EUSEC
Dashboard
Pricing Services Insurance

NIS2 is in force.
Management is personally liable.
Supply Chain Security is mandatory.

Security ratings and audit-ready evidence for your supply chain security duty required by Art. 21 NIS2 / § 30 BSIG.

How EUSEC solves this
NIS2 obligations · BSIG

NIS2 obligations.

§ 30(2) — Risk management
01Risk analysis & security policies§ 30(2) no. 1
02Incident handling§ 30(2) no. 2
03Business continuity & crisis management§ 30(2) no. 3
04Supply chain security§ 30(2) no. 4EUSEC
05Secure procurement, development & vulnerabilities§ 30(2) no. 5
06Assessing the effectiveness of measures§ 30(2) no. 6
07Cyber hygiene & training§ 30(2) no. 7
08Cryptography & encryption§ 30(2) no. 8
09Access control & asset management§ 30(2) no. 9
10Multi-factor authentication & secured communications§ 30(2) no. 10
Further NIS2 obligations
11Registration with the BSI§ 33
12Reporting · 24h/72h/1 month§ 32
13Management: approval, oversight & liability§ 38 (1),(2)personal liability
14Management: training duty§ 38 (3)
15Evidence & supervision (authority)§§ 39 / 61 / 62
Mandatory since 06 Dec 2025 no transition period
Exhibit 01 — The Obligation

NIS2 is live. No grace period.

Around 29,500 entities across 18 sectors fall under NIS2 and the german law BSIG. Three duties apply immediately: register with the BSI, report significant incidents (24h / 72h / 1 month, § 32), and implement and document risk-management measures (§ 30). Top management is personally liable for this. Since 6 December 2025, Germany’s NIS2 Implementation Act has been in force — with no transition period. Securing your supply chain is one of ten mandatory measures required by law (§ 30 BSIG). It is the only one not fully in your own hands: you carry responsibility for the security of your supply chain — including companies you don’t own — and you must be able to demonstrate, at any time, what you are doing about it.

06.12.
2025, in force — the new BSIG applies immediately, with no transition period for the ten measures under § 30
0
days of grace — the BSI registration deadline (6 March 2026) has already passed
€10M
or 2% of worldwide annual turnover — maximum fine for essential entities (§ 65)
§ 38
Management is personally liable, must approve and oversee the measures.
The full obligation set

Other NIS2 obligations.

Beyond the ten risk-management measures of § 30 BSIG, there are five further obligation areas: registration, reporting, governance and supervision. Most you meet with internal processes and clear governance — the structural exception is the supply chain (§ 30(2) no. 4). The EUSEC Inside Rating covers all of these areas as a structured self-assessment.

k § 33 BSIG

Registration with the BSI

Entry in the BSI portal with current master data and contact points; changes must be reported.

Art. 27 / 3(4)
l § 32 BSIG

Reporting obligations

Report significant incidents — early warning 24h, follow-up 72h, final report 1 month.

Art. 23
m § 38 (1),(2) BSIG

Approval & oversight

Management must approve the risk-management measures and oversee their implementation — and is personally liable for this.

Art. 20(1)
n § 38 (3) BSIG

Training duty

Management must take part in regular training on cybersecurity risks.

Art. 20(2)
o §§ 39 / 61 / 62 BSIG

Evidence & supervision

Periodic evidence obligation (KRITIS, § 39) plus the BSI’s information, audit and enforcement powers (§§ 61/62).

Art. 31–34

All of these obligations you drive in-house — with one structural exception: the security of your supply chain. That is exactly where EUSEC fits.

Exhibit 02 — The Problem

Do-it-yourself vs EUSEC?

Risk analysis, MFA, training, encryption — these you implement within your own four walls. Supply chain security (§ 30(2) no. 4 BSIG) is different: it requires you to assess and manage the security posture of suppliers whose systems you have no access to. That is exactly where the biggest incidents originate — and exactly where most companies are blind.

Liability without control

You bear personal responsibility (§ 38 BSIG) for the cybersecurity of companies you do not control. An incident at a supplier becomes your incident.

The scaling problem

Hundreds, often thousands of suppliers. Questionnaires and email chains do not scale. By the time the answers come back, the risk picture has long since changed.

Self-disclosures deceive

A questionnaire measures what a supplier says about itself — not what is visible from the outside. That produces a false sense of security, not solid evidence.

Risk is dynamic

A snapshot is out of date the moment it is taken. The supplier that was “green” yesterday can have an open, exploitable vulnerability today.

You don’t know WHEN you will be checked

For essential entities, the BSI can demand evidence at any time and without cause. If you only start documenting once the request arrives, you are too late.

No documentation, no evidence

When the incident or the supervisory request comes, only what you can substantiate counts. No documentation of your supply chain measures means: no evidence of your due diligence.

The edge

Supply Chain Security is not a nice-to-have. This is the edge where personal liability begins.

Exhibit 03 — The Evidence

You can be audited at any time.

Critical-infrastructure operators · KRITIS
Every 3 years — automatically

Proactive, periodic obligation to provide evidence to the BSI.

Basis: § 39 BSIG
Essential entities
Any time — on request

No fixed cycle, but the BSI can order evidence and audits proactively and without cause.

Basis: §§ 61/62 BSIG — supervisory powers
Important entities
Cause-based — reactive

Typically inspected after an incident or on specific suspicion.

Basis: §§ 61/62 BSIG — supervisory powers
The consequence

Evidence cannot be created on demand. Maintain the documentation of your supply chain and have it ready before the autorities ask you.

Exhibit 06 — Plain Talk

There is no NIS2 certification.

A “NIS2 certificate” does not exist. No private party can certify NIS2-Compliance; so EUSEC does not certify NIS2 compliance as well. Compliance and conformity is for the authority alone to judge. What we deliver is the independent proof of due diligence, continuous assessment and the audit-ready documentation of your supply chain security.

EUSEC — European Cyber Rating Agency
Scalable. Solid.

10 company ratings — free. Start today.

No credit card. No account required. No commitment.
Results straight to your inbox.