NISG 2026 course All courses

Lesson 4.4 · 6 min

Supply chain and procurement

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

Supply chain security

Point (d) requires supply chain security, including the relationships with direct suppliers and service providers, their vulnerabilities, the quality of their products and their cyber security practices § 32(4)(d) NISG 2026. Under the EU catalogue § 2 NISV 2026 (Implementing Regulation (EU) 2024/2690, Annex point 5):

According to the Federal Office this means everyone in the supply chain around the network and information systems that support your services, down to the air conditioning in the server room. Whether a service provider's ISO 27001 certification is enough must be decided case by case on the risk assessment (Federal Office, FAQ on supply chain).

Acquisition, development and maintenance

Point (e) requires security in acquiring, developing and maintaining systems, including vulnerability handling and disclosure § 32(4)(e) NISG 2026. The catalogue lists (Annex point 6):

TopicIn shortAnnex point
Procurementsecurity requirements; updates for the whole lifetime or replacement when support ends; information on hardware and software components and secure configuration; checking the requirements are met6.1
Own developmentsecurity rules for every phase, security testing, protected test data; outsourced development too6.2
Configuration and changesset and enforce secure configurations; document, test and assess changes, justify emergency changes afterwards6.3, 6.4
Security testingscope and frequency from the risk assessment, documented method and results6.5
Patcheswithin a reasonable time, tested first, from trusted sources; not patching only documented and justified6.6
Network securitynetwork architecture documented; remote access controlled; service provider connections only on request and time-limited; unneeded services switched off; a plan for modern email security standards6.7
Segmentationnetworks in zones by risk; critical systems in secured zones; management, production and testing separated6.8
Malwareprotection against malware and unauthorised software, with detection and response software where appropriate6.9
Vulnerabilitiesfollow warnings from CSIRTs, authorities and vendors; scan where appropriate; fix critical vulnerabilities without delay; a disclosure procedure in line with national policy6.10

For businesses with machines and plant, this also means: controllers and networked devices belong in the inventory, in the segmentation and in the maintenance contracts with their manufacturers.

Checklist

Quiz

Your IT provider maintains your servers by remote access. What does the EU catalogue say about such connections?

  1. Connections only after a request for approval and for a set period
  2. Permanently open access is simplest and allowed
  3. Remote maintenance is forbidden
  4. That's entirely up to the provider
Show the answer

The answer is A: Connections only after a request for approval and for a set period. Implementing Regulation (EU) 2024/2690, Annex point 6.7.2(h), through § 2 NISV 2026: connections from service providers only after a request for authorisation and for a set period, such as the duration of maintenance work.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.