Point of law
Supply chain security
Section 30(2) no. 4 BSIG covers the relationships with direct suppliers and service providers and reaches no further into the chain. The requirement is therefore passed on by contract and not by statute. For an entity that is not itself in scope the basis is therefore the contract. A clause imposed as a standard term is subject to content review under section 307 BGB.
The questionnaire comes from the customer, not the authority
A customer sends a security questionnaire and an annex referring to the BSI Act. The contract is up for renewal, the covering letter names a deadline, and whether the recipient is itself in scope does not appear in it.
The duty ends at the direct supplier
How far the requirement reaches into the chain is the first question, and the provision answers it narrowly. Section 30(2) no. 4 BSIG covers the security aspects of the relationships with direct suppliers or service providers. A sub-supplier of that supplier is not covered, and a clause passing the whole catalogue downwards has no basis in the statute.
What has to be taken into account in substance is stated by Art. 21(3) of the NIS 2 Directive and not by section 30(2) no. 4 BSIG. Named there are the specific vulnerabilities of each individual supplier, the overall quality of its products and of its cybersecurity practices, and the security of its development processes. The transposing Act does not repeat that paragraph.
What the criticality of a supplier is measured by
Liste zu erledigender Punkte
- Access to systems that the service in scope needs
- The ability to interrupt the service through an outage of its own
- Access to data whose loss impairs the service
- Replaceability within a period the service can tolerate
- The ability to detect, because without it the customer learns of an incident too late
The order follows section 30(1) sentence 2 BSIG, which ties proportionality to exposure to risk and to the consequences. A list ordered by invoice amount orders by a different measure, and the supplier of remote maintenance software sits at the bottom of it.
Two chains, and only one continues by operation of law
Whether the route taken in data protection law transfers to the security route is the assumption behind most flow-down clauses. It does not hold.
The same chain, two reaches
| Art. 28 GDPR | Merkmal | Section 30(2) no. 4 BSIG |
|---|---|---|
| As far as the further processorArt. 28(4) sentence 1 GDPR imposes the same data protection obligations on it, and does so by operation of law. | Reach | As far as the direct supplierThe provision reaches no further. Anything beyond it arises by contract. |
| Provided for by statuteUnder Art. 28(4) sentence 2 GDPR the first processor is liable to the controller for compliance by the further one. | Liability in the chain | According to the contractThe BSIG contains no liability rule for the chain. |
| Subject to authorisationUnder Art. 28(2) GDPR only with authorisation, and with a right to object where the authorisation is general. | Change of a supplier | Free unless agreed otherwise |
| Provided for by statuteArt. 28(3)(h) GDPR requires audits, including inspections, to be allowed for and contributed to. | Right to audit | Only where agreed |
A data centre regularly sits in both chains, a supplier of control software without any link to personal data only in the right-hand one. Anyone asking about both chains in one questionnaire requires information from the second supplier without a legal basis.
Anyone not in scope owes under a contract and not under a statute
What the requirement on a supplier outside the scope follows from decides whether it is negotiable. The BSIG does not bind that supplier, and the customer passes on what it owes the authority itself. The basis is therefore the contract alone.
Three clauses and their yardstick
The flow-down clause covering all sub-suppliers
As a standard term it is measured against section 307(1) BGB, which under section 310(1) sentence 2 BGB applies against a business as well. A duty to pass the whole catalogue downwards without regard to the service is likely to be unreasonable in case of doubt under section 307(2) no. 2 BGB.
The 24-hour notification period
The customer needs it because section 32(1) no. 1 BSIG binds it within 24 hours. It is reasonable so far as the supplier’s own detection allows. Where it does not, the promise is an assurance without a foundation, and the customer gains nothing from it.
The unrestricted right to audit
In the data protection chain it is owed in any event under Art. 28(3)(h) GDPR. Beyond that it is a matter for negotiation, and a limitation to a trigger, prior notice and the systems covered by the engagement is customary.
Where a clause is individually negotiated the content review falls away, because section 307 BGB concerns standard terms. Negotiating a clause therefore improves not only its content but changes the yardstick applied to it.
How we support you in the supply chain
For the role of supplier it is worth having a statement of measures that answers several questionnaires with one document. It names the measures, the sub-suppliers with access and the detection and reporting routes, and it is updated once a year. For the entity’s own chain a grading by the criticality above suffices, from the self-declaration to evidence with a right to audit.
Frequently asked questions
We are not in scope. Why is the customer asking anyway?
Because under section 30(2) no. 4 BSIG it has to take into account the security aspects of the relationship with its direct suppliers. It owes that consideration to the authority, and that is why it asks you for the information. Your basis is the contract, and the requirement is therefore negotiable.
Do we have to pass requirements on to our own suppliers?
That does not follow from the BSIG, because the provision reaches as far as the direct supplier. It can follow from the contract, and then the clause has to be examined. In the data protection chain the opposite applies, because Art. 28(4) sentence 1 GDPR requires the same obligations to be imposed on the further processor.
Is a self-declaration enough?
For non-critical services frequently. The yardstick follows from section 30(1) sentence 2 BSIG, which ties proportionality to exposure to risk and to the consequences, and not to the invoice amount. Where a supplier has access to the systems of the service in scope, more is likely to be required.
Is a 24-hour notification period reasonable for us?
That turns on your own ability to detect. The customer needs it because section 32(1) no. 1 BSIG binds it within 24 hours. A clause prescribing a shorter period without regard to the service would, as a standard term, be measured against section 307(2) no. 2 BGB. Where it is individually negotiated, that review falls away.
Does a certification help as an answer?
In the data protection chain expressly, because Art. 28(5) GDPR names an approved certification mechanism as a factor in demonstrating sufficient guarantees. In the security chain the customer decides what it accepts as evidence, because the requirement comes from its contract.
More questions from this area
Checking whether NIS2 applies
Under section 33(1) BSIG it is the entity itself that establishes whether it is in scope, and the federal office registers of its own motion only where that duty is not met.
Cyber Resilience Act
Under Art. 3(13) CRA a manufacturer is also anyone who has a product developed and markets it under its own name or trade mark, irrespective of payment.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.