Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Point of law

Supply chain security

Section 30(2) no. 4 BSIG covers the relationships with direct suppliers and service providers and reaches no further into the chain. The requirement is therefore passed on by contract and not by statute. For an entity that is not itself in scope the basis is therefore the contract. A clause imposed as a standard term is subject to content review under section 307 BGB.

The questionnaire comes from the customer, not the authority

A customer sends a security questionnaire and an annex referring to the BSI Act. The contract is up for renewal, the covering letter names a deadline, and whether the recipient is itself in scope does not appear in it.

The duty ends at the direct supplier

How far the requirement reaches into the chain is the first question, and the provision answers it narrowly. Section 30(2) no. 4 BSIG covers the security aspects of the relationships with direct suppliers or service providers. A sub-supplier of that supplier is not covered, and a clause passing the whole catalogue downwards has no basis in the statute.

What has to be taken into account in substance is stated by Art. 21(3) of the NIS 2 Directive and not by section 30(2) no. 4 BSIG. Named there are the specific vulnerabilities of each individual supplier, the overall quality of its products and of its cybersecurity practices, and the security of its development processes. The transposing Act does not repeat that paragraph.

What the criticality of a supplier is measured by

Liste zu erledigender Punkte

  • Access to systems that the service in scope needs
  • The ability to interrupt the service through an outage of its own
  • Access to data whose loss impairs the service
  • Replaceability within a period the service can tolerate
  • The ability to detect, because without it the customer learns of an incident too late

The order follows section 30(1) sentence 2 BSIG, which ties proportionality to exposure to risk and to the consequences. A list ordered by invoice amount orders by a different measure, and the supplier of remote maintenance software sits at the bottom of it.

Two chains, and only one continues by operation of law

Whether the route taken in data protection law transfers to the security route is the assumption behind most flow-down clauses. It does not hold.

The same chain, two reaches

Art. 28 GDPRMerkmalSection 30(2) no. 4 BSIG
As far as the further processorArt. 28(4) sentence 1 GDPR imposes the same data protection obligations on it, and does so by operation of law.ReachAs far as the direct supplierThe provision reaches no further. Anything beyond it arises by contract.
Provided for by statuteUnder Art. 28(4) sentence 2 GDPR the first processor is liable to the controller for compliance by the further one.Liability in the chainAccording to the contractThe BSIG contains no liability rule for the chain.
Subject to authorisationUnder Art. 28(2) GDPR only with authorisation, and with a right to object where the authorisation is general.Change of a supplierFree unless agreed otherwise
Provided for by statuteArt. 28(3)(h) GDPR requires audits, including inspections, to be allowed for and contributed to.Right to auditOnly where agreed

A data centre regularly sits in both chains, a supplier of control software without any link to personal data only in the right-hand one. Anyone asking about both chains in one questionnaire requires information from the second supplier without a legal basis.

Anyone not in scope owes under a contract and not under a statute

What the requirement on a supplier outside the scope follows from decides whether it is negotiable. The BSIG does not bind that supplier, and the customer passes on what it owes the authority itself. The basis is therefore the contract alone.

Three clauses and their yardstick

The flow-down clause covering all sub-suppliers

As a standard term it is measured against section 307(1) BGB, which under section 310(1) sentence 2 BGB applies against a business as well. A duty to pass the whole catalogue downwards without regard to the service is likely to be unreasonable in case of doubt under section 307(2) no. 2 BGB.

The 24-hour notification period

The customer needs it because section 32(1) no. 1 BSIG binds it within 24 hours. It is reasonable so far as the supplier’s own detection allows. Where it does not, the promise is an assurance without a foundation, and the customer gains nothing from it.

The unrestricted right to audit

In the data protection chain it is owed in any event under Art. 28(3)(h) GDPR. Beyond that it is a matter for negotiation, and a limitation to a trigger, prior notice and the systems covered by the engagement is customary.

Where a clause is individually negotiated the content review falls away, because section 307 BGB concerns standard terms. Negotiating a clause therefore improves not only its content but changes the yardstick applied to it.

How we support you in the supply chain

For the role of supplier it is worth having a statement of measures that answers several questionnaires with one document. It names the measures, the sub-suppliers with access and the detection and reporting routes, and it is updated once a year. For the entity’s own chain a grading by the criticality above suffices, from the self-declaration to evidence with a right to audit.

Frequently asked questions

We are not in scope. Why is the customer asking anyway?

Because under section 30(2) no. 4 BSIG it has to take into account the security aspects of the relationship with its direct suppliers. It owes that consideration to the authority, and that is why it asks you for the information. Your basis is the contract, and the requirement is therefore negotiable.

Do we have to pass requirements on to our own suppliers?

That does not follow from the BSIG, because the provision reaches as far as the direct supplier. It can follow from the contract, and then the clause has to be examined. In the data protection chain the opposite applies, because Art. 28(4) sentence 1 GDPR requires the same obligations to be imposed on the further processor.

Is a self-declaration enough?

For non-critical services frequently. The yardstick follows from section 30(1) sentence 2 BSIG, which ties proportionality to exposure to risk and to the consequences, and not to the invoice amount. Where a supplier has access to the systems of the service in scope, more is likely to be required.

Is a 24-hour notification period reasonable for us?

That turns on your own ability to detect. The customer needs it because section 32(1) no. 1 BSIG binds it within 24 hours. A clause prescribing a shorter period without regard to the service would, as a standard term, be measured against section 307(2) no. 2 BGB. Where it is individually negotiated, that review falls away.

Does a certification help as an answer?

In the data protection chain expressly, because Art. 28(5) GDPR names an approved certification mechanism as a factor in demonstrating sufficient guarantees. In the security chain the customer decides what it accepts as evidence, because the requirement comes from its contract.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.