Skip to content

NISG 2026 · Supply chain

Not in scope — and asked anyway

The law covers roughly 4,000 entities. The requirements reach many more companies, because § 32 Abs. 4 lit. d obliges entities in scope to account for the security of their supply chain — and they pass the requirements on.

How the requirement reaches you

  1. Security questionnaires

    Often the first contact: a list of questions about MFA, backup, patch levels, reporting paths and subcontractors, on a short deadline.

  2. Contract clauses

    New or amended clauses on incident notification, audit rights, and passing requirements to your own suppliers.

  3. Evidence

    Certificates, audit reports or self-declarations — increasingly dated and verifiable rather than a screenshot.

  4. And sometimes a tender

    A supplier who cannot answer drops out before price or capability is discussed.

The point many get wrong

Supplying a covered company does not make you covered. And conversely, an activity that sounds harmless in the company name may well fall inside one of the 18 sectors. These are two separate questions, and the check answers the second.

What you can do now

  • Check whether you are in scope after all — size and activity decide it, not the trade in the register.
  • Answer the common questions properly once and maintain the answers, rather than handling each request from scratch.
  • Collect evidence that is dated and attributable.
  • Decide who answers these requests in-house, and within what time.

The difference in practice

Prepared, you answer a supplier enquiry in days rather than weeks. Unprepared, it becomes a project that starts in the middle of a procurement — which is where contracts are lost.

FAQ

Frequently asked questions

The questions we hear most often from security and IT leaders.

Something not covered here? Ask us directly

No. It means your customer is, and is passing on the requirement. Whether you are covered yourself is a separate question that turns on your activity and your size — the free check answers it in about five minutes.

Yes, and that is the usual route. The statutory duty sits with your customer; what reaches you is a contract term. It is enforceable because it is a contract, not because the NISG applies to you.

Multi-factor authentication, backup and restore testing, patch timescales, incident reporting contacts, and whether you pass requirements to your own subcontractors. Answering them well once and maintaining the answers is far less work than handling each request from scratch.

Often it helps and rarely it is sufficient on its own — customers increasingly ask for dated, attributable evidence about the specific service they buy. A certificate scoped to something else answers a different question.

Not sure which of these applies to you?

The free check answers the ordinary case in five minutes. For anything else a conversation is the quicker route.