Written by the NIS2Compass Team ·
Your company is not directly NIS2-obliged, but your NIS2-obliged customers (automotive OEM, chemicals, pharma, large machine builders) send security assessments, contract clauses and audit requests. §30 No. 4 BSIG turns you into the object of examination. NIS2Compass delivers the content you need to answer customer requirements confidently, without being forced into own NIS2 compliance.
Direct obligation unlikely
Classic hauliers, component and SaaS suppliers are rarely directly listed in Annex 1 or 2. An individual assessment is recommended.
Indirect pressure via §30 No. 4
NIS2-obliged customers must assess their suppliers. You receive questionnaires and audit requests, also below your own thresholds.
Contract clauses in framework agreements
OEMs add NIS2 security clauses to framework agreements. Rejection often means losing the customer.
Many suppliers mistakenly consider themselves directly NIS2-obliged, or conversely, not relevant at all. The real pressure arrives via the supply chain.
OEMs send assessments with 50-200 questions. Deadline: days. Without an own process: unstructured single responses and rework.
Framework agreements come back with NIS2 clauses: audit rights, notification duties, processor agreements. Which clauses do you accept?
A supplier with 180 employees serves an automotive OEM. The customer suddenly sends a 120-question security assessment and demands new contract clauses. Direct NIS2 obligation is typically not given. The pressure comes from the customer's §30 No. 4 BSIG duty. NIS2Compass delivers article clusters on supply chain security, contract clauses and concentration risk. The supplier templates (written from the customer's perspective) can be used mirrored as a structured response template, prepared once, reusable for every customer questionnaire.
Supply chain article cluster
A-11, A-31, A-32, A-33 as base for responses
Templates used mirrored
Build your response template once, reuse many times
NIS2 Guide
8 chapters, 124 substeps as structural reference
Customers must assess you as a supplier. Typical question areas: access control, encryption, incident process, backup, training, supplier management (including sub-suppliers).
§30 No. 4 BSIG obliges customers to agree on audit rights with critical suppliers. You may be asked to allow on-site audits. Scope, frequency and confidentiality must be negotiated.
Customers demand that you report security incidents that could affect them. Timeframes are often analogous to §32 BSIG (24/72 hours), even though you are not subject to §32 yourself.
More in the blog: Am I affected by NIS2?, NIS2 vs. ISO 27001, Is ISO 27001 enough for NIS2 compliance?.
| Kriterium | NIS2Compass | Klassische Beratung | ISMS-Tool | Selbstumsetzung |
|---|---|---|---|---|
| Monthly cost | €29 | €700-1,200/day | €200-2,000/month | €0 |
| Structured questionnaire responses | yes (articles + templates) | individual (expensive) | often not the focus | ad-hoc chaos |
| Fits multiple customers | yes, reusable | billed per project | yes, but expensive | own work |
| Contract clause argumentation | yes (article A-32) | yes | rarely | own work |
| Onboarding | 10 minutes | days to weeks | days + setup | months |
| Scaling with growing customer base | cost-neutral | linearly rising | linearly rising | linearly rising |
Prepared once, reusable for every customer.