Supply Chain Security Under NIS-2: Why SMEs Are Also Indirectly Affected

Table of Contents

Supply Chain Security Under NIS-2: Why SMEs Are Also Indirectly Affected

The NIS 2 Directive officially applies only to companies above a certain size and in specific sectors. However, supply chain security under NIS 2 has long since affected small and medium-sized enterprises as well, even though they are not formally subject to the requirement. The reason: Companies subject to NIS 2 pass their security requirements on to their suppliers via contractual clauses—thereby creating a trickle-down effect that affects the entire supply chain.


How NIS-2 Relates to Your Supply Chain

The NIS 2 Directive (Network and Information Security Directive 2) requires companies in critical and important sectors to actively manage risks in their supply chains. Article 21 of the directive stipulates that affected companies must assess the security practices of their service providers and suppliers and, if necessary, impose contractual requirements.

In practice, this means that a medium-sized manufacturing company classified as critical infrastructure can no longer simply assume that its IT service providers, software vendors, or logistics partners are sufficiently secure. It must provide proof of this—in writing.

This creates indirect pressure on SMEs that serve as suppliers: Those who wish to continue receiving orders from customers subject to NIS 2 must comply with those customers' security standards.


The Trickle-Down Effect: When Responsibilities Shift

The term “trickle-down” aptly describes what happens in practice: safety obligations trickle down from regulated companies through the entire supply chain.

According to a June 2026 study by PwC, 47 percent of companies are already reporting cyber incidents in their supplier networks. This shows that supply chain security is not a theoretical risk, but a real threat. Attackers deliberately target less securely protected suppliers as a point of entry—a pattern seen in high-profile incidents such as the SolarWinds attack or the Kaseya hack.

Companies subject to NIS 2 are aware of this risk. They are responding with specific measures:

  • Contractual Security Clauses: Requirements for minimum security standards are included in contracts
  • Supplier Audits: Suppliers Must Provide Evidence of Their Security Measures
  • Security Questionnaires: Standardized assessments evaluate partners' security readiness
  • Certification Requirements: ISO 27001 or equivalent certifications are required

Any SME that fails to meet these requirements risks losing business relationships—regardless of whether it is subject to NIS 2 itself.


Which industries are particularly affected?

Not all SMEs are equally affected. The extent of the impact depends on who they supply. The risk is particularly high in the following areas:

  • IT and software providers that deliver systems for critical infrastructure
  • Logistics and transportation service providers that are part of critical supply chains
  • Technology suppliers in the automotive, energy, or healthcare sectors
  • Facility management and building services personnel who have physical access to KRITIS sites
  • Consulting firms and system integrators that have access to sensitive systems

The article on the NIS 2 Directive—"Who Must Take Action and What Companies Need to Know Now" provides a comprehensive overview of which sectors are directly covered by NIS 2.


What SMEs Need to Do Specifically

For SMEs that operate as suppliers, there is a clear course of action. The following measures address the typical requirements that customers subject to NIS 2 will impose:

1. Document and verify the security level

In practice, many small and medium-sized enterprises (SMEs) already maintain a solid level of IT security—but they do not document it. The first step, therefore, is to identify existing measures and present them in a structured way: What access controls are in place? How are passwords and permissions managed? Is there a contingency plan?

2. Review and Prepare Contract Clauses

Customer security requirements are increasingly becoming part of contracts. SMEs should review their existing contracts for relevant clauses and prepare for new requirements. This also includes the question: What is a customer allowed to examine during an audit?

3. Implement Minimum Technical Standards

Typical minimum requirements include:

  • Multi-factor authentication for all critical access points
  • Regular Software Updates and Patch Management
  • Network Segmentation and Access Controls
  • Data Backup According to the 3-2-1 Rule
  • Encryption of Sensitive Data in Transit and at Rest

4. Build Incident Response Capabilities

NIS-2 places particular emphasis on the ability to detect, report, and respond to security incidents. It is also important for suppliers to know: What should I do if an incident occurs? Who should be notified, and how quickly?

5. Understand the risks in your own supply chain

SMEs are often not only suppliers but also purchase products and services from third-party providers. Supply chain attacks demonstrate just how dangerous unmanaged third-party risks can be. Read more in the article on supply chain attacks and third-party risks.


Zero Trust as a Structural Response to Supply Chain Risks

One approach that is equally suitable for SMEs and larger companies is the zero-trust principle. It is based on the premise that no user, device, or system is automatically considered trustworthy—not even within one’s own network.

In terms of supply chain security, this means that every instance of external access by a partner or service provider is verified, restricted, and logged. This reduces the risk that a compromised supplier could be exploited as a point of entry.

The article on zero-trust architecture as a security principle provides a detailed introduction to the concept.


Implementing NIS-2 Requirements Step by Step

SMEs that want to meet their customers' security requirements don't have to change everything at once. A structured approach helps ensure that resources are used effectively:

  1. Assessment: Which IT systems, data, and processes are relevant?
  2. Risk Analysis: Where Are the Biggest Vulnerabilities?
  3. Action Plan: Which measures have the greatest impact?
  4. Implementation and Testing: Implement Measures and Evaluate Their Effectiveness
  5. Documentation: Record everything in a way that is traceable and ready for audit

For a detailed guide on how to implement the NIS 2 requirements step by step, see the article “Implementing NIS 2 Requirements Step by Step.”


What's at stake

The pressure on SMEs to take action is very real. Companies subject to NIS 2 are legally required to secure their supply chains—and will increasingly be assessing which partners meet these requirements. Suppliers who cannot keep up will find themselves on the defensive: contracts will not be renewed, new orders will not be placed, and, in the worst-case scenario, the business relationship will be terminated.

At the same time, this situation presents an opportunity. SMEs that invest in cybersecurity early on position themselves as reliable, forward-thinking partners. This is a competitive advantage that is becoming increasingly evident in the market.


FAQ: Supply Chain Security and NIS 2 for SMEs

Does my small business have to comply with the NIS 2 Directive, even if we are not directly affected by it?

A direct legal obligation applies only to companies that meet the thresholds and fall within the sectors covered by the NIS 2 Directive. However, if you are a supplier or service provider to companies subject to NIS 2, those companies may impose security requirements on you through your contract that are based on the NIS 2 guidelines. In such cases, compliance is not a legal obligation but a contractual one.

What measures are most important for small and medium-sized enterprises (SMEs) to meet customer security requirements?

Priority should be given to multi-factor authentication, standardized patch management, data backup, access controls, and a documented procedure in the event of a security incident. These measures address the most common requirements found in supplier questionnaires and audits.

How long does it take to implement the relevant safety standards?

That depends on the initial situation. Many SMEs already have technical security measures in place but do not document them adequately. In such cases, a structured assessment and documentation can be completed within a few weeks. More extensive technical measures, such as network segmentation or the development of an incident response plan, require more time and should be planned in phases.


This content was generated using AI, but was reviewed and edited by our editorial team before publication.

Share:

Scroll up

Jamil Isayyed

Jamil is an experienced digital process professional, has a rich international background in the information technology and services industry spanning Germany, Greece and Palestine. He holds a Bachelor's degree in Computer Science and a Scrum Master certification from the Scrum Alliance with a focus on Computer Software Engineering. Jamil is passionate about leading and building high-performance teams that deliver exceptional experiences and create valuable opportunities for clients. In addition to his main role, he is the Director of Axsos Academy GmbH. In this role, he leads a dynamic German-Palestinian bootcamp designed to help young people enter the IT market and build a successful career.

Bernd Length

Bernd Länge has been working in the IT industry for over 20 years and advises clients and interested parties on cyber security issues as well as on the development and implementation of information security management and data protection. In this role, he acts as an external data protection and information security officer for clients. It is important to him to take a pragmatic approach and work closely with clients, partners and vendors to ensure that clients' enterprise security is up to date.

Martin Müller

As a technology enthusiast and committed leader, he has been helping companies in the IT sector to shape the future of work for over 20 years. Thanks to his quick thinking and ability to develop effective solutions, he is able to formulate a clear vision of what our future way of working will look like. Step by step, he overcomes challenges and drives us forward into the future. However, he does not accomplish these tasks alone. He has a competent team that he trusts completely and can rely on. Together they overcome every hurdle! Through positive, critical thinking, the second-best solution often leads to incremental success - after all, even an empire wasn't built in a day. This approach makes him unique in his role and he looks forward to working with you on the path to the future.

Rolf Stephan

His enthusiasm for information technology led Rolf to study computer science and graduate from the University of Karlsruhe, now the KIT / Karlsruhe Institute of Technology. Rolf has been working in the IT sector ever since and knows the industry inside out - both nationally and internationally. For more than 25 years, he has focused on international cooperation between experts across all cultures. He also pursued this approach in the first company he founded, AD Solutions AG, which quickly developed into a renowned international IT service provider with several branches in Germany, Switzerland, Austria and the USA. Rolf Stephan has been General Manager since 2010 and CEO of AXON IVY AG, headquartered in Switzerland, since 2021. He has been an investor, shareholder and Chairman of the Supervisory Board of Axsos AG since 2009.

Frank Müller

Frank is a passionate IT expert and visionary entrepreneur. He loves and believes in peace and freedom. For him, these values are more than just words. They are the result of great awareness, responsibility and a solid foundation. His foundation is his faith in Jesus and his unconditional love for people. Frank builds his great visions on this foundation, such as his commitment to peace in the Holy Land. He is not afraid to realize creative and unconventional ideas, such as founding a medium-sized company that spans four countries and cultures and offers its employees a great deal of freedom. Founding a bootcamp academy in the midst of the coronavirus pandemic is certainly one of these ventures. Through these efforts, Frank creates new innovations and added value for his customers and the people who travel with him. With more than 32 years of IT experience and 15 years as an entrepreneur, Frank helps other entrepreneurs focus on their core business and translate their needs into technology opportunities and implementations. His team and he can translate these requirements into a customized IT strategy, processes and technologies. Frank always has a heart for the people he supports and wants to encourage them to break new ground and develop their potential. Frank is open to exchanging ideas with people who see values not as CSR or marketing chatter, but as the basis of their actions. He seeks contact with people who want to change the world for the better. He also welcomes those who are looking for support from him or his team on their journey into the cloud, digitalization or the use of AI.