NIS2 · Supply chain

Not in scope — and obliged all the same.

Most system houses sit below the size threshold and do not have to register with the BSI. The reach-through does not come from the regulator but from the customer — through the contract.

The mechanism

Why the duty reaches you although it falls on your customer

Entities in scope have to manage the security of their supply chain. That is one of the ten areas of measures under § 30 Abs. 2 BSIG. They cannot hand this duty over by outsourcing their IT — the responsibility stays with them.

So they pass the requirement on. Not as a request, but as a contract clause, because the implementing regulation prescribes exactly that.

In any case, essential and important entities should contractually oblige their suppliers to comply with security measures and should have this evidenced to them.
BSI, information pack “Sichere Lieferkette”
Even where IT is entirely outsourced, you remain responsible yourself. Contracts alone are not enough — the duty stays with management.
BSI, NIS2 FAQ, summarised in substance
In practice

What lands on your desk as a result

Usually not as a legal letter, but as a spreadsheet with a deadline.

A supplier questionnaire with questions that require an analysis across the entire managed estate.

A request for evidence of the patch level as of a date in the past.

A contract amendment with reporting deadlines you have to be technically able to meet.

A demand for an audit right or for regular audit reports.

The question of who at your end may access the customer's systems — and how that is evidenced.

Contractual duties

Six points your customer has to agree with you

Listed in Anhang 5.1.4 of Implementing Regulation (EU) 2024/2690. On the right is what octoja uses to make the answer evidenceable.

Cybersecurity requirements

What you implement technically can be evidenced from day-to-day operation instead of from a self-declaration.

Reporting incidents without undue delay

Alerting with service hours per channel and a timestamp per message — the basis for being able to meet a 24-hour deadline at all.

A right to audit or to receive audit reports

Reports can be produced on a schedule and per customer. Your client gets the evidence without anyone assembling screenshots.

Qualification and reliability of the personnel deployed

Who may access which system is governed through groups and 17 device action rights, and is traceable in the access overview.

Remediation of vulnerabilities

Patch level per endpoint, approvals naming the decision-maker with a timestamp, exceptions with a stored justification.

A continuously current register of the suppliers and systems in use

The inventory is captured automatically and keeps a change history — including the end of operating system support.

The other side

That same duty is your sales argument.

Your customers have to produce evidence and often do not know how. Whoever can deliver that is no longer selling remote support, but the ability to prove.

A patch compliance report that lands in the customer's inbox automatically every month answers their documentation duty under § 30 Abs. 1 Satz 3 BSIG — and at the same time answers the question of why your contract is worth its price.

Answer the next questionnaire out of the system

During trial access you produce the reports with your own devices and see which questions that covers — and which it does not.