Lesson 1.5 · 5 min
Not covered, but a supplier
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- No duties under the NISG. A business outside the NISG 2026 needn't register or report. The requirements reach it anyway, through its customers.
- Your customers must secure their supply chain. Covered businesses must take into account the security of their relationships with their direct suppliers and service providers.
- What contracts should say. Security requirements, training, reporting incidents, audit rights, fixing vulnerabilities, subcontractors and duties when the contract ends.
- There is no NIS2 certificate. Whether an ISO 27001 certification is enough is for the customer to decide on its risk assessment. A general reference in the terms and conditions isn't enough.
- Anyone may report. Businesses that aren't covered can also report incidents, threats and near misses to the national CSIRT, voluntarily and anonymously.
In detail
If you aren't covered
Then the duties of the NISG 2026 don't apply to you: no registration, no reporting duty, no self-declaration. Keep a record of how you checked (lessons 1.2 to 1.4); customers will ask.
Why customers ask anyway
Covered entities must deal with supply chain security in their risk management, including their relationships with their direct suppliers and service providers, their vulnerabilities, the quality of their products and their cyber security practices § 32(4)(d) NISG 2026. The NISV 2026 makes the catalogue of requirements in Implementing Regulation (EU) 2024/2690 binding on all covered entities for this § 2 NISV 2026.
The Federal Office counts in all participants of the supply chain around the network and information systems that support the entity's services, down to the air conditioning for the server room; not every supplier is meant, but not only IT providers either (Federal Office, FAQ).
What may end up in your contracts
Where appropriate on its risk assessment, the customer sets out in the contract (Implementing Regulation (EU) 2024/2690, Annex point 5.1.4):
- cyber security requirements for you, including for the ICT products and services you supply;
- requirements for your staff's awareness, skills, training and where appropriate certification;
- background checks on your staff;
- your duty to report without undue delay any security incident that poses a risk to it;
- a right to audit or to receive audit reports;
- your duty to fix vulnerabilities that put it at risk;
- rules for subcontractors;
- your duties when the contract ends, such as returning and deleting its information.
The customer also keeps a register of its direct suppliers with a contact point and the ICT products and services each supplies (Annex point 5.2), and includes suppliers in its awareness programme where appropriate (Annex point 8.1.2).
What counts as proof
There is no general certificate of compliance with the NISG 2026. Whether a supplier's ISO 27001 certification is enough must be decided case by case on the risk assessment; its scope and validity matter. A general reference to the NISG 2026 in terms and conditions or purchasing conditions doesn't meet the requirements; what is needed are specific contractual duties that can be checked (Federal Office, FAQ).
Reporting voluntarily
Entities outside the act's scope can voluntarily report cyber security incidents, cyber threats and near misses to the national CSIRT § 37(2) NISG 2026, without revealing who they are § 37(3) NISG 2026.
Check yourself anyway
Many suppliers are covered themselves without knowing it: as IT providers with remote maintenance (Annex 1 no. 9), as manufacturers in NACE divisions 26 to 30, or through their group's figures.
Checklist
- We have checked, and recorded, that we aren't covered ourselves.
- We know which of our customers fall under the NISG 2026.
- We have a standard answer for information security questionnaires.
- We can report incidents affecting customers without delay: who does it and the contacts are settled.
- We review new clauses on audit rights, vulnerabilities and subcontractors before we sign.
Quiz
A covered customer's purchasing conditions make a general reference to the NISG 2026. In the Federal Office's view, is that enough for its supply chain security?
- Yes, if the supplier signs
- No, specific contractual duties that can be checked are needed
- It isn't enough only for suppliers from abroad
- Yes, the reference is enough
Show the answer
The answer is B: No, specific contractual duties that can be checked are needed. According to the Federal Office (FAQ, supply chain), a general reference in terms or purchasing conditions isn't enough; the requirements aim at specific contractual duties that can be checked.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 32, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 2, RIS, in German, version of 6 October 2026
- Implementing Regulation (EU) 2024/2690, Art. 2 and Annex, EUR-Lex (also in English)
- Network and Information System Security Act 2026 (NISG 2026) § 37, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Federal Office for Cyber Security, FAQ: supply chain, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.