

Criticality rather than equal treatment. A provider with administrative access to production systems warrants a different depth of examination than a supplier with no system connection at all. Useful criteria are the extent of access, replaceability, contribution to delivering your own services, and the consequences of an outage.

Contractual anchoring. Security requirements, duties to cooperate and to inform in the event of security incidents, rules on subcontractors, audit and information rights, and provisions for termination belong in the contract rather than in a statement of intent.

Evidence with an expiry date. Certificates, audit reports and self-assessments are snapshots. The part to read is the scope: a certificate whose scope does not cover the service delivered to you says very little.

Reporting paths that align. Your own 24-hour deadline under § 32 BSIG runs from the point of becoming aware of a significant security incident. If a service provider informs you days later, the deadline is structurally unmeetable. Short contractual information duties are therefore not a formality; they are the precondition of your own ability to report at all.

If you are the supplier being asked

The statutory duties fall on the entity in scope. A supplier does not become subject to registration or reporting because its customer is. Whether a supplier is itself covered depends on its own activity and size under § 28 BSIG and Annexes 1 and 2.

What does happen is that the requirements are passed down by contract, and that is legitimate: your customer has to be able to evidence this control. Three things are worth doing rather than resisting.

Ask which duty a clause serves. A requirement traceable to § 30(2) no. 4 BSIG is negotiable in its detail but not in its existence; one that is traceable to nothing usually came from a template.

Read the incident notification clause closely. That clause has a hard statutory deadline behind it, and it is the one where an unrealistic commitment will actually be tested.

And check the scope of any certificate you offer before offering it. Producing a group certificate that does not cover the delivering entity costs credibility that a later, better answer will not recover.

What supply chain security does not mean

There is no statutory obligation to demand a particular certification from suppliers. The BSIG names no specific means of evidence; choosing one is a question of appropriateness. Equally, contractual flow-down does not transfer the statutory duty: it remains with the entity in scope, which is why a supplier's assurance never fully discharges it.

What is actually examined

Examining bodies and supervisory authorities are less interested in whether a questionnaire exists than in the control loop behind it. The recurring questions: is the supplier register complete and current, and how would you know? On what criteria was criticality classified, and who decided? What consequence did a poor assessment have? Was there a condition, a deadline, an escalation path, or was the finding simply filed? And what was done with suppliers who could not meet a requirement?

That last question is the uncomfortable one, because the honest answer is often "nothing". A documented residual risk, time-limited and approved by the responsible function, stands up far better here than a formally complete assessment with no consequences attached.

The limits of the questionnaire

Self-assessments are a legitimate instrument, but they measure willingness to answer, not security. The sensible approach is to grade the depth of examination by criticality: a standardised self-assessment for the breadth, audit reports or certificates with a matching scope for critical providers, and in individual cases your own examination on a contractual basis. A questionnaire that is the same length for everyone costs time everywhere and delivers depth nowhere.

Neighbouring regimes

For financial entities, DORA governs the management of ICT third-party risk separately and in considerably more detail; the contractual requirements sit in Chapter V, Section I (Articles 28 to 30) of Regulation (EU) 2022/2554. An ISMS to ISO/IEC 27001 likewise contains measures on supplier relationships and generally supplies a large part of the structure for § 30(2) sentence 2 no. 4 BSIG. The catalogue in § 30(2) BSIG is expressly not exhaustive: sentence 2 requires "at least" the measures it names.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework