NISG 2026 course All courses

Lesson 1.5 · 5 min

Not covered, but a supplier

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

If you aren't covered

Then the duties of the NISG 2026 don't apply to you: no registration, no reporting duty, no self-declaration. Keep a record of how you checked (lessons 1.2 to 1.4); customers will ask.

Why customers ask anyway

Covered entities must deal with supply chain security in their risk management, including their relationships with their direct suppliers and service providers, their vulnerabilities, the quality of their products and their cyber security practices § 32(4)(d) NISG 2026. The NISV 2026 makes the catalogue of requirements in Implementing Regulation (EU) 2024/2690 binding on all covered entities for this § 2 NISV 2026.

The Federal Office counts in all participants of the supply chain around the network and information systems that support the entity's services, down to the air conditioning for the server room; not every supplier is meant, but not only IT providers either (Federal Office, FAQ).

What may end up in your contracts

Where appropriate on its risk assessment, the customer sets out in the contract (Implementing Regulation (EU) 2024/2690, Annex point 5.1.4):

  1. cyber security requirements for you, including for the ICT products and services you supply;
  2. requirements for your staff's awareness, skills, training and where appropriate certification;
  3. background checks on your staff;
  4. your duty to report without undue delay any security incident that poses a risk to it;
  5. a right to audit or to receive audit reports;
  6. your duty to fix vulnerabilities that put it at risk;
  7. rules for subcontractors;
  8. your duties when the contract ends, such as returning and deleting its information.

The customer also keeps a register of its direct suppliers with a contact point and the ICT products and services each supplies (Annex point 5.2), and includes suppliers in its awareness programme where appropriate (Annex point 8.1.2).

What counts as proof

There is no general certificate of compliance with the NISG 2026. Whether a supplier's ISO 27001 certification is enough must be decided case by case on the risk assessment; its scope and validity matter. A general reference to the NISG 2026 in terms and conditions or purchasing conditions doesn't meet the requirements; what is needed are specific contractual duties that can be checked (Federal Office, FAQ).

Reporting voluntarily

Entities outside the act's scope can voluntarily report cyber security incidents, cyber threats and near misses to the national CSIRT § 37(2) NISG 2026, without revealing who they are § 37(3) NISG 2026.

Check yourself anyway

Many suppliers are covered themselves without knowing it: as IT providers with remote maintenance (Annex 1 no. 9), as manufacturers in NACE divisions 26 to 30, or through their group's figures.

Checklist

Quiz

A covered customer's purchasing conditions make a general reference to the NISG 2026. In the Federal Office's view, is that enough for its supply chain security?

  1. Yes, if the supplier signs
  2. No, specific contractual duties that can be checked are needed
  3. It isn't enough only for suppliers from abroad
  4. Yes, the reference is enough
Show the answer

The answer is B: No, specific contractual duties that can be checked are needed. According to the Federal Office (FAQ, supply chain), a general reference in terms or purchasing conditions isn't enough; the requirements aim at specific contractual duties that can be checked.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.