Around 29,500 entities across 18 sectors fall under NIS2 and the german law BSIG. Three duties apply immediately: register with the BSI, report significant incidents (24h / 72h / 1 month, § 32), and implement and document risk-management measures (§ 30). Top management is personally liable for this. Since 6 December 2025, Germany’s NIS2 Implementation Act has been in force — with no transition period. Securing your supply chain is one of ten mandatory measures required by law (§ 30 BSIG). It is the only one not fully in your own hands: you carry responsibility for the security of your supply chain — including companies you don’t own — and you must be able to demonstrate, at any time, what you are doing about it.
Beyond the ten risk-management measures of § 30 BSIG, there are five further obligation areas: registration, reporting, governance and supervision. Most you meet with internal processes and clear governance — the structural exception is the supply chain (§ 30(2) no. 4). The EUSEC Inside Rating covers all of these areas as a structured self-assessment.
Entry in the BSI portal with current master data and contact points; changes must be reported.
Report significant incidents — early warning 24h, follow-up 72h, final report 1 month.
Management must approve the risk-management measures and oversee their implementation — and is personally liable for this.
Management must take part in regular training on cybersecurity risks.
Periodic evidence obligation (KRITIS, § 39) plus the BSI’s information, audit and enforcement powers (§§ 61/62).
All of these obligations you drive in-house — with one structural exception: the security of your supply chain. That is exactly where EUSEC fits.
Risk analysis, MFA, training, encryption — these you implement within your own four walls. Supply chain security (§ 30(2) no. 4 BSIG) is different: it requires you to assess and manage the security posture of suppliers whose systems you have no access to. That is exactly where the biggest incidents originate — and exactly where most companies are blind.
You bear personal responsibility (§ 38 BSIG) for the cybersecurity of companies you do not control. An incident at a supplier becomes your incident.
Hundreds, often thousands of suppliers. Questionnaires and email chains do not scale. By the time the answers come back, the risk picture has long since changed.
A questionnaire measures what a supplier says about itself — not what is visible from the outside. That produces a false sense of security, not solid evidence.
A snapshot is out of date the moment it is taken. The supplier that was “green” yesterday can have an open, exploitable vulnerability today.
For essential entities, the BSI can demand evidence at any time and without cause. If you only start documenting once the request arrives, you are too late.
When the incident or the supervisory request comes, only what you can substantiate counts. No documentation of your supply chain measures means: no evidence of your due diligence.
Supply Chain Security is not a nice-to-have. This is the edge where personal liability begins.
Proactive, periodic obligation to provide evidence to the BSI.
No fixed cycle, but the BSI can order evidence and audits proactively and without cause.
Typically inspected after an incident or on specific suspicion.
Evidence cannot be created on demand. Maintain the documentation of your supply chain and have it ready before the autorities ask you.
A “NIS2 certificate” does not exist. No private party can certify NIS2-Compliance; so EUSEC does not certify NIS2 compliance as well. Compliance and conformity is for the authority alone to judge. What we deliver is the independent proof of due diligence, continuous assessment and the audit-ready documentation of your supply chain security.
No credit card. No account required. No commitment.
Results straight to your inbox.