NIS2
In shortForces companies to know their IT supply chain. That is exactly step one towards sovereignty.
NIS2 is usually read as a security topic. For the sovereignty question one particular provision matters, and it sits in Article 21.
The provision that counts
In-scope organisations must assess supply chain risks, including the security of their direct suppliers and service providers. In other words, they must know what they depend on — not roughly, but on paper.
That turns a strategic question into a compliance exercise: who are our critical IT suppliers, which law do they answer to, what happens when they fail, and how long does a replacement take?
Who is in scope
The scope is considerably wider than under the previous directive. It covers essential and important entities across 18 sectors, generally from 50 staff or EUR 10 million annual turnover — including energy, transport, health, water, digital infrastructure, ICT service management, post, waste, chemicals, food and manufacturing.
Germany transposed the directive through its NIS2 implementation act. Check the current scope assessment with the BSI before assuming it does not reach you.
The part that gets attention
Management must approve the risk management measures, supervise their implementation, and can be held personally liable. Mandatory training included.
That is why NIS2 moves budgets where ten years of arguing moved nothing.
How to use it well
The supplier overview it requires is the same list a sovereignty review needs. If you have to produce it anyway, add two more columns: the parent company's jurisdiction, and the estimated time to switch. The extra effort is marginal; the insight is not.