Lesson 4.4 · 6 min
Supply chain and procurement
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- A policy for suppliers and service providers. Selection criteria, security requirements in contracts, monitoring suppliers, and a register of all direct suppliers and the ICT they provide.
- Security from the purchase on. Security requirements, updates for the whole lifetime or replacement when support ends, information on components and secure configuration.
- Patch, but tested. Security patches within a reasonable time, from trusted sources and tested first. Not applying a patch needs a reason.
- Remote access only on request, and for a limited time. Connections from service providers only after approval and for a set period. The network is documented and split into zones.
- Follow warnings, fix critical ones at once. Follow warnings from CSIRTs and vendors, scan where appropriate, fix critical vulnerabilities without delay.
In detail
Supply chain security
Point (d) requires supply chain security, including the relationships with direct suppliers and service providers, their vulnerabilities, the quality of their products and their cyber security practices § 32(4)(d) NISG 2026. Under the EU catalogue § 2 NISV 2026 (Implementing Regulation (EU) 2024/2690, Annex point 5):
- Policy: the entity defines its role in the supply chain and tells its direct suppliers (point 5.1.1);
- Selection: criteria are the suppliers' cyber security practices, their ability to meet your specifications, the quality and resilience of their products, and the chance to limit dependence on single suppliers (point 5.1.2);
- Contracts: where appropriate, security requirements, training, background checks, reporting incidents without delay, audit rights, fixing vulnerabilities, rules for subcontractors and duties when the contract ends (point 5.1.4; in detail in lesson 1.5);
- Monitoring: follow reports on service levels, review incidents at suppliers, analyse risks from changes (points 5.1.6 and 5.1.7);
- A register of all direct suppliers with a contact point and the ICT products, services and processes they provide (point 5.2).
According to the Federal Office this means everyone in the supply chain around the network and information systems that support your services, down to the air conditioning in the server room. Whether a service provider's ISO 27001 certification is enough must be decided case by case on the risk assessment (Federal Office, FAQ on supply chain).
Acquisition, development and maintenance
Point (e) requires security in acquiring, developing and maintaining systems, including vulnerability handling and disclosure § 32(4)(e) NISG 2026. The catalogue lists (Annex point 6):
| Topic | In short | Annex point |
|---|---|---|
| Procurement | security requirements; updates for the whole lifetime or replacement when support ends; information on hardware and software components and secure configuration; checking the requirements are met | 6.1 |
| Own development | security rules for every phase, security testing, protected test data; outsourced development too | 6.2 |
| Configuration and changes | set and enforce secure configurations; document, test and assess changes, justify emergency changes afterwards | 6.3, 6.4 |
| Security testing | scope and frequency from the risk assessment, documented method and results | 6.5 |
| Patches | within a reasonable time, tested first, from trusted sources; not patching only documented and justified | 6.6 |
| Network security | network architecture documented; remote access controlled; service provider connections only on request and time-limited; unneeded services switched off; a plan for modern email security standards | 6.7 |
| Segmentation | networks in zones by risk; critical systems in secured zones; management, production and testing separated | 6.8 |
| Malware | protection against malware and unauthorised software, with detection and response software where appropriate | 6.9 |
| Vulnerabilities | follow warnings from CSIRTs, authorities and vendors; scan where appropriate; fix critical vulnerabilities without delay; a disclosure procedure in line with national policy | 6.10 |
For businesses with machines and plant, this also means: controllers and networked devices belong in the inventory, in the segmentation and in the maintenance contracts with their manufacturers.
Checklist
- We have a register of all direct IT suppliers with a contact point and what they provide.
- Our contracts with key service providers cover incident reporting, audit rights, vulnerabilities and termination.
- When buying, we ask how long security updates will be provided.
- Remote maintenance access is open only on request and for a limited time.
- We follow warnings from the CSIRT and vendors and fix critical issues without delay.
Quiz
Your IT provider maintains your servers by remote access. What does the EU catalogue say about such connections?
- Connections only after a request for approval and for a set period
- Permanently open access is simplest and allowed
- Remote maintenance is forbidden
- That's entirely up to the provider
Show the answer
The answer is A: Connections only after a request for approval and for a set period. Implementing Regulation (EU) 2024/2690, Annex point 6.7.2(h), through § 2 NISV 2026: connections from service providers only after a request for authorisation and for a set period, such as the duration of maintenance work.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 32, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 2, RIS, in German, version of 6 October 2026
- Implementing Regulation (EU) 2024/2690, Art. 2 and Annex, EUR-Lex (also in English)
- Federal Office for Cyber Security, FAQ: supply chain, in German (read on 6 October 2026)
- Federal Office for Cyber Security, FAQ: measures, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.