NIS2 and Supply Chain Security: Managing Third-Party Risks
This text was generated using artificial intelligence (AI).
Attackers often target not their actual target, but its service providers. The NIS2 Directive addresses this issue by requiring affected companies to actively manage the security of their supply chain. This article explains what the German implementing law specifically requires and how you can effectively manage third-party risks (as of August 2026).
In connection with NIS2, the following are often Supplier Risk Management, Vendor Risk Management (VRM), Third-Party Risk Management (TPRM) and Cyber Supply Chain Risk Management (C-SCRM) . These terms overlap, but each has a different focus: VRM focuses primarily on suppliers, TPRM covers all third parties, and C-SCRM specifically addresses cyber risks within the supply chain.
Key Points at a Glance
The NIS2 Implementation Act took effect on December 6, 2025, without a transition period. According to the BSI, the number of regulated entities will increase from approximately 4,500 to approximately 29,500.
Section 30(2)(4) of the BSIG expressly requires supply chain security, including relationships with direct suppliers or service providers.
Companies must assess their suppliers' specific vulnerabilities, incorporate security requirements into contracts, and continuously monitor compliance.
Under Section 65 of the BSIG, violations are subject to fines of up to ten million euros; for companies with high revenue, fines may amount to up to 2 percent of total revenue. Management bears personal responsibility for implementing and monitoring compliance.
Automated security ratings, combined with vendor risk management, make it feasible and documentable to evaluate many suppliers.
Why NIS2 Specifically Regulates the Supply Chain
The NIS2 Directive (EU) 2022/2555 lists supply chain security as one of the ten minimum measures for cyber risk management. Article 21(2)(d) explicitly mentions it, including the security-related aspects of relationships with direct suppliers or service providers. The German legislature has adopted this requirement almost verbatim in Section 30(2)(4) of the new BSI Act.
Recital 85 of the Directive explains the reason: There has been a rise in incidents where companies are compromised through vulnerabilities in third-party products and services. Remote maintenance access, a tampered software component, or an inadequately secured cloud service opens the door for attackers to enter otherwise well-protected networks. A company’s own firewall is of little help if a supplier with privileged access is itself vulnerable.
The NIS2 Implementation Act has been in effect in Germany since December 6, 2025, with no grace period from the very first day. According to its own statements, the BSI now oversees approximately 29,500 organizations across 18 sectors, ranging from energy and healthcare to transportation and manufacturing. Many small and medium-sized enterprises are subject to cybersecurity regulations for the first time. Our article provides a comprehensive overview of the scope of application, thresholds, and obligations: NIS2 Directive.
What the law specifically requires: assessment, contracts, monitoring
The obligation to ensure supply chain security consists of three components. First, supplier assessment: Article 21(3) of the Directive requires that the specific vulnerabilities of each direct supplier be taken into account, as well as the overall quality of its products and its cybersecurity practices, including the security of its development processes. A blanket assessment based on gut feeling does not meet this standard.
Second, contractual provisions. Security requirements are effective only if they are agreed upon in a binding manner. In practice, these include, among other things:
Specific security requirements for the service provider, such as those related to patch management and encryption
Reporting Procedures and Deadlines for Security Incidents That Fulfill Your Own Reporting Obligations
Rights to access information and conduct audits, so you can verify compliance
Regulations Governing the Use of Subcontractors
Exit Clauses and Obligations to Cooperate in the Event of an Orderly Separation
Third, continuous monitoring. A one-time assessment during onboarding does not provide a permanent picture of the risk landscape, because a supplier’s attack surface changes with every new system and every configuration change. Added to this is the governance level: According to Section 38 of the BSIG, management must implement risk management measures, monitor their implementation, and undergo regular training. If management violates these obligations, it is liable to its own organization for damages caused through negligence. Our overview of the NIS2 Requirements and Mandatory Measures.
Questionnaire, Security Rating, Audit: A Comparison of Three Methods
Three methods have become established for supplier evaluation; they take different perspectives and complement one another. Questionnaires assess processes and organization from the supplier’s perspective. A Security Rating measures the attack surface that is actually visible from the Internet. Audits conduct in-depth reviews of internal processes. The following overview illustrates the differences.
Criterion
Questionnaire
Security Rating
On-site audit
Perspective
Supplier's Self-Declaration
An External Perspective on Realistically Attainable Systems
In-Depth Review of Internal Processes
Cost per Supplier
Steps: Create, Follow Up, Evaluate
Minimal: Analysis without the supplier's involvement
High: Preparation, Appointment, Report
Timeliness
Status as of the time of the survey
can be updated on an ongoing basis
Status as of the audit date
Objectivity
depending on self-assessment
measurable technical findings
high, as verified by an independent audit
Scalability:
limited by feedback and evaluation
high, entire portfolio in parallel
low, individual suppliers
Typical Applications
Process and Compliance Issues
Ongoing monitoring of all suppliers
Critical partners with deep access
In practice, this combination has proven effective: Ratings provide an ongoing, objective basis for the entire portfolio. Questionnaires delve deeper into process-related issues with relevant partners. Audits are reserved for the few suppliers who are deeply integrated into your systems. This allows you to focus your efforts where the risk lies.
Automated Security Ratings and VRM: How to Implement Them Successfully
Anyone tasked with evaluating 50 or 200 suppliers will quickly reach capacity limits using manual methods. Automated security ratings solve this scalability problem. The analysis examines a supplier’s externally accessible systems from an attacker’s perspective, without installing agents and without the company’s involvement. The technical foundation for this is provided by External Attack Surface Management (EASM). LocateRisk provides initial results within 48 hours; after that, regular reassessments keep the picture up to date.
When it comes to supplier ratings, their reliability also depends on how up-to-date the vulnerability data is. LocateRisk uses Preemptive Intelligence, to cross-reference reports from multiple sources with a vendor’s attack surface, even if a final NVD assessment is not yet available. This makes new potential risks visible earlier, prompting a risk-based review.
Important for setting realistic expectations: The assessment reveals which of a vendor’s systems are accessible via the Internet, what software is in use there, and where configuration flaws exist. In case of doubt, the vendor itself determines whether a specific installed version is actually vulnerable. The rating provides prioritized starting points for this and makes the discussion concrete, whereas a questionnaire remains abstract.
The second component is a structured vendor risk management system. This allows you to centrally manage questionnaires, evaluate responses, store supporting documentation such as certificates, and automatically remind suppliers of outstanding responses. The combination of an external technical assessment and documented self-disclosure provides a robust overall picture for each supplier while also generating the documentation you need to present to management and regulatory authorities. To see how this works in practice, visit our page on Third Party Risk Management. LocateRisk operates the platform in compliance with the GDPR in certified German data centers, using an ISO 27001-certified ISMS.
Practical Workflow: Supply Chain Security in Five Steps
Getting started doesn't have to be a major project. With this approach, you can build the required processes step by step:
Take inventory of suppliers and classify them. Identify all direct suppliers and service providers, from IT service providers to software vendors. Classify them by criticality: Who has access to your systems or data, and how quickly could a partner be replaced?
Assess risks. Conduct a security assessment of your entire portfolio to establish an objective baseline. For critical suppliers, conduct a more in-depth review using a targeted questionnaire on processes, certifications, and emergency preparedness.
Modify contracts. Include security requirements, incident reporting obligations, audit rights, and regulations for subcontractors in new contracts. Prioritize existing contracts based on criticality and update them upon the next renewal.
Monitor continuously. Have ratings updated regularly and define thresholds at which you will take action, such as in the event of a significant deterioration in the security level. Schedule recurring reassessments for critical partners.
Document and report. Document evaluations, actions, and decisions in a way that is easy to follow. Report regularly to management, as they are required to monitor implementation in accordance with § 38 BSIG and need reliable metrics to do so.
This spreads the workload out over the course of the year, and each step also generates the documentation that would be required in an emergency or during an audit.
Indirectly, yes. Regulated companies must assess their direct suppliers and pass on security requirements through their contracts. Suppliers or IT service providers working for customers subject to NIS2 should therefore expect questionnaires, ratings, and new contract clauses. A demonstrably high level of security thus becomes a factor in sales, not just in compliance.
Questionnaires remain a useful tool, but they cover only part of the requirements. Article 21(3) of the Directive requires that the specific vulnerabilities of each direct provider and the quality of its cybersecurity practices be taken into account. This also requires a technical assessment of the actual attack surface and ongoing monitoring between survey cycles.
The legal obligation applies to direct providers and service providers—that is, your direct contractual partners. A risk-based approach makes sense here: Prioritize partners with access to systems or data, such as IT service providers, software vendors, cloud and data center operators, and maintenance companies with remote access.
Section 65 of the BSIG provides for fines of up to ten million euros for particularly important institutions, and up to 2 percent of total annual revenue for those with annual revenue exceeding 500 million euros. For important institutions, the fines are up to seven million euros or 1.4 percent, respectively. In addition, pursuant to § 38 of the BSIG in conjunction with the provisions of corporate law, management is liable to its own institution for damages caused by culpable breaches of duty.
Conclusion: From a Mandatory Requirement to a Controllable Process
NIS2 makes supply chain security a verifiable management responsibility: evaluating suppliers, incorporating requirements into contracts, and continuously monitoring compliance. With automated security ratings and structured vendor risk management, you can fulfill these obligations without significantly expanding your staff and keep track of your entire supplier portfolio. Our page shows you exactly how to get started. Vendor risk management made easy. There, you can request a demo and start evaluating your first suppliers right away.
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.