Skip to content
SOVEREIGNTYBALANE
Blog
26 July 2026 · 4 min read

NIS2 may not apply to you. It applies to your biggest customer.

Germany's implementation act has covered around 29,500 entities since December 2025. It reaches everyone else through the supply chain — as a questionnaire, a contract clause, a condition for the next order.


Germany's act implementing the NIS 2 Directive entered into force on 6 December 2025. The legislator estimates around 29,500 entities fall under it, and there is no general transition period. Other member states implemented the same directive on their own timelines, so the dates differ — the mechanism below does not.

For most small and mid-sized companies the first question is thereby answered: you are not covered. The second question matters more, and it is rarely asked: is one of your customers covered?

The pass-through

Regulated entities must account for risk in their supply chain. They cannot delegate that obligation to a service provider, so they pass it on — not as law, since they have no authority to make law, but through the one lever they do have: the contract.

That is why NIS2 currently reaches a great many businesses that do not appear in the statute at all. The trades business working for an energy utility. The agency whose largest client is a hospital. The supplier whose customer falls in scope. The software firm maintaining a water authority's line-of-business application.

The sequence is always the same: a questionnaire arrives with a two-week deadline, and whoever cannot answer it comes off worse at the next award than the competitor who can.

What is actually asked

The contents of these questionnaires are refreshingly unspectacular. Five points come up nearly every time:

Who is responsible for information security at your company — by name, with a deputy?

How do you report a security incident: to whom, within what deadline, through which channel? Regulated entities themselves face short statutory reporting deadlines, which they can only meet if their suppliers react quickly.

What access do your service providers have to our systems, and how is it revoked?

Is there a backup, and when was it last restored — not verified, restored?

What happens at your company when an employee leaves?

QuestionWho answers internallyWhat counts as evidence
Responsibility for information securitymanagementname, deputy, date
Reporting path and deadline for incidentsIT or service providerone page of process with phone numbers
Service provider accessITlist of remote access paths and how they are revoked
Backup and last restoreITdate of the last restore
Employee departuresHRchecklist of accounts and devices

These are questions you can answer in a day if you have thought about them beforehand, and cannot answer in two weeks if nobody is responsible.

Two pages, written once

The practical advice is therefore organisational rather than legal: write down the answers to those five questions before anyone asks. Two pages are enough. Put a date on it, name the people responsible, review it once a year.

From then on those two pages are your answer to every questionnaire that arrives. They also help in tenders, in insurance applications, and with the question of whether anybody actually knows where the backup lives.

If you want to check whether the act does cover you after all, the BSI publishes an applicability check. It is guidance and not legally binding, but it answers the question in fifteen minutes rather than through a legal mandate. Regulated entities must also register; the BSI's portal for that has been open since mid-2026.

Why this belongs to sovereignty

At first glance NIS2 is a security topic, not a location topic. At second glance the two meet in three places.

First, the questionnaires ask about sub-processors. A company that does not know its own chain cannot state it — and one that does know it sees for the first time how many third parties sit on its data. That information otherwise appears only in the annex to the Data processing agreement, which nobody reads.

Second, a reporting deadline measured in hours is only achievable if you can reach somebody. A vendor with no contact in your time zone is not an inconvenience at that point, it is a risk.

Third, the burden of proof shifts. Sovereignty used to be an argument in procurement. Through the supply chain it becomes a requirement that gets ticked off — and a small supplier who can produce two pages beats a larger one who needs three weeks.

What you do not need is a certification. It is expensive, disproportionate for most small companies, and it does not answer the five questions better than two well-written pages. When Certifications pay off is a separate calculation, and it rarely favours the certificate as long as nobody explicitly demands one.

Sources

Read next