News
12 min read

Supply Chain Security Under NIS2: Why Your Suppliers Become a Risk

Learn how to secure your supply chain under NIS2, prevent attacks through suppliers, and minimize your personal liability as a managing director.

A stylized digital chain with one link glowing red, symbolizing the risk of a cyberattack through the supply chain.
A stylized digital chain with one link glowing red, symbolizing the risk of a cyberattack through the supply chain.

Why cybercriminals are targeting your supply chain

Large corporations have invested heavily in their IT infrastructure over the past few years. They run their own security operations centers, use state-of-the-art defense systems, and train their staff continuously. As a result, it is getting harder and harder for cybercriminals to break directly into these networks. That is why attackers are shifting their focus to what looks like a weaker link: suppliers and service providers. In the German Mittelstand, especially at companies with fewer than 500 employees, security measures are often less developed. This inevitably puts your supply chain in the crosshairs of professional hacking groups.

The principle of island hopping

The method attackers use here is known as island hopping. Rather than breaking directly into their main target, hackers first compromise the systems of a smaller partner. From there, they exploit existing interfaces, trust relationships, or email connections to move unnoticed into the network of the actual target company. An incident like this can have devastating consequences, as the typical course of a ransomware compromise in the Mittelstand shows. A recent study by industrial insurer QBE underscores how relevant this threat is: a full 64 percent of cyber incidents are directly linked to weaknesses in the supply chain[1].

  • Direct system connections via unsecured VPN tunnels or API interfaces to the main partner
  • Spoofed emails from known suppliers that carry malicious attachments and are treated as trustworthy by employees
  • Poor update processes at service providers, which leave known security holes open for months
  • Missing monitoring of your own IT infrastructure, which lets a breach at a partner go undetected for days

As a managing director or IT lead, you need to be aware that your own security is inseparable from that of your partners. Cybercriminals do not care how large your business is; they use every available path. To counter these threats effectively, you need comprehensive protection. With professional support in cybersecurity, you can systematically identify weaknesses, detect threats early, and strengthen your own position in the supply chain.

NIS2 Article 21: what the directive requires for your supplier security

With the introduction of the NIS2 directive, lawmakers extend the focus well beyond the boundaries of your own company. Under Article 21(2)(d) of the directive, which is anchored in German law in the BSIG, supply chain security is one of the legally mandated risk management measures[2]. As a managing director or IT lead, you are legally obliged to actively manage the cybersecurity risks in your relationships with your direct partners. That means cybersecurity no longer stops at your own firewall but extends across your entire operational value chain.

The law makes a pragmatic distinction here between direct suppliers and service providers[2]. So you do not have to secure the entire supply chain all the way down to the raw material suppliers, but can concentrate on your direct tier-1 partners. These include, for example, software developers, cloud hosters, or external IT service providers that have access to your systems. If such a service provider is compromised, it creates a direct entry point into your own company network, which is why lawmakers impose strict vetting and monitoring obligations here.

The legal minimum requirements for suppliers

To put these requirements into practice and avoid personal liability for management, you need to establish systematic processes. The BSI recommends a structured management approach for cyber supply chain risks. Every affected company must be able to demonstrate that it assesses its service providers' security measures, binds them contractually, and monitors them on an ongoing basis.

  • Classifying suppliers into risk classes based on their access to sensitive data and IT systems
  • Contractually defining concrete IT security standards such as encryption, patch management, and access controls
  • Establishing joint incident response processes for a fast reaction to a security incident at a service provider
  • Regularly reviewing and auditing security measures through questionnaires or certificate checks

These obligations pose considerable organizational challenges, especially for the Mittelstand. With the CAVRIX Compliance service, you get integrated tools for automated documentation and record-keeping that support you in meeting these requirements. Combined with the real-time security services of Cybersecurity and continuous monitoring of your own systems through the Command Center, you can document supplier security in a verifiable way and minimize risks.

Managing director liability: why unsecured suppliers are your personal risk

Under the new legislation, securing your supply chain is no longer a purely technical or operational matter but a non-transferable duty of management. With the transposition of the European NIS2 directive into German law, responsibility for the security of service providers and suppliers moves directly into the managing director's office. Any negligence in this area leads straight to the question of liability, which we also examined in detail in our article on the personal liability of management.

If a cyberattack succeeds because a supplier was not adequately vetted and secured, lawmakers come down hard. In the case of serious breaches of risk management obligations, affected companies face fines of up to 10 million euros or 2 percent of total worldwide annual revenue for the previous financial year, whichever is higher[3]. As the managing director of a mid-sized company, you cannot simply delegate this responsibility to your IT department or an external service provider.

Personal liability under Section 38 BSIG

Section 38 of the new IT Security Act (BSIG) is particularly explosive here. It explicitly governs the personal liability of management. If, as a managing director, you neglect the monitoring and implementation of the mandated security measures, in a worst-case scenario you are personally and unlimitedly liable with your private assets[4]. A simple discharge by the shareholders' meeting is generally legally ineffective for statutory breaches of duty of this kind.

On top of that, many cyber insurance providers refuse to pay out in the event of a claim if it turns out that basic risk assessments of suppliers were not carried out or documented. That means you risk not only regulatory fines but also the loss of insurance cover for your entire company, which can amount to a threat to your very existence.

Security areaPrevious practice in the MittelstandNew NIS2 requirements
Overall responsibilityDelegated to IT or external service providers without oversightNon-delegable duty of management with an obligation to monitor
Supplier securityReliance on contracts without regular reviewSystematic risk analysis and auditing of all relevant service providers
Liability riskSole liability of the GmbH with company assetsPersonal and unlimited liability of management with private assets

To minimize these personal liability risks effectively, you need to structure your supplier risk management as quickly as possible. With CAVRIX, you can make this transition without building your own expensive compliance team. Our service gives you integrated modules that let you map the security requirements of the NIS2 directive with ease and prove compliance without gaps. Combined with our Cybersecurity service, your IT is monitored around the clock. Through our Command Center, you always have the status of your compliance-relevant tasks and all active security alerts in view.

How to vet your partners: a pragmatic roadmap for the Mittelstand

Under NIS2, the security of your supply chain is no longer a purely IT task but a direct duty of management. The risk is real: around 60 percent of major cyber incidents start with an external partner or supplier[5]. For mid-sized businesses, however, that does not mean you have to vet every service provider with enormous administrative effort. NIS2 does not demand blanket audits for every small partner but explicitly calls for a proportionate and risk-based approach[5]. The goal is a pragmatic vetting process that conserves your resources while protecting you legally.

Risk-based classification: the supplier triage

To keep the effort manageable, you should sort your suppliers into risk classes. This so-called supplier triage is the foundation of your argument before regulators[5]. It documents that you have thought systematically about potential entry points. For internal compliance officers and IT managers in the Mittelstand, this structuring is the most important step in minimizing liability risks effectively. A failure in this area can otherwise quickly lead to personal responsibility, as the strict rules on personal liability under NIS2 make clear. Prioritization follows clear criteria.

  • Critical service providers: partners with direct access to your IT infrastructure, sensitive customer data, or business-critical systems[5].
  • Strategic partners: suppliers whose failure would significantly delay your production or operations but who do not have deep access rights to your systems.
  • Low-risk partners: service providers without IT interfaces and without critical influence on the core business, such as cleaning services or catering providers[5].

Three pragmatic vetting tools for the Mittelstand

For the actual review of your partners, you have three proven instruments at your disposal. First, you should use standardized security questionnaires tailored to the respective risk class. Second, clear cybersecurity clauses belong in every new supplier contract. Third, you should require proof of established security standards such as ISO 27001 or a demonstrated NIS2 alignment[5]. To manage this process cleanly without your own compliance department, the CAVRIX service helps you. Through the intuitive Command Center combined with robust Cybersecurity, you keep the security status of your critical service providers in view at all times and document all measures in a fully audit-compliant way.

Supplier categoryAudit depth and frequencyRequired evidence
Critical (e.g. IT service providers)In-depth annual audit and continuous monitoringISO 27001 certificate, detailed questionnaire, or concrete security evidence
Strategic (e.g. core logistics)Annual review via standardized queriesContractual security clauses, completed self-disclosure questionnaire
Low risk (e.g. office supplies)One-time check at onboarding, no regular audit neededAcceptance of the basic purchasing terms with an IT security clause

Building digital resilience: how to secure your supply chain with CAVRIX

Securing your supply chain does not have to be an unsolvable bureaucratic monster. Although the European NIS2 directive obliges companies to rigorously assess the IT security of their suppliers and service providers, the Mittelstand often lacks the resources for elaborate manual audits. In its latest situation report, the BSI emphasizes how targeted attacks through the supply chain are increasing and bypassing established protective measures. The integrated CAVRIX services support you in implementing these legal requirements pragmatically and strengthening your digital resilience for the long term. With automated processes, you take the load off your IT department while ensuring that your NIS2 compliance is documented without gaps.

Proactive risk management with the Cybersecurity and Compliance modules

To meet the supply chain security requirements efficiently, CAVRIX combines state-of-the-art defense methods with intelligent governance. With the Compliance service, you get access to integrated compliance modules that automatically align your entire IT operations with the strict criteria of NIS2. Instead of manually collecting documents, automated evidence gathering produces audit-proof reports. At the same time, the Cybersecurity service monitors your systems around the clock through a professional security operations center. This proactive protection ensures that potential threats trying to enter your network through weaknesses at your suppliers are detected and isolated immediately.

Risk area at the supplierChallenge for the MittelstandSolution through CAVRIX
Insecure digital interfacesDirect access by external service providers to your company network gives attackers an easy entry point.Continuous endpoint monitoring and real-time threat detection through the integrated Cybersecurity module.
Lack of evidence from partnersManually checking every single supplier's compliance with security standards is time-consuming.Automated audit reports and structured compliance evidence through the Compliance module for quick submission to authorities.
Human factor at the service providerSuppliers' employees can fall for phishing emails and transmit compromised data.Strengthening your own workforce through ongoing security awareness and phishing simulations.

Full transparency in day-to-day work: the Command Center as control hub

Managing your IT security in a busy day-to-day routine calls for a clear, straightforward interface. With the CAVRIX Command Center, you steer your entire security and compliance landscape through an AI-native interface directly inside familiar tools like Microsoft Teams, Slack, or email. You do not have to be an IT specialist to understand the current status of your systems. With simple questions in natural language, you immediately get information about active security tasks, the status of your NIS2 preparations, or open risks in the supply chain. That not only gives you maximum control but also effectively protects you from existential risks and reduces the personal liability of management in the event of compliance breaches.

Frequently asked questions

Who counts as part of the supply chain under NIS2?

NIS2 covers all direct suppliers and service providers that have access to your IT systems or provide critical services. This includes cloud providers and IT service providers, but also external maintenance firms that have physical or digital access to your networks.

What fines do managing directors face for NIS2 breaches?

For breaches of risk management obligations, which include supply chain security, fines of up to 10 million euros or 2 percent of worldwide annual revenue are on the table. On top of that, managing directors can be held personally liable for failures.

How can I vet my suppliers' IT security pragmatically?

You should first classify your suppliers by risk. Service providers with deep system access require detailed security evidence or ISO certifications, while for low-risk suppliers a simple self-disclosure or contractual assurances are enough.

Do my suppliers themselves have to be NIS2-compliant?

Not necessarily all of them. However, if your company falls under the NIS2 directive, you have to ensure that your suppliers meet certain security standards. As a result, many mid-sized suppliers are indirectly forced through contracts to upgrade their IT security.

What role do IT service providers play in NIS2 compliance?

IT service providers and managed service providers (MSPs) are critical links in the chain. They must demonstrate strict security standards, since attacks on them can directly endanger your company. With CAVRIX solutions such as Managed IT and Cybersecurity, you are set up optimally here.

Sources

  1. qbe.de
  2. secjur.com
  3. nis2compass.de
  4. secjur.com
  5. de.isms.online

Where does your company stand?

30 minutes, free, no commitment. We show you where you stand.