Not in scope — and obliged all the same.
Most system houses sit below the size threshold and do not have to register with the BSI. The reach-through does not come from the regulator but from the customer — through the contract.
Why the duty reaches you although it falls on your customer
Entities in scope have to manage the security of their supply chain. That is one of the ten areas of measures under § 30 Abs. 2 BSIG. They cannot hand this duty over by outsourcing their IT — the responsibility stays with them.
So they pass the requirement on. Not as a request, but as a contract clause, because the implementing regulation prescribes exactly that.
In any case, essential and important entities should contractually oblige their suppliers to comply with security measures and should have this evidenced to them.
Even where IT is entirely outsourced, you remain responsible yourself. Contracts alone are not enough — the duty stays with management.
What lands on your desk as a result
Usually not as a legal letter, but as a spreadsheet with a deadline.
A supplier questionnaire with questions that require an analysis across the entire managed estate.
A request for evidence of the patch level as of a date in the past.
A contract amendment with reporting deadlines you have to be technically able to meet.
A demand for an audit right or for regular audit reports.
The question of who at your end may access the customer's systems — and how that is evidenced.
Six points your customer has to agree with you
Listed in Anhang 5.1.4 of Implementing Regulation (EU) 2024/2690. On the right is what octoja uses to make the answer evidenceable.
Cybersecurity requirements
What you implement technically can be evidenced from day-to-day operation instead of from a self-declaration.
Reporting incidents without undue delay
Alerting with service hours per channel and a timestamp per message — the basis for being able to meet a 24-hour deadline at all.
A right to audit or to receive audit reports
Reports can be produced on a schedule and per customer. Your client gets the evidence without anyone assembling screenshots.
Qualification and reliability of the personnel deployed
Who may access which system is governed through groups and 17 device action rights, and is traceable in the access overview.
Remediation of vulnerabilities
Patch level per endpoint, approvals naming the decision-maker with a timestamp, exceptions with a stored justification.
A continuously current register of the suppliers and systems in use
The inventory is captured automatically and keeps a change history — including the end of operating system support.
That same duty is your sales argument.
Your customers have to produce evidence and often do not know how. Whoever can deliver that is no longer selling remote support, but the ability to prove.
A patch compliance report that lands in the customer's inbox automatically every month answers their documentation duty under § 30 Abs. 1 Satz 3 BSIG — and at the same time answers the question of why your contract is worth its price.
Answer the next questionnaire out of the system
During trial access you produce the reports with your own devices and see which questions that covers — and which it does not.