{"id":9296,"date":"2026-08-06T10:03:36","date_gmt":"2026-08-06T10:03:36","guid":{"rendered":"http:\/\/locaterisk.com\/de\/?post_type=wissen&#038;p=9296"},"modified":"2026-08-06T11:22:08","modified_gmt":"2026-08-06T11:22:08","slug":"nis2-supply-chain-security","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/nis2-supply-chain-security\/","title":{"rendered":"NIS2 and Supply Chain Security: Managing Third-Party Risks"},"content":{"rendered":"<h1 class=\"wp-block-heading\">NIS2 and Supply Chain Security: Managing Third-Party Risks<\/h1>\n<span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n\n\n<p>Attackers often target not their actual target, but its service providers. The NIS2 Directive addresses this issue by requiring affected companies to actively manage the security of their supply chain. This article explains what the German implementing law specifically requires and how you can effectively manage third-party risks (as of August 2026).<\/p>\n<p>In connection with NIS2, the following are often <strong>Supplier Risk Management<\/strong>, <strong>Vendor Risk Management (VRM)<\/strong>, <strong>Third-Party Risk Management (TPRM)<\/strong> and <strong>Cyber Supply Chain Risk Management (C-SCRM)<\/strong> . These terms overlap, but each has a different focus: VRM focuses primarily on suppliers, TPRM covers all third parties, and C-SCRM specifically addresses cyber risks within the supply chain.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>The NIS2 Implementation Act took effect on December 6, 2025, without a transition period. According to the BSI, the number of regulated entities will increase from approximately 4,500 to approximately 29,500.<\/li><li>Section 30(2)(4) of the BSIG expressly requires supply chain security, including relationships with direct suppliers or service providers.<\/li><li>Companies must assess their suppliers' specific vulnerabilities, incorporate security requirements into contracts, and continuously monitor compliance.<\/li><li>Under Section 65 of the BSIG, violations are subject to fines of up to ten million euros; for companies with high revenue, fines may amount to up to 2 percent of total revenue. Management bears personal responsibility for implementing and monitoring compliance.<\/li><li>Automated security ratings, combined with vendor risk management, make it feasible and documentable to evaluate many suppliers.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Why NIS2 Specifically Regulates the Supply Chain<\/h2>\n\n\n\n<p>The NIS2 Directive (EU) 2022\/2555 lists supply chain security as one of the ten minimum measures for cyber risk management. Article 21(2)(d) explicitly mentions it, including the security-related aspects of relationships with direct suppliers or service providers. The German legislature has adopted this requirement almost verbatim in Section 30(2)(4) of the new BSI Act.<\/p>\n\n\n\n<p>Recital 85 of the Directive explains the reason: There has been a rise in incidents where companies are compromised through vulnerabilities in third-party products and services. Remote maintenance access, a tampered software component, or an inadequately secured cloud service opens the door for attackers to enter otherwise well-protected networks. A company\u2019s own firewall is of little help if a supplier with privileged access is itself vulnerable.<\/p>\n\n\n\n<p>The NIS2 Implementation Act has been in effect in Germany since December 6, 2025, with no grace period from the very first day. According to its own statements, the BSI now oversees approximately 29,500 organizations across 18 sectors, ranging from energy and healthcare to transportation and manufacturing. Many small and medium-sized enterprises are subject to cybersecurity regulations for the first time. Our article provides a comprehensive overview of the scope of application, thresholds, and obligations: <a href=\"\/en\/know\/nis2-directive-overview\/\">NIS2 Directive<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What the law specifically requires: assessment, contracts, monitoring<\/h2>\n\n\n\n<p>The obligation to ensure supply chain security consists of three components. First, supplier assessment: Article 21(3) of the Directive requires that the specific vulnerabilities of each direct supplier be taken into account, as well as the overall quality of its products and its cybersecurity practices, including the security of its development processes. A blanket assessment based on gut feeling does not meet this standard.<\/p>\n\n\n\n<p>Second, contractual provisions. Security requirements are effective only if they are agreed upon in a binding manner. In practice, these include, among other things:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Specific security requirements for the service provider, such as those related to patch management and encryption<\/li><li>Reporting Procedures and Deadlines for Security Incidents That Fulfill Your Own Reporting Obligations<\/li><li>Rights to access information and conduct audits, so you can verify compliance<\/li><li>Regulations Governing the Use of Subcontractors<\/li><li>Exit Clauses and Obligations to Cooperate in the Event of an Orderly Separation<\/li><\/ul>\n\n\n\n<p>Third, continuous monitoring. A one-time assessment during onboarding does not provide a permanent picture of the risk landscape, because a supplier\u2019s attack surface changes with every new system and every configuration change. Added to this is the governance level: According to Section 38 of the BSIG, management must implement risk management measures, monitor their implementation, and undergo regular training. If management violates these obligations, it is liable to its own organization for damages caused through negligence. Our overview of the <a href=\"\/en\/know\/nis2-requirements-mandatory-measures\/\">NIS2 Requirements and Mandatory Measures<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Questionnaire, Security Rating, Audit: A Comparison of Three Methods<\/h2>\n\n\n\n<p>Three methods have become established for supplier evaluation; they take different perspectives and complement one another. Questionnaires assess processes and organization from the supplier\u2019s perspective. A <a href=\"\/en\/know\/what-is-a-security-rating\/\">Security Rating<\/a> measures the attack surface that is actually visible from the Internet. Audits conduct in-depth reviews of internal processes. The following overview illustrates the differences.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Criterion<\/th><th>Questionnaire<\/th><th>Security Rating<\/th><th>On-site audit<\/th><\/tr><\/thead><tbody><tr><td>Perspective<\/td><td>Supplier's Self-Declaration<\/td><td>An External Perspective on Realistically Attainable Systems<\/td><td>In-Depth Review of Internal Processes<\/td><\/tr><tr><td>Cost per Supplier<\/td><td>Steps: Create, Follow Up, Evaluate<\/td><td>Minimal: Analysis without the supplier's involvement<\/td><td>High: Preparation, Appointment, Report<\/td><\/tr><tr><td>Timeliness<\/td><td>Status as of the time of the survey<\/td><td>can be updated on an ongoing basis<\/td><td>Status as of the audit date<\/td><\/tr><tr><td>Objectivity<\/td><td>depending on self-assessment<\/td><td>measurable technical findings<\/td><td>high, as verified by an independent audit<\/td><\/tr><tr><td>Scalability:<\/td><td>limited by feedback and evaluation<\/td><td>high, entire portfolio in parallel<\/td><td>low, individual suppliers<\/td><\/tr><tr><td>Typical Applications<\/td><td>Process and Compliance Issues<\/td><td>Ongoing monitoring of all suppliers<\/td><td>Critical partners with deep access<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>In practice, this combination has proven effective: Ratings provide an ongoing, objective basis for the entire portfolio. Questionnaires delve deeper into process-related issues with relevant partners. Audits are reserved for the few suppliers who are deeply integrated into your systems. This allows you to focus your efforts where the risk lies.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Automated Security Ratings and VRM: How to Implement Them Successfully<\/h2>\n\n\n\n<p>Anyone tasked with evaluating 50 or 200 suppliers will quickly reach capacity limits using manual methods. Automated security ratings solve this scalability problem. The analysis examines a supplier\u2019s externally accessible systems from an attacker\u2019s perspective, without installing agents and without the company\u2019s involvement. The technical foundation for this is provided by <a href=\"\/en\/know\/what-is-easm\/\">External Attack Surface Management (EASM)<\/a>. LocateRisk provides initial results within 48 hours; after that, regular reassessments keep the picture up to date.<\/p>\n<p>When it comes to supplier ratings, their reliability also depends on how up-to-date the vulnerability data is. LocateRisk uses <a href=\"\/en\/landing\/preemptive-intelligence-identifying-cyber-risks-before-they-become-apparent\/\">Preemptive Intelligence<\/a>, to cross-reference reports from multiple sources with a vendor\u2019s attack surface, even if a final NVD assessment is not yet available. This makes new potential risks visible earlier, prompting a risk-based review.<\/p>\n\n\n<p>Important for setting realistic expectations: The assessment reveals which of a vendor\u2019s systems are accessible via the Internet, what software is in use there, and where configuration flaws exist. In case of doubt, the vendor itself determines whether a specific installed version is actually vulnerable. The rating provides prioritized starting points for this and makes the discussion concrete, whereas a questionnaire remains abstract.<\/p>\n\n\n\n<p>The second component is a structured vendor risk management system. This allows you to centrally manage questionnaires, evaluate responses, store supporting documentation such as certificates, and automatically remind suppliers of outstanding responses. The combination of an external technical assessment and documented self-disclosure provides a robust overall picture for each supplier while also generating the documentation you need to present to management and regulatory authorities. To see how this works in practice, visit our page on <a href=\"\/en\/landing\/third-party-risk-management\/\">Third Party Risk Management<\/a>. LocateRisk operates the platform in compliance with the GDPR in certified German data centers, using an ISO 27001-certified ISMS.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Practical Workflow: Supply Chain Security in Five Steps<\/h2>\n\n\n\n<p>Getting started doesn't have to be a major project. With this approach, you can build the required processes step by step:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>Take inventory of suppliers and classify them.<\/strong> Identify all direct suppliers and service providers, from IT service providers to software vendors. Classify them by criticality: Who has access to your systems or data, and how quickly could a partner be replaced?<\/li><li><strong>Assess risks.<\/strong> Conduct a security assessment of your entire portfolio to establish an objective baseline. For critical suppliers, conduct a more in-depth review using a targeted questionnaire on processes, certifications, and emergency preparedness.<\/li><li><strong>Modify contracts.<\/strong> Include security requirements, incident reporting obligations, audit rights, and regulations for subcontractors in new contracts. Prioritize existing contracts based on criticality and update them upon the next renewal.<\/li><li><strong>Monitor continuously.<\/strong> Have ratings updated regularly and define thresholds at which you will take action, such as in the event of a significant deterioration in the security level. Schedule recurring reassessments for critical partners.<\/li><li><strong>Document and report.<\/strong> Document evaluations, actions, and decisions in a way that is easy to follow. Report regularly to management, as they are required to monitor implementation in accordance with \u00a7 38 BSIG and need reliable metrics to do so.<\/li><\/ol>\n\n\n\n<p>This spreads the workload out over the course of the year, and each step also generates the documentation that would be required in an emergency or during an audit.<\/p>\n\n\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Does supply chain security also apply to companies that are not themselves subject to NIS2?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Indirectly, yes. Regulated companies must assess their direct suppliers and pass on security requirements through their contracts. Suppliers or IT service providers working for customers subject to NIS2 should therefore expect questionnaires, ratings, and new contract clauses. A demonstrably high level of security thus becomes a factor in sales, not just in compliance.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Is an annual questionnaire sufficient for NIS2 compliance?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Questionnaires remain a useful tool, but they cover only part of the requirements. Article 21(3) of the Directive requires that the specific vulnerabilities of each direct provider and the quality of its cybersecurity practices be taken into account. This also requires a technical assessment of the actual attack surface and ongoing monitoring between survey cycles.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Which suppliers should I include in the evaluation?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">The legal obligation applies to direct providers and service providers\u2014that is, your direct contractual partners. A risk-based approach makes sense here: Prioritize partners with access to systems or data, such as IT service providers, software vendors, cloud and data center operators, and maintenance companies with remote access.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What penalties apply for violations of supply chain obligations?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Section 65 of the BSIG provides for fines of up to ten million euros for particularly important institutions, and up to 2 percent of total annual revenue for those with annual revenue exceeding 500 million euros. For important institutions, the fines are up to seven million euros or 1.4 percent, respectively. In addition, pursuant to \u00a7 38 of the BSIG in conjunction with the provisions of corporate law, management is liable to its own institution for damages caused by culpable breaches of duty.<\/p><\/div><\/div><\/div><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion: From a Mandatory Requirement to a Controllable Process<\/h2>\n\n\n\n<p>NIS2 makes supply chain security a verifiable management responsibility: evaluating suppliers, incorporating requirements into contracts, and continuously monitoring compliance. With automated security ratings and structured vendor risk management, you can fulfill these obligations without significantly expanding your staff and keep track of your entire supplier portfolio. Our page shows you exactly how to get started. <a href=\"\/en\/landing\/vendor-risk-management-made-easy\/\">Vendor risk management made easy<\/a>. There, you can request a demo and start evaluating your first suppliers right away.<\/p>","protected":false},"excerpt":{"rendered":"<p>NIS2 Makes Supply Chain Compliance Mandatory: Requirements Under Section 30 of the BSIG, a Comparison of Methods, and a 5-Step Workflow with Security Ratings and VRM.<\/p>","protected":false},"author":0,"featured_media":0,"template":"","wissen_thema":[819],"class_list":["post-9296","wissen","type-wissen","status-publish","hentry","wissen_thema-regulatorik-compliance"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NIS2 Lieferkettensicherheit richtig umsetzen \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"NIS2 fordert Sicherheit der Lieferkette: Was \u00a7 30 BSIG verlangt, wie Sie Lieferanten bewerten und wie Security Ratings plus VRM die Umsetzung erleichtern.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/locaterisk.com\/en\/know\/nis2-supply-chain-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIS2 Lieferkettensicherheit richtig umsetzen \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"NIS2 fordert Sicherheit der Lieferkette: Was \u00a7 30 BSIG verlangt, wie Sie Lieferanten bewerten und wie Security Ratings plus VRM die Umsetzung erleichtern.\" \/>\n<meta property=\"og:url\" content=\"http:\/\/locaterisk.com\/en\/know\/nis2-supply-chain-security\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-06T11:22:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-lieferkettensicherheit\\\/\",\"url\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-lieferkettensicherheit\\\/\",\"name\":\"NIS2 Lieferkettensicherheit richtig umsetzen \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-08-06T10:03:36+00:00\",\"dateModified\":\"2026-08-06T11:22:08+00:00\",\"description\":\"NIS2 fordert Sicherheit der Lieferkette: Was \u00a7 30 BSIG verlangt, wie Sie Lieferanten bewerten und wie Security Ratings plus VRM die Umsetzung erleichtern.\",\"breadcrumb\":{\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-lieferkettensicherheit\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-lieferkettensicherheit\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-lieferkettensicherheit\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"NIS2 und Lieferkettensicherheit: Drittanbieter-Risiken im Griff\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Implementing NIS2 Supply Chain Security the Right Way \u2013 LocateRisk","description":"NIS2 Requires Supply Chain Security: What Section 30 of the BSIG Requires, How to Evaluate Suppliers, and How Security Ratings and VRM Facilitate Implementation.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/locaterisk.com\/en\/know\/nis2-supply-chain-security\/","og_locale":"en_US","og_type":"article","og_title":"NIS2 Lieferkettensicherheit richtig umsetzen \u2013 LocateRisk","og_description":"NIS2 fordert Sicherheit der Lieferkette: Was \u00a7 30 BSIG verlangt, wie Sie Lieferanten bewerten und wie Security Ratings plus VRM die Umsetzung erleichtern.","og_url":"http:\/\/locaterisk.com\/en\/know\/nis2-supply-chain-security\/","og_site_name":"LocateRisk","article_modified_time":"2026-08-06T11:22:08+00:00","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/locaterisk.com\/de\/wissen\/nis2-lieferkettensicherheit\/","url":"http:\/\/locaterisk.com\/de\/wissen\/nis2-lieferkettensicherheit\/","name":"Implementing NIS2 Supply Chain Security the Right Way \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-08-06T10:03:36+00:00","dateModified":"2026-08-06T11:22:08+00:00","description":"NIS2 Requires Supply Chain Security: What Section 30 of the BSIG Requires, How to Evaluate Suppliers, and How Security Ratings and VRM Facilitate Implementation.","breadcrumb":{"@id":"http:\/\/locaterisk.com\/de\/wissen\/nis2-lieferkettensicherheit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/locaterisk.com\/de\/wissen\/nis2-lieferkettensicherheit\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/locaterisk.com\/de\/wissen\/nis2-lieferkettensicherheit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/locaterisk.com\/de\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"NIS2 und Lieferkettensicherheit: Drittanbieter-Risiken im Griff"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"version-history":[{"count":5,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9296\/revisions"}],"predecessor-version":[{"id":9339,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9296\/revisions\/9339"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=9296"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=9296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}