NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Weiterführende Seiten

  • Blog
  • FAQ
  • Glossar
  • Use Cases
  • Branchen
  • Preisgestaltung

Offizielle Quellen

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Ihr Navigator durch die NIS2-Compliance

Rechtliches

  • Datenschutzerklärung
  • Allgemeine Geschäftsbedingungen
  • Cookie-Richtlinie
  • Impressum

Ressourcen

  • Blog
  • Use Cases
  • Branchen
  • Preise
  • FAQ
  • Glossar

Kontakt

Kontakt

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. Alle Rechte vorbehalten.

Entwickelt in DeutschlandAllianz für Cyber-Sicherheit — Teilnehmer
HomeIndustriesSupply Chain & Suppliers

NIS2 in the Supply Chain: A Guide for Suppliers

Written by the NIS2Compass Team · Last updated: April 2026

Your company is not directly NIS2-obliged, but your NIS2-obliged customers (automotive OEM, chemicals, pharma, large machine builders) send security assessments, contract clauses and audit requests. §30 No. 4 BSIG turns you into the object of examination. NIS2Compass delivers the content you need to answer customer requirements confidently, without being forced into own NIS2 compliance.

  • Response templates for typical customer questionnaires
  • 40+ articles as a technical argumentation base
  • Supplier templates usable mirrored as your own response base
  • Contract clause analysis: audit rights, notification duties, ISO substitutes
Try Pro · €29/monthBlog: Am I affected by NIS2?
Hosted in Germany·GDPR-compliant·cancellable monthly

Are you as a supplier affected by NIS2?

Direct obligation unlikely

Classic hauliers, component and SaaS suppliers are rarely directly listed in Annex 1 or 2. An individual assessment is recommended.

Indirect pressure via §30 No. 4

NIS2-obliged customers must assess their suppliers. You receive questionnaires and audit requests, also below your own thresholds.

Contract clauses in framework agreements

OEMs add NIS2 security clauses to framework agreements. Rejection often means losing the customer.

Clarify your supplier classification: „Am I affected by NIS2?" in the blog

Typical NIS2 challenges in the supply chain

Affected or not?

Many suppliers mistakenly consider themselves directly NIS2-obliged, or conversely, not relevant at all. The real pressure arrives via the supply chain.

Customer questionnaire wave

OEMs send assessments with 50-200 questions. Deadline: days. Without an own process: unstructured single responses and rework.

Contract changes under time pressure

Framework agreements come back with NIS2 clauses: audit rights, notification duties, processor agreements. Which clauses do you accept?

How NIS2Compass helps suppliers

A supplier with 180 employees serves an automotive OEM. The customer suddenly sends a 120-question security assessment and demands new contract clauses. Direct NIS2 obligation is typically not given. The pressure comes from the customer's §30 No. 4 BSIG duty. NIS2Compass delivers article clusters on supply chain security, contract clauses and concentration risk. The supplier templates (written from the customer's perspective) can be used mirrored as a structured response template, prepared once, reusable for every customer questionnaire.

Supply chain article cluster

A-11, A-31, A-32, A-33 as base for responses

Templates used mirrored

Build your response template once, reuse many times

NIS2 Guide

8 chapters, 124 substeps as structural reference

Which NIS2 requirements are coming at suppliers?

§30 No. 4

Security questionnaire (passed through from customer duty)

Customers must assess you as a supplier. Typical question areas: access control, encryption, incident process, backup, training, supplier management (including sub-suppliers).

§30 No. 4

Audit rights in framework agreements

§30 No. 4 BSIG obliges customers to agree on audit rights with critical suppliers. You may be asked to allow on-site audits. Scope, frequency and confidentiality must be negotiated.

§32

Notification of security incidents

Customers demand that you report security incidents that could affect them. Timeframes are often analogous to §32 BSIG (24/72 hours), even though you are not subject to §32 yourself.

More in the blog: Am I affected by NIS2?, NIS2 vs. ISO 27001, Is ISO 27001 enough for NIS2 compliance?.

NIS2Compass in comparison for suppliers

Comparison NIS2Compass vs. compliance consulting, ISMS tool and self-response for suppliers
KriteriumNIS2CompassKlassische BeratungISMS-ToolSelbstumsetzung
Monthly cost€29€700-1,200/day€200-2,000/month€0
Structured questionnaire responsesyes (articles + templates)individual (expensive)often not the focusad-hoc chaos
Fits multiple customersyes, reusablebilled per projectyes, but expensiveown work
Contract clause argumentationyes (article A-32)yesrarelyown work
Onboarding10 minutesdays to weeksdays + setupmonths
Scaling with growing customer basecost-neutrallinearly risinglinearly risinglinearly rising

Frequently asked questions on NIS2 for suppliers

Ready to answer customer questionnaires in a structured way?

Prepared once, reusable for every customer.

Try Pro · €29/monthBlog: Am I affected by NIS2?
cancellable monthly·no setup fee·Hosted in Germany

Official sources

  • §30 BSIG in full text (German)
  • BSIG Annex 1 (German)
  • BSIG Annex 2 (German)
  • BSI guide on NIS2 regulation (German)