NIS2 & SaaS: Why Supply Chain Becomes Biggest Compliance Gap
Since December 2025, the NIS2 Implementation Act has applied. Around 29,500 companies are affected, but only 38 percent have registered on time. The biggest blind spot: SaaS providers in the supply chain …
The NIS2 Implementation Act has been in force since December 6, 2025. The BSI registration deadline expired on March 6, 2026. Result: Only 11,500 out of approximately 29,500 obligated companies have registered. Even more critical is what most registrants have overlooked: Their SaaS providers are part of the supply chain. And for these, management is personally liable.
The key points at a glance
- 📋 NIS2 Implementation Act in force since December 6, 2025. BSI registration deadline expired on March 6, 2026 (BSI).
- 📊 Only 11,500 out of 29,850 obligated companies registered on time. Registration rate: 38.5 percent (Security Insider).
- ⚖️ Fines up to 10 million euros or 2 percent of global annual turnover for particularly important entities (§ 65 BSIG).
- 👤 Executive management is personally liable. Waiver of liability is legally excluded (§ 38 BSIG).
- 🔗 SaaS providers without NIS2 compliance represent a direct liability risk for their customers.
What NIS2 means for cloud stacks
NIS2 does not only affect traditional KRITIS operators. The new law covers around 29,850 companies in Germany–six times more than under the previous IT Security Act. The threshold is 50 employees or 10 million euros in annual revenue within one of 18 regulated sectors. Energy suppliers, healthcare companies, financial services providers, as well as manufacturers of chemicals, food, and digital services are included.
The blind spot lies in the supply chain. Article 21 of the NIS2 Directive explicitly requires the security of the entire supply chain, including security-relevant aspects of the relationships between individual entities and their immediate suppliers or service providers. In practice, this means that anyone using Salesforce, HubSpot, Slack, or another SaaS tool must be able to demonstrate that the provider has implemented appropriate security measures.
This is a fundamental shift from the previous approach. Until now, securing one’s own infrastructure was sufficient. Now, IT management must document which SaaS services are in use, what data is processed there, and whether the provider meets the requirements of the NIS2 Implementation Act.
Why BSI registration is just the beginning
On January 6, 2026, the BSI opened its registration portal. Companies had three months to register. When the deadline expired on March 6, 2026, only 11,500 companies had registered, according to Security Insider. Two weeks before the deadline, the number was even lower–just 4,856.
The low registration rate of 38.5 percent has several causes. Many companies are unsure whether they fall under the regulation. The 18 sectors and threshold values are complex, and the distinction between important and particularly important entities is not straightforward. Other companies simply didn’t have registration on their radar.
But registration is only the formal starting point. The real challenge begins afterward: implementing technical and organizational measures. And here, NIS2 meets a reality that overwhelms many IT departments: their own SaaS stack.
The SaaS supply chain problem in detail
According to the Zylo SaaS Management Index, a larger mid-sized company uses between 80 and 120 SaaS applications. From CRM and project management to accounting, communication, and HR. Each of these applications potentially processes sensitive data. And each is a link in the supply chain covered by NIS2.
The central question is: Can the SaaS provider prove that appropriate cybersecurity measures have been implemented? In practice, this proof is missing in most cases. Many SaaS providers, especially smaller European and American vendors, lack ISO 27001 or SOC 2 Type II certifications. They refer to their terms and conditions and privacy policies, but this is insufficient for NIS2-compliant supply chain documentation.
The situation becomes particularly critical with SaaS providers based in the USA. Here, NIS2 requirements collide with the US CLOUD Act: US authorities can compel American companies to disclose data–even if it is stored on European servers. For NIS2-regulated companies in regulated industries, this creates an additional compliance risk that must be documented and assessed.
Fines and personal liability: What’s at stake
NIS2 distinguishes between two categories of entities, and fines differ accordingly.
Particularly important entities (energy, transport, health, drinking water, digital infrastructure, space, banking, financial market infrastructures) face fines of up to 10 million euros or 2 percent of global annual turnover–whichever is higher.
Important entities (postal services, waste, chemicals, food, manufacturing, digital service providers, research) face fines of up to 7 million euros or 1.4 percent of annual turnover.
Personal liability of management is regulated in § 38 BSIG. Managing directors and executives must oversee the implementation of risk management measures. According to ing-ism.de, the waiver of claims against management is legally excluded. This means: A CEO cannot be released from liability via a shareholder resolution.
Checklist: Making your SaaS supply chain NIS2-compliant
IT managers who want to bring their SaaS stack into compliance with NIS2 should systematically work through these steps.
1. Create a SaaS inventory. Record all active SaaS services, including shadow IT. Tools like Zylo, Productiv, or manual analysis of SSO logs can help. Important: Also include services procured independently by individual departments.
2. Classify data per service. What data is processed in each SaaS tool? Personal data, trade secrets, financial data? The level of criticality determines the extent of the audit.
3. Request security evidence. ISO 27001, SOC 2 Type II, BSI C5, or comparable certifications. If certifications are missing: Send security questionnaires (e.g., SIG Questionnaire, CAIQ from the Cloud Security Alliance) to the provider.
4. Review and update contract clauses. Check existing contracts for security clauses. NIS2 requires contractual provisions on incident reporting obligations, audit rights, and minimum standards. If the current contract does not cover this: Negotiate an addendum.
5. Define the incident response chain. How will the company learn about a security incident at the SaaS provider? NIS2 requires an initial report to the BSI within 24 hours. If the SaaS provider lacks its own incident reporting structure, the company needs a contractual commitment on notification timelines.
6. Prepare documentation for audits. Store all evidence centrally: Certifications, completed questionnaires, contract clauses, risk assessments. The BSI has announced it will conduct active audits after March 6, 2026. Documentation must be ready for inspection.
Which SaaS categories are particularly critical
Not every SaaS tool carries the same level of relevance. Prioritization should be based on data sensitivity and depth of access.
Highest priority: Identity providers (Azure AD, Okta, Google Workspace), as they control access to all other systems. An incident here impacts the entire IT environment. Email services (Microsoft 365, Google Workspace) also fall into this category, as they are the most common entry point for phishing and social engineering attacks.
High priority: CRM systems (Salesforce, HubSpot) containing customer data and trade secrets. ERP systems (SAP, Oracle), which manage financial data and core operational processes. And HR platforms (Personio, Workday), which process sensitive employee information.
Medium priority: Project management tools (Jira, Asana), communication platforms (Slack, Teams), and document management systems (Confluence, Notion). While these handle business data, they typically do not process highly sensitive personal or financial information.
A common mistake: Organizations often review only the obvious major vendors and overlook specialized tools used within individual departments. A marketing tool with API access to the CRM is just as much part of the supply chain as Salesforce itself.
What happens if companies do not act
The BSI has announced that after the registration deadline on March 6, 2026, it will actively identify non-registered companies. The authority can request affected facilities to register and impose fines for non-compliance.
For particularly important facilities, an additional tool is available: The BSI can conduct on-site inspections and directly verify the implementation of security measures. In case of serious violations, the authority can order measures up to the prohibition of activities by management personnel.
Even without a BSI inspection, pressure to act arises from the supply chain itself. Large companies that take NIS2 seriously will demand security proof from their suppliers and service providers. Those who cannot provide this risk losing business relationships. The compliance pressure flows down the supply chain.
Conclusion
NIS2 is no paper tiger. The law applies, the deadlines are running, and the personal liability of management is real. The biggest gap in the compliance architecture of many companies is not their own infrastructure, but the SaaS stack. Dozens of providers, rarely checked, seldom contractually secured, and each a potential entry point for attackers and a liability risk for management.
The pragmatic approach: create a SaaS inventory, prioritize by data criticality, demand security proof, tighten contracts. Those who approach this systematically will have the supply chain requirement of NIS2 under control in three to six months. Those who wait risk fines, business losses, and personal liability.
Frequently Asked Questions
Do I need to check every SaaS provider for NIS2 compliance?
Not every one with the same intensity. Prioritize by data criticality: Identity Providers and email services first, then CRM and ERP, then downstream tools. A complete inventory of all SaaS services is a prerequisite, however.
Is my SaaS provider’s ISO 27001 sufficient as NIS2 proof?
ISO 27001 is a good starting point, but not sufficient on its own. NIS2 requires additional contractual regulations on reporting obligations, audit rights, and minimum standards. Check whether the scope of the certification covers the service you use.
How quickly must I report a security incident to the BSI?
Particularly important facilities must submit an initial report within 24 hours. Within 72 hours, an assessment follows, and within one month, a final report. This also applies if the incident occurs with a SaaS provider and affects your data.
Is my company liable if a SaaS provider is hacked?
Not automatically for the hack itself, but for lacking supply chain security measures. If you cannot prove that you have checked the provider and agreed on contractual security clauses, this is a violation of risk management obligations.
What is the difference between important and particularly important facilities?
Particularly important facilities belong to sectors such as energy, health, banking, and digital infrastructure. They are subject to stricter supervision (on-site inspections) and higher fines (up to 10 million euros). Important facilities include sectors such as postal services, chemicals, and food with fines up to 7 million euros.
Further Articles
- Sovereignty-Washing – Why EU-Rechenzentrum still doesn’t mean data sovereignty (cloudmagazin)
- TLS Certificates 2026 – Why 200-day validity means the end of manual management (cloudmagazin)
- Cloud-native Identity – OAuth 2.1, Passkeys and the future of authentication (cloudmagazin)
More from the MBF Media Network
SecurityTodayDSGVO 2026: What’s ChangingDigital ChiefsCloud Repatriation 2026Image source: Dan Nelson / Pexels

