CybersicherheitJune 24, 2026·5 min read

NIS2 for suppliers: How supply chain clauses hit small businesses too

Under 50 employees and still NIS2 requirements in the contract? Why regulated customers pass their obligations on to suppliers — and how you should respond.

Not in scope — and obligated anyway

The thresholds of the NIS2 Directive are clear: as a rule, only companies with 50 or more employees or €10 million in annual turnover in one of the covered sectors are directly regulated. Many smaller businesses therefore believe they are safe. What they overlook is a mechanism that has long been at work in practice: the contractual pass-through of security requirements along the supply chain.

Why your customers put you on the hook

Affected entities must also ensure the security of their supply chain under § 30 BSIG (Germany's NIS2 implementation act) — including their direct suppliers and service providers. A regulated company can only meet this obligation by imposing demonstrable minimum standards on its suppliers. The result is security annexes in framework agreements, supplier questionnaires, and audit rights that increasingly reach trade businesses, software service providers, and logistics companies with fewer than 50 employees.

Typical clauses in supplier contracts

  • Minimum measures: multi-factor authentication, patch management, encryption, and backup concepts as contractual obligations
  • Reporting duties: security incidents at the supplier must be notified to the customer within 24 or 48 hours
  • Evidence and audit rights: the customer may demand certificates, self-assessments, or on-site inspections
  • Termination and liability clauses: violations of the security annex entitle the customer to extraordinary termination or trigger contractual penalties

Sign or negotiate?

Supply chain clauses are a matter of negotiation — unlike the law itself. Before signing, check which measures you can realistically implement, and negotiate deadlines, materiality thresholds for notifications, and the liability cap. A blanket-accepted 24-hour reporting obligation without an internal procedure is a liability risk, not a sales argument.

The opportunity behind the obligation

A small business that can demonstrate documented basic security measures gains an advantage in tenders from regulated customers. Whether your customer itself falls under NIS2 can be clarified via the overview of affected sectors; a structured self-assessment of your own situation is offered by the NIS2 check.

Matching tool

Comply with NIS2 before the BSI comes knocking.

Check now with the BSI →

Frequently asked questions

Can the BSI sanction me directly as a supplier?

No. Fines under the BSIG only hit the regulated entities themselves. As a supplier not directly in scope, you are liable exclusively under contract to your customer — for example via contractual penalties, damages, or termination of the contract for violations of agreed security annexes.

Do I have to accept every security clause as a supplier?

No, the clauses are freely negotiable. Basic technical measures and a reporting obligation for significant incidents are customary and usually bearable. You should critically review unlimited audit rights, very short reporting deadlines without a materiality threshold, and liability clauses without a cap.

Is an ISO 27001 certification sufficient as evidence?

In most cases, yes — an ISO 27001 certification largely covers the typical requirements from supplier questionnaires and often replaces laborious individual evidence. For small businesses, a documented security concept based on recognized standards such as the BSI IT-Grundschutz or DIN SPEC 27076 is frequently sufficient as an alternative.

Which measures should I implement first as a small business?

Start with the measures asked about in nearly every supplier questionnaire: multi-factor authentication for all remote access, regular updates and backups, a named contact person for security incidents, and a short, documented reporting procedure. These four points cover the majority of contractual requirements.

Related articles

Cybersicherheit

NIS2: Who is affected and what to do now

A practical guide to the applicability analysis and the key obligations under the German BSIG.

Cybersicherheit

The 7 most expensive compliance mistakes made by German SMEs

From the missing LUCID registration to the late data breach notification: these seven omissions regularly cost mid-sized companies five- to seven-figure sums.

← All articles