Home / Blog / Article

NIS2 in the Supply Chain: When the Customer Becomes the Auditor

29,500 companies fall under NIS2 — and pass the requirements down to suppliers. What small firms must evidence in 2026, and how to do it.

🔒 IT Security & CompliancePublished on August 22, 2026 | Read time: approx. 13 minutes | Author: Pragma-Code Editorial
NIS2 requirements travelling down the supply chain

Germany's NIS2 implementation act has applied since 6 December 2025 — with no transition period. Attention so far has focused on the roughly 29,500 directly regulated entities. The real reach, however, begins one level below: with the suppliers, service providers and software houses that sit well under every threshold and still suddenly have to answer questionnaires, audits and contract clauses. This article sets out what is actually being asked and how a small firm can deliver it at a reasonable cost.

Part of our Themen-Hub series:

This article is an in-depth expert contribution from our content cluster. Discover the complete overview on our main page:IT Security & Compliance

Executive Summary
  • The multiplier sits in the contract: NIS2 regulates roughly 29,500 entities directly. Because those entities must secure their supply chain, the regulation reaches a multiple of that number indirectly — through framework agreements, supplier questionnaires and audit clauses.
  • Missing answers cost contracts, not fines: An unregulated supplier faces no BSI proceedings. It faces removal from the approved supplier list — a risk that materialises earlier and is harder to repair.
  • The evidence pack is manageable: Security policy, asset and access overview, backup and recovery evidence, reporting channel, patch process and proof of awareness training. Six documents cover the bulk of every questionnaire in circulation.
DACH Compliance 2026

The letter comes from the customer, not the regulator

Most companies that start thinking seriously about information security in 2026 do so because a major customer sent a questionnaire. That, in practice, is what NIS2 looks like.

1. What has applied since December 2025

The European NIS 2 Directive should have been transposed into national law by 17 October 2024. Germany missed that deadline by a wide margin; only four of the 27 member states met it. On 7 May 2025 the Commission issued a reasoned opinion to 19 states, Germany among them. Only on 6 December 2025 did the German NIS2 implementation and cybersecurity strengthening act enter into force — with no transition period, despite industry associations having asked for exactly that.

Substantively, the act amends the BSI Act and makes the Federal Office for Information Security the central supervisory authority with far-reaching powers: it can order inspections, issue binding instructions and impose sanctions. The scope grows from around 4,500 to roughly 29,500 entities across 18 sectors. The registration deadline with the BSI expired on 6 March 2026.

The gap between the legal position and self-perception is striking. The Cyber Security Report 2026 finds that around 48 per cent of surveyed companies underestimate their own regulatory exposure. Many machine builders, suppliers and chemical companies across the DACH region assumed that cybersecurity regulation applies only to large groups and classic critical-infrastructure operators. In reality, thousands of mid-sized firms cross the 50-employee threshold into scope without noticing.

Definition of the threshold: In Germany, NIS2 generally applies from 50 employees or 10 million euros in annual turnover, provided the company operates in one of the 18 listed sectors. Individual sectors have deviating rules. Classification as an Essential Entity or an Important Entity depends on sector and size.

2. The pass-through mechanism

For small suppliers the decisive rule is not the threshold but the NIS2 Supply Chain Obligation. Regulated entities must assess and manage risks in their supply chain, including relationships with direct suppliers and service providers. No compliance officer at a regulated company can discharge that duty without asking their suppliers. So they ask — in writing, on a recurring basis, and with consequences at contract renewal.

In practice the pass-through runs along three channels that differ considerably in effort and negotiability.

01

The supplier questionnaire. Typically 40 to 120 questions on organisation, technology and process. It arrives annually, often with a short return deadline. Without standardised answers on file, it consumes several person-days every year.

02

The contract clause. Security annexes to framework agreements define minimum measures, reporting duties towards the customer and audit rights. Unlike the questionnaire, the clause is binding and survives staff turnover on both sides.

03

The audit, on site or by video. The sharpest stage, standard for critical providers with system access. Here self-declaration no longer counts; evidence does — logs, screenshots, configurations, restore tests.

The economic core is simple. An unregulated company risks no fine under the BSI Act. It risks failing the next supplier assessment. That is arguably more expensive, because it happens sooner and cannot be settled with a payment.

3. Am I regulated myself?

Before switching into supplier mode, it is worth honestly checking whether you are in fact regulated. The 48 per cent figure from the Cyber Security Report suggests this question is answered in the negative too quickly. Three constellations are routinely overlooked.

Group-wide counting

Headcount and turnover are not always assessed per legal entity. Affiliated companies may be counted together — a subsidiary with 30 employees inside a group of 400 looks rather different than it does on its own letterhead.

Sector follows the product

Sector allocation follows the activity, not the self-description. A software house that builds control systems exclusively for water utilities has a harder argument than one with a mixed customer base.

Managed services and data centres

Providers of IT services, data centre services and managed security services are addressed explicitly. Anyone operating servers for customers should examine this classification very carefully rather than relying on their own size.

Catching up on registration

The 6 March 2026 deadline has passed. Any regulated entity that failed to register is operating in a legal grey zone. Registering late is in every case better than waiting to be discovered.

Anyone who concludes from this check that they are regulated themselves will find the complete set of duties in our NIS2 guide for SMEs. Everyone else reads on from here as a supplier.

4. The evidence pack

The good news for small firms: questionnaires differ in wording but hardly in substance. They ask the same things in shifting order. Producing six artefacts once and maintaining them twice a year answers the bulk of every enquiry — and means that in an audit you can hand something over instead of telling a story.

1
Security policy with an effective date

Two to four pages will do. What matters is management approval, date, version and a named owner. A short, signed policy beats a twenty-page document without sign-off.

2
Asset and access overview

Which systems exist, who holds administrative access, and how is access revoked when someone leaves? These three questions appear in every questionnaire and are the most common trigger for follow-up requests.

3
Backup and recovery evidence

What is asked for is not the backup concept but the log of the last restore test, with date and result. A backup that has never been restored increasingly counts as absent in audits.

4
Reporting channel and availability

A named person, a monitored address, a phone number outside business hours. Customers need assurance that someone is reachable within hours during an incident — that now appears in nearly every clause.

5
Patch and vulnerability process

How do you learn about a critical vulnerability, who decides on deployment, and within what deadline? An SBOM for your own software products lifts the answer to a level many competitors cannot match.

6
Proof of awareness training

Attendance list, date, content. Phishing remains the most common entry route, which is why this question features prominently. One annual session with an attendance list satisfies it fully.

One point is routinely underestimated: the customer is not only checking whether measures exist but whether they can be evidenced. In practice, the entire difference between a passed and a re-opened supplier assessment sits between those two things.

Comparison: self-declaration vs. verifiable evidence

Self-declaration (increasingly insufficient)
  • Backups: “We back up daily.” Without a test log that is a statement of intent.
  • Access: “Only the admin has full access.” Without a list, the number of admins stays open.
  • Training: “Staff are aware.” Not verifiable without an attendance list.
  • Patches: “Updates are applied promptly.” Not assessable without a deadline and an owner.
Verifiable evidence (target state)
  • Backups: Log of the last restore test with date, duration and result.
  • Access: Exported role list from the identity provider, reviewed quarterly.
  • Training: Attendance list with date and content summary from the current year.
  • Patches: Documented process with deadlines by criticality and a named decision authority.

The difference is organisational rather than technical. Almost every firm we work with already does the things in the right-hand column — they simply do not record them. The effort therefore rarely lies in the measure but in the evidence, and a few hours per quarter secure it permanently.

A second effect is economically interesting. A small provider that can present a complete evidence pack changes the nature of the negotiation. Instead of discussing price and risk premium, procurement discusses capability. In several projects we have seen a cleanly documented security posture be the reason a framework agreement was renewed even though a cheaper competitor was in the running.

Expert tip: one answer dossier instead of ten questionnaires

Record the answers to the 60 most common questions once in an internal document, each with a pointer to the underlying evidence. New questionnaires then become a mapping exercise rather than a research project. In our client projects, the effort per questionnaire typically drops from days to hours.

5. The 24 / 72 / 30 reporting chain

Regulated entities must report significant security incidents in three stages: an Early Warning within 24 hours, an update within 72 hours and a final report within one month. This matters for suppliers because their customers can only meet those deadlines if they are informed in time. Security annexes therefore now routinely contain a reporting deadline towards the customer that is shorter than the statutory one — frequently twelve hours, occasionally eight.

Hour 0 to 12: notify the customer

The contractually agreed deadline. What is expected is not root cause analysis but fact: what happened, which customer systems or data flows might be affected, and who your contact is.

Hour 24: early warning to the BSI

An obligation of the regulated entity. Your contribution as a supplier is to provide reliable information — timestamps, affected interfaces, state of containment.

Hour 72: update

A first assessment of severity and impact. Anyone unable to produce their own logging at this point is offering conjecture — and will be rated accordingly in the supplier assessment.

Day 30: final report

Root cause, damage picture, measures taken. For suppliers this is the chance to turn an incident into evidence of maturity — provided the measures are actually implemented rather than merely announced.

The practical consequence is unspectacular and still rarely implemented: logging must exist and be retained for at least 90 days before anything happens. Without logs, every report after 72 hours is a narrative. We describe how a dependable recovery process is organised in The DACH Ransomware Wave.

6. Penalties and management liability

For directly regulated entities the act sets a tiered penalty framework. More important than the absolute figures, for most management boards, is a different point: the duty to implement appropriate risk management measures rests personally with the management and cannot be delegated.

Essential entities

The higher category, typically larger operators in particularly sensitive sectors.

up to €10m or 2%

of worldwide annual turnover, whichever amount is higher.

Important entities

The second category, with near-identical substantive requirements.

up to €7m or 1.4%

of worldwide annual turnover, whichever amount is higher.

To date, no case is publicly known in which a German company has been fined under NIS2. Concluding from that the supervision is toothless would be a mistake. Supervisory authorities typically build registration and inspection capacity first and sanction later. The penalty range is also not the only lever: orders, mandatory inspections and publication of breaches hit many companies more immediately.

The distinction from the German critical-infrastructure umbrella act also matters. NIS2 governs digital cybersecurity; the umbrella act governs the physical and operational resilience of critical infrastructure. Large operators frequently fall under both, with partly overlapping and partly separate evidence requirements.

7. Implementation in six steps

The following sequence is tailored to firms of 5 to 50 employees without a dedicated information security team. It can be completed alongside daily business in roughly a quarter.

  1. Step 1: assess exposure honestly

    Hold sector allocation, headcount and turnover against the thresholds and include group-wide attribution. The outcome is a documented determination — not as a formality, but so the question does not get relitigated every quarter.

  2. Step 2: review customer contracts for security annexes

    Which reporting deadlines, minimum measures and audit rights have you already signed? In many firms the most binding requirement has long been sitting in the contract folder, unknown to anyone in operations.

  3. Step 3: produce the six evidence documents

    Policy, asset and access overview, restore log, reporting channel, patch process, training record. Short, dated, approved. The standard is completeness, not elegance.

  4. Step 4: actually run a restore test

    Recover one system from backup, time it, log the result. That single afternoon changes the quality of every answer you give afterwards — and reliably surfaces at least one unpleasant surprise.

  5. Step 5: build the answer dossier

    The 60 most common questions with an answer and a pointer to the relevant evidence document. From here on, every further customer questionnaire becomes routine rather than a project.

  6. Step 6: schedule a half-yearly refresh

    Two calendar slots of two hours each: review documents, reconcile the access list, follow up on training. Without a fixed date the pack ages out within a year and the work starts over.

Regulation rarely reaches a small firm through the statute book. It reaches it through the procurement department of its largest customer — and there, no transition period applies, only a return deadline.

Quick check: are you supply-ready under NIS2?

Approved security policy with date, version and named owner
Current overview of administrative access including the revocation process
Log of a genuine restore test from the past twelve months
Named reporting channel with availability outside business hours
Defined patch process, complemented by an SBOM for your own software
Training record with attendance list from the current year

Conclusion

NIS2 is designed as regulation for 29,500 entities and operates as a market requirement for a multiple of that. For a small supplier this is initially an imposition: bearing cost for a law that formally does not address them. Commercially, however, it is one of the few compliance requirements that pays for itself directly — because the measures are the same ones that prevent a shutdown after an attack.

The effort is also front-loaded and then low. A firm with the six evidence documents, a real restore test behind it and a maintained answer dossier handles customer questionnaires in hours rather than days. A firm without them renegotiates under time pressure every year — and eventually loses a framework agreement to a competitor whose paperwork was more complete.

Our experience from mid-market projects is that the most expensive component is not the technology but the delay. The first three documents take a day to produce. They simply tend not to get produced until the questionnaire is already on the desk.

Do you have questions about the NIS2 supply chain?

Book a free initial consultation

Have a vision?

Let's check together how we can make your idea take flight.

Book your free strategy call now

Extended Specialized Glossary

NIS2 Supply Chain Obligation

The duty of regulated entities to assess and manage security risks in their own supply chain, including relationships with direct suppliers and service providers. It is the mechanism through which NIS2 reaches suppliers that are not themselves regulated.

Essential Entity

The higher of the two NIS2 categories. Germany's implementation act provides for fines of up to 10 million euros or 2 per cent of worldwide annual turnover, whichever is higher.

Important Entity

The second NIS2 category, with a slightly lower penalty range of up to 7 million euros or 1.4 per cent of worldwide annual turnover. The substantive security requirements barely differ.

Early Warning

The first stage of the NIS2 reporting chain: a significant security incident must be reported within 24 hours, followed by an update after 72 hours and a final report after one month.

SBOM

Software Bill of Materials — a machine-readable inventory of every component and dependency in a piece of software. It makes it possible to answer within minutes whether your own product is affected by a newly disclosed vulnerability.

Alexander Ohl

Alexander Ohl

Pragma-Code Support (AI)• Online

Hello! I am the Pragma-Code Assistant. How can I help you today? You can ask me about our services or select a topic below.