NIS2 Audit: How the Vendor List Crumbles in Two Hours
7 Min. Read Time
As of March 6, 2026, the BSI will actively check which companies have missed their NIS2 registration – approximately 18,500 are missing. In the audit cycle that is now underway, most DACH mid-sized companies do not fail at risk analysis or incident response planning, but at a seemingly trivial requirement: a current supply chain list with risk assessment per vendor. Those who can present a complete vendor list plus risk score in under two hours at the first audit session have passed the first hurdle. Those who cannot will face additional requests.
Key Takeaways
- Supply Chain Audit is the biggest challenge. NIS2 requires documented vendor risks in fixed categories. In the initial BSI audits, the majority do not fail at the concept, but at the data foundation: no consolidated list, no risk classification, no audit trail.
- The first audit follows a standard structure. The BSI auditor requests a vendor list, classification as essential or important, last risk review per vendor, and proof that reporting to the management board occurs at least annually in the first 90 minutes.
- Fines risk hits board members personally. Up to 10 million Euros for critical assets, plus personal liability of the management board. This is the lever that will finally bring procurement and IT security to the same table in 2026.
RelatedNIS2 Enforcement Hits 29,500 German Firms / Supervisory Authorities Target SMEs with 72-Hour Reporting Obligation
Why the Vendor List is the Critical Audit Point
In the NIS2 requirement framework, the supply chain does not receive the same level of attention as other areas. However, in the audit report, it takes center stage. The reason is practical: risk concepts and incident response plans are well-developed in most DACH medium-sized enterprises due to efforts from the past few years related to the DSGVO, ISO 27001, and KRITIS regulations. On the other hand, supply chains have rarely been subject to structured risk assessments. NIS2 addresses this gap and makes supply chain risk assessment a mandatory part of the audit process.
The German implementation law largely adopts the European framework but sharpens the expectation for documented supply chain assessments. Specifically, if you have a vendor list in an Excel table with 200 rows without a risk score, you technically have a list, but not a NIS2-compliant supply chain assessment. The BSI auditor will look for the score, not just the table, during the initial audit.
The second reason for this emphasis is the connection to the 24- and 72-hour reporting obligation. If, in the event of a breach, you do not know which vendors are connected to which data and systems, you cannot provide the required quality of report to the BSI. The vendor list is not just an audit artifact; it is the operational foundation of incident response. Both aspects are interconnected and both fail due to the same data issue.
What the BSI Auditor Looks for in the First 90 Minutes
The initial audits since April follow a recognizable pattern. The BSI auditor starts with three requirements before moving on to the actual concept review. First, a list of all suppliers with access to affected systems or data. Second, a classification of these suppliers into at least two categories (essential vs. important service providers). Third, evidence that each classification is based on a current risk assessment and is reviewed at least annually.
At this point, the audit trajectory is decided. Those who can provide the three requirements clearly move on to the substantive discussion. Those who present a list without classification enter a follow-up process with a two to four-week deadline. In the majority of the initial audits conducted so far, the latter has been the standard, not the exception.
The practical preparation tip from the first experience reports: an A4 extract from the vendor management tool showing the top ten vendors classified according to NIS2 with risk scores and the latest review. Those who can provide this before the audit date signal readiness. Those who cannot fall into the standard follow-up cycle.
What Actually Exists in the Typical DACH-Mittelstand
The reality in most houses is more heterogeneous than the NIS2 requirements suggest. Vendor data is spread across three to five parallel systems: a procurement tool for the commercial perspective, an IT service management (ITSM) system for the service level, an identity provider for the access perspective, and an Excel spreadsheet in the data protection team for the DSGVO list. There is no consolidated view, and no NIS2-specific risk score is maintained in any of the sources.
This fragmentation is not an isolated case but the standard state. It cannot be resolved in two weeks. However, a consolidated top 30 list of NIS2-relevant vendors with minimal risk scores based on existing data can be achieved in two to six weeks. This list is not the ultimate vendor management solution, but it serves as the audit evidence needed for the initial audit.
Importantly, the list must be maintained. A list valid as of May 2026 would be outdated by an audit in November, as the BSI requires an annual review process. The organizational challenge is not about “how to create the list,” but “who will maintain it and how often.” In houses that take the topic seriously, the vendor risk review becomes part of the quarterly IT security steering meeting and is assigned a clear owner from procurement.
What Breaks, What Carries: Audit Preparation in 6 Weeks
What Breaks
- Vendor data is spread across three to five systems without a consolidated view.
- NIS2-specific risk scores are missing in all source systems.
- No clear owner for the vendor risk review.
- Procurement and IT security speak different classification languages.
What Carries
- The top 30 vendors cover 80 percent of the NIS2 risk in most houses.
- Procurement has a list with contract volumes, which is the fastest way to prioritize.
- The DSGVO processor list often includes 60 to 70 percent of the relevant vendors.
- A quarterly steering meeting already exists in most houses and can accommodate the review.
The pragmatic conclusion: The initial audit is not a formality but a requirement in a form that most houses underestimate. Whoever creates, documents, and assigns an owner to the top 30 list within six weeks has addressed the largest portion of the NIS2 audit requirements. The rest is concept discussion, which is less problematic in most houses.
What Hurts at the First Occurrence Here
The NIS2 audit is just one side of the coin. The other is the 24-hour report to the BSI, which immediately follows the incident. In this report, the affected company must specify which systems and vendor connections have been compromised. Without a consolidated vendor view, the initial report may need to be revised within the 72-hour confirmation period due to new vendor connections that were not mentioned initially.
This is not a theoretical risk. In the first incidents since the regulation came into force, it was evident that incomplete initial reports are not only considered incomplete but also as a sign of an underdeveloped security organization. The consequence is not necessarily a fine, but a more intensive follow-up audit, which is significantly more resource-intensive than the initial audit.
The vendor list is not only an audit tool but also an incident response tool. In organizations that strategically address this topic, the list is given a permanent place in the crisis management playbook and is tested annually. This exercise takes a day and significantly reduces the risk of an incomplete initial report.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
How is the vendor list specifically structured?
The NIS2-compliant vendor list includes at least four fields per vendor: commercial identity (name, contract volume), technical identity (which systems or data are affected), NIS2 classification (essential or important), and the last review date. More complex lists may include a risk score scale from 1 to 5, escalation contact for the vendor, and the vendor’s last penetration test or ISMS audit evidence. A good initial draft typically has 30 lines, while a mature list may have 100 to 200.
Is the DSGVO processor list sufficient as a basis?
It is a useful basis but not sufficient. The DSGVO list includes vendors processing personal data, which is only part of the NIS2 scope. NIS2 also requires vendors with access to business-critical systems without personal data, such as OT maintenance service providers or network providers. In practice, this means: The DSGVO list typically covers 60 to 70 percent of the NIS2-relevant vendors, the rest must be supplemented from procurement and ITSM processes.
What happens if the BSI auditor finds an incomplete list?
The immediate consequence is a request with a deadline of two to four weeks. If this request is not met, the process escalates to a more detailed audit, where further evidence on security management will be requested. Only if deficiencies are identified in the detailed audit does a fine become a threat. An incomplete list alone is not the trigger for a fine, but it is the entry point to an escalation path that can become costly.
What role do external auditors play in the preparation?
External auditors are valuable in the preparation phase but are not always necessary. For particularly critical assets (bwE), an external audit report is mandatory within three years at the latest. For important assets (wE), self-assessment is permitted. Companies classified as wE in the DACH region can challenge the initial audit with internal preparation and seek targeted external advice for vendor classification methodology.
How often should the vendor list be updated?
At least annually, but in practice, whenever there is a significant contract change or new system integration. Most organizations establish a quarterly review period to add new vendors and remove expired contracts. This frequency is sufficient for audit purposes and aligns with standard IT security steering cycles, so no additional meetings are required.
Source Title Image: Pexels / zeynep (px:36488985)
Editor’s Reading Tips
- NIS2 Enforcement affects 29,500 German companies
- Supervisory authorities target SMEs with 72-hour reporting requirement
- Healthcare Data Leak: 96 hours to report
Editor’s Picks
Editor’s PickNIS2 Enforcement 2026: BSI Audit Phase & DACH ChecklistEditor’s PickGDPR Fines 2026: Why Regulators Are Now Targeting SMEsEditor’s Pick500,000 Patient Data in 96 Hours: DACH Hospital Anonymous Report
More from the MBF Media Network
cloudmagazinWhen Staff Feed Customer Data to ChatGPTMyBusinessFutureSAP BPC: The SQL Backdoor in Quarterly EarningsDigital ChiefsThe 40% Question: Where the AI Budget Really Comes From





