Skip to content
Back to Blog
NIS2 for Suppliers: Why Cybersecurity Is Now Your Problem Too
Legal

NIS2 for Suppliers: Why Cybersecurity Is Now Your Problem Too

NIS2 doesn't just affect large corporations. Through supply chain requirements, it reaches businesses with as few as 20 employees. Here's what SME suppliers should prepare for now.

Christopher Krah19 February 202611 min read

NIS2 for Suppliers: Why Cybersecurity Is Now Your Problem Too

You think NIS2 doesn't apply to you? Your biggest customers disagree.

I hear this all the time. A manufacturing shop with 20 employees in the Eifel region, supplying parts to an automotive OEM, tells me: "That's something for the big players." And technically, they're right. Their company falls below the NIS2 thresholds. But then came the email from the OEM. Subject line: Supply Chain Security Audit Q2 2026.

I've worked at DHL, Delivery Hero, and New Relic. I know the large-enterprise perspective from the inside. And I can tell you this: they will conduct exactly these kinds of audits. The question isn't whether, but when.

In this article, I'll show you what's coming for suppliers, what your large customers will specifically demand, and what you can realistically do as a 20-person operation. No fear-mongering, no "you must overhaul everything immediately." Instead, an honest look at the situation.

What NIS2 Actually Requires

Germany's NIS2 Implementation Act (NIS2UmsuCG) has been in force since December 6, 2025. No transition period. It directly applies to roughly 29,000 companies in sectors like energy, transport, healthcare, food production, and manufacturing. The core requirements are in Section 30 of the BSIG (Germany's Federal Cybersecurity Act) and cover ten categories of measures. Here are the five most relevant for suppliers:

  • Risk management for IT systems and networks
  • Incident reports to the BSI (Germany's Federal Office for Information Security) within 24 hours of detection
  • Security policies and their ongoing documentation
  • Cybersecurity training for executive management (yes, the bosses personally)
  • And here's the key point: securing the supply chain

The penalties are not trivial. Up to 10 million euros in fines or 2% of global annual revenue. And executive management is personally liable. That's new, and it hits hard. When a CEO is personally on the hook for their company's IT security with their own assets, you can imagine how thoroughly they'll scrutinize their supply chain.

The Supply Chain Effect: Why It Reaches You Anyway

This is where it gets relevant for suppliers. Section 30 requires every NIS2-obligated company to assess and document the security of its direct supply chain. That means: your large customer must prove that you have secure IT processes.

The NIS2 cascade effect in the supply chain

The principle works like this: the OEM needs compliance. Compliance demands secure suppliers. So the requirements land on your desk, whether you fall directly under NIS2 or not.

I saw this firsthand at DHL. Supplier audits were routine there. Anyone who didn't meet the requirements was dropped from the procurement process. Period. No discussion. And that's exactly how NIS2 will play out, only now it's formalized and backed by law.

The European Commission designed it this way on purpose. The idea: even if you can't directly regulate every SME, market pressure through the supply chain ensures that security standards trickle down. Your large customer won't ask politely. They'll make it a condition for doing business.

In the automotive industry, TISAX adds another layer. If you're already a supplier there, you know information security audits. But NIS2 goes beyond TISAX. The two standards overlap, but NIS2 demands additional things like the 24-hour reporting obligation, formal incident management, and explicit executive responsibility. Having TISAX gives you a head start, but it doesn't cover everything.

The effect also extends beyond automotive. Energy providers, hospitals, logistics companies, food manufacturers: they all fall under NIS2. And they all have suppliers. You might be one of them.

What Your Large Customers Will Demand

Let's get specific. What's heading your way? I've looked at the requirements currently showing up in supplier audits within the NIS2 context. The pattern repeats:

Documentation you'll need to present:

  • An IT security policy (not a 200-page document, but more than "we have a password")
  • Proof of regular backups and recovery tests
  • Records of your recent security incidents and how you responded
  • Contractual agreements with your own IT service providers

Technical checkpoints that will come up:

  • Encryption of sensitive data, both in transit and at rest
  • Multi-factor authentication for remote access and VPN connections
  • Regular software updates and patch management
  • Network segmentation between office IT and production OT
  • Monitoring: are accesses to critical systems being logged?

Organizational questions that will arise:

  • Who is responsible for IT security at your company?
  • Do you have an emergency plan for cyberattacks?
  • Are your employees trained?

I know that sounds like a lot. But let's be honest: most of these are things you should be doing anyway. NIS2 just gives it a name and a deadline.

Minimum Viable Security for a 20-Person Company

Now let's get practical. You don't need ISO 27001 certification to pass the audits. But you need a baseline. I call it "Minimum Viable Security": the minimum level of security your customers will accept.

Step 1: Establish Responsibility

Designate someone responsible for IT security. With 20 employees, this doesn't need to be a full-time role. But someone needs to own it. That can be the managing director or a technically capable employee. What matters is that this person has oversight and serves as the point of contact for your customers during audit inquiries.

Step 2: Take Inventory

List out:

  • What IT systems do you use? (ERP, email, production controls, ...)
  • Where does your data live? (On-premises, cloud, at your IT service provider?)
  • Who has access to what?
  • What contracts do you have with IT service providers?

Step 3: Implement the Quick Wins

These are measures that cost little and deliver a lot:

  • Enable multi-factor authentication for all services (it's included with Microsoft 365, Google Workspace, and similar platforms)
  • Set up automatic backups and test recovery once per quarter to confirm it actually works
  • Automate software updates where possible. For production IT: define maintenance windows
  • Train employees once: recognizing phishing, secure passwords, reporting suspicious emails
  • Reduce admin privileges to the bare minimum. Not every employee needs administrator access

Step 4: Create Documentation

Write down what you're doing. A simple IT security policy roughly follows this structure:

  1. Scope and responsibilities: which systems are covered and who manages them?
  2. Protective measures: what specifically are you doing?
  3. Incident management: what happens during an attack?
  4. Review and improvement: how often do you revisit this?

Ten to fifteen pages are enough. No novel. Your large customers want to see that you've thought it through and work systematically. And yes: the document needs to be alive. Writing it once and filing it away accomplishes nothing. Plan to review and update it at least once a year.

A practical tip: many IT service providers offer templates for IT security policies tailored to small businesses. Ask your provider. You don't need to reinvent the wheel.

Step 5: Build an Emergency Plan

A cyberattack will happen eventually. Ransomware, compromised email accounts, data leaks. The question is: do you know what to do when it happens?

Your emergency plan should answer:

  • Who do you call? (IT service provider, BSI hotline, cyber insurance)
  • How do you isolate affected systems from the network?
  • How do you communicate internally, externally, and to authorities?
  • Where are your offline backups in case the online backups are compromised?

Print out the emergency plan. Seriously. When your IT is encrypted, a digital document on the encrypted server won't help. A laminated sheet next to the router sounds old-fashioned, but it works.

Step 6: Evaluate Cyber Insurance

This is often overlooked. Cyber insurance doesn't replace a security policy, but it's an important building block. The costs of a ransomware incident for a 20-person business quickly reach 50,000 to 200,000 euros: forensics, business interruption, notifying affected customers, and potentially fines.

Many insurers now require proof that you've implemented basic security measures before they'll even issue a policy. Steps 1 through 5 are therefore doubly useful: they prepare you for customer audits and make you insurable.

BSI Registration: What You Need to Know

A brief detour. If you do fall directly under NIS2 (50+ employees and 10 million euros in revenue in certain sectors), you must register with the BSI (Germany's Federal Office for Information Security). The portal has been live since January 2026. The deadline for particularly important entities was March 6, 2026.

But even if you fall below the thresholds: check anyway. The criteria are complex. Sometimes being active in a specific sector is enough, and the thresholds don't apply as expected. Energy, transport, healthcare, manufacturing, chemicals, food, digital infrastructure. The list of affected sectors is long.

For registration you'll need:

  • A company account with the MUK identity service of the federal government
  • Details about your company and the affected services
  • A contact point for the BSI

The registration process itself is straightforward. But you should clarify beforehand whether you're affected. The BSI offers an applicability check on its website.

What You Can Do This Week

I'm a hands-on person. Big plans are nice, but what counts is what you actually implement. Here's my suggestion for this week:

Monday: Check the BSI website to see if your company falls directly under NIS2. The applicability check takes 30 minutes, done.

Tuesday: Call your biggest customer and ask directly: "What IT security requirements do you place on suppliers under NIS2?" You'll be surprised how specific the answer is. Many procurement departments already have the questionnaires prepared.

Wednesday: Do the inventory from Step 2. Pen, paper, one hour. Walk through each department and note which software and access credentials are in use. Don't forget production IT: machine controllers, SCADA systems, IoT sensors.

Thursday: Enable multi-factor authentication for all cloud services. With Microsoft 365, Google Workspace, and most other providers, it's included in the license. No extra cost, just 15 minutes of configuration per user.

Friday: Sit down and write the first page of your IT security policy. Just the first page. The rest will follow. And if it doesn't: that's what consultants and IT service providers are for.

That sounds simple. And it is simple. The hardest part is starting.

Competitive Advantage, Not Just a Checkbox

I'd like to close with a thought I keep coming back to with topics like these. NIS2 compliance as a supplier isn't just risk mitigation. It's a competitive advantage.

Imagine your large customer has to choose between two equivalent suppliers. One has a documented IT security policy, an emergency plan, verifiable MFA, and regular training. The other says: "We handle it somehow." Who will the procurement manager choose?

During my time at Instacart and DHL, I saw how procurement departments operate. They have checklists. And anyone who doesn't meet the checklist doesn't make the list. Regardless of how good the product is. IT security is becoming a qualification criterion, just like quality certificates or delivery capability.

The businesses that tackle this now will be the preferred suppliers in two years. Those that wait will eventually need to scramble to catch up when their most important customer threatens not to renew the contract.

By the way: if you also need to address the EU AI Act, take a look at our article on EU AI Act training requirements. Compliance topics increasingly interconnect, and getting ahead on one front makes the others easier.

At Plexito, we help SMEs in the Eifel and Rhineland regions get their IT systems ready for requirements like these. Not with a 200-page report, but with practical implementation. Learn more on our services page. Or reach out to us directly through our contact form.

Share:
#nis2#compliance#manufacturing#sme

Related Articles

E-Invoice 2027: What German SMBs Need to Prepare Now
Legal
19 February 202612 min read

E-Invoice 2027: What German SMBs Need to Prepare Now

Starting in 2027, Germany requires e-invoicing for businesses with over EUR 800,000 in revenue. Three phases, XRechnung vs. ZUGFeRD, procedural documentation, and concrete steps for your business.

#e-rechnung#gobd#kmu