{"id":14274,"date":"2026-05-08T17:38:52","date_gmt":"2026-05-08T17:38:52","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/05\/09\/nis2-audit-how-the-vendor-list-crumbles-in-two-hours\/"},"modified":"2026-07-09T16:43:33","modified_gmt":"2026-07-09T16:43:33","slug":"nis2-audit-how-the-vendor-list-crumbles-in-two-hours","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/05\/08\/nis2-audit-how-the-vendor-list-crumbles-in-two-hours\/","title":{"rendered":"NIS2 Audit: How the Vendor List Crumbles in Two Hours"},"content":{"rendered":"<p style=\"display:inline-block;color:#69d8ed;font-weight:700;font-size:0.85em;letter-spacing:0.08em;text-transform:uppercase;margin-bottom:18px;\">7 Min. Read Time<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\"><strong>As of March 6, 2026, the BSI will actively check which companies have missed their NIS2 registration &#8211; approximately 18,500 are missing. In the audit cycle that is now underway, most DACH mid-sized companies do not fail at risk analysis or incident response planning, but at a seemingly trivial requirement: a current supply chain list with risk assessment per vendor. Those who can present a complete vendor list plus risk score in under two hours at the first audit session have passed the first hurdle. Those who cannot will face additional requests.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Supply Chain Audit is the biggest challenge.<\/strong> NIS2 requires documented vendor risks in fixed categories. In the initial BSI audits, the majority do not fail at the concept, but at the data foundation: no consolidated list, no risk classification, no audit trail.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">The first audit follows a standard structure.<\/strong> The BSI auditor requests a vendor list, classification as essential or important, last risk review per vendor, and proof that reporting to the management board occurs at least annually in the first 90 minutes.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Fines risk hits board members personally.<\/strong> Up to 10 million Euros for critical assets, plus personal liability of the management board. This is the lever that will finally bring procurement and IT security to the same table in 2026.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#b8c5ce;margin:20px 0 32px 0;border-top:1px solid rgba(230,227,218,0.12);border-bottom:1px solid rgba(230,227,218,0.12);padding:10px 0;\"><span style=\"color:#69d8ed;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was\/\" style=\"color:#333;text-decoration:underline;\">NIS2 Enforcement Hits 29,500 German Firms<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/web.archive.org\/web\/*\/https:\/\/www.securitytoday.de\/2026\/05\/03\/dsgvo-fines-2026-mittelstand-aufsichtsbehoerden-72h-reporting-obligation\/\" style=\"color:#333;text-decoration:underline;\">Supervisory Authorities Target SMEs with 72-Hour Reporting Obligation<\/a><\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Why the Vendor List is the Critical Audit Point<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">In the NIS2 requirement framework, the supply chain does not receive the same level of attention as other areas. However, in the audit report, it takes center stage. The reason is practical: risk concepts and incident response plans are well-developed in most DACH medium-sized enterprises due to efforts from the past few years related to the DSGVO, ISO 27001, and KRITIS regulations. On the other hand, supply chains have rarely been subject to structured risk assessments. NIS2 addresses this gap and makes supply chain risk assessment a mandatory part of the audit process.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The <a href=\"https:\/\/www.openkritis.de\/it-sicherheitsgesetz\/nis2-umsetzung-gesetz-cybersicherheit.html\">German implementation law<\/a> largely adopts the European framework but sharpens the expectation for documented supply chain assessments. Specifically, if you have a vendor list in an Excel table with 200 rows without a risk score, you technically have a list, but not a NIS2-compliant supply chain assessment. The BSI auditor will look for the score, not just the table, during the initial audit.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The second reason for this emphasis is the connection to the 24- and 72-hour reporting obligation. If, in the event of a breach, you do not know which vendors are connected to which data and systems, you cannot provide the required quality of report to the BSI. The vendor list is not just an audit artifact; it is the operational foundation of incident response. Both aspects are interconnected and both fail due to the same data issue.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What the BSI Auditor Looks for in the First 90 Minutes<\/h2>\n<div style=\"background:#003340;color:#fff;text-align:center;padding:40px 24px;margin:32px 0;border-radius:8px;\">\n<div style=\"font-size:3.4em;font-weight:800;color:#69d8ed;letter-spacing:-0.03em;line-height:1;\">18,500<\/div>\n<div style=\"font-size:1em;color:rgba(255,255,255,0.88);margin-top:12px;max-width:520px;margin-left:auto;margin-right:auto;line-height:1.5;\">DACH companies have missed the NIS2 registration deadline of 06.03.2026. Active BSI audits may result in fines of up to 10 million Euros plus personal liability for management.<\/div>\n<div style=\"font-size:0.78em;color:rgba(255,255,255,0.5);margin-top:12px;\">Source: Advisori Analysis, BSI Communication April 2026<\/div>\n<\/div>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The initial audits since April follow a recognizable pattern. The BSI auditor starts with three requirements before moving on to the actual concept review. First, a list of all suppliers with access to affected systems or data. Second, a classification of these suppliers into at least two categories (essential vs. important service providers). Third, evidence that each classification is based on a current risk assessment and is reviewed at least annually.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">At this point, the audit trajectory is decided. Those who can provide the three requirements clearly move on to the substantive discussion. Those who present a list without classification enter a follow-up process with a two to four-week deadline. In the majority of the initial audits conducted so far, the latter has been the standard, not the exception.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The practical preparation tip from the first experience reports: an A4 extract from the vendor management tool showing the top ten vendors classified according to NIS2 with risk scores and the latest review. Those who can provide this before the audit date signal readiness. Those who cannot fall into the standard follow-up cycle.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What Actually Exists in the Typical DACH-Mittelstand<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The reality in most houses is more heterogeneous than the NIS2 requirements suggest. Vendor data is spread across three to five parallel systems: a procurement tool for the commercial perspective, an IT service management (ITSM) system for the service level, an identity provider for the access perspective, and an Excel spreadsheet in the data protection team for the DSGVO list. There is no consolidated view, and no NIS2-specific risk score is maintained in any of the sources.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">This fragmentation is not an isolated case but the standard state. It cannot be resolved in two weeks. However, a consolidated top 30 list of NIS2-relevant vendors with minimal risk scores based on existing data can be achieved in two to six weeks. This list is not the ultimate vendor management solution, but it serves as the audit evidence needed for the initial audit.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Importantly, the list must be maintained. A list valid as of May 2026 would be outdated by an audit in November, as the BSI requires an annual review process. The organizational challenge is not about &#8220;how to create the list,&#8221; but &#8220;who will maintain it and how often.&#8221; In houses that take the topic seriously, the vendor risk review becomes part of the quarterly IT security steering meeting and is assigned a clear owner from procurement.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What Breaks, What Carries: Audit Preparation in 6 Weeks<\/h2>\n<div style=\"display:grid;grid-template-columns:repeat(auto-fit,minmax(280px,1fr));gap:16px;margin:28px 0;\">\n<div style=\"background:#fafafa;padding:18px 20px;border-radius:6px;border:1px solid rgba(192,57,43,0.25);\">\n<p style=\"margin:0 0 10px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#c0392b;\">What Breaks<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">Vendor data is spread across three to five systems without a consolidated view.<\/li>\n<li style=\"margin-bottom:6px;\">NIS2-specific risk scores are missing in all source systems.<\/li>\n<li style=\"margin-bottom:6px;\">No clear owner for the vendor risk review.<\/li>\n<li>Procurement and IT security speak different classification languages.<\/li>\n<\/ul>\n<\/div>\n<div style=\"background:#fafafa;padding:18px 20px;border-radius:6px;border:1px solid rgba(45,122,62,0.25);\">\n<p style=\"margin:0 0 10px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#2d7a3e;\">What Carries<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">The top 30 vendors cover 80 percent of the NIS2 risk in most houses.<\/li>\n<li style=\"margin-bottom:6px;\">Procurement has a list with contract volumes, which is the fastest way to prioritize.<\/li>\n<li style=\"margin-bottom:6px;\">The DSGVO processor list often includes 60 to 70 percent of the relevant vendors.<\/li>\n<li>A quarterly steering meeting already exists in most houses and can accommodate the review.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The pragmatic conclusion: The initial audit is not a formality but a requirement in a form that most houses underestimate. Whoever creates, documents, and assigns an owner to the top 30 list within six weeks has addressed the largest portion of the NIS2 audit requirements. The rest is concept discussion, which is less problematic in most houses.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What Hurts at the First Occurrence Here<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The NIS2 audit is just one side of the coin. The other is the <a href=\"https:\/\/www.advisori.de\/blog\/nis2-bussgeld-haftung-frist-maerz-2026\">24-hour report to the BSI<\/a>, which immediately follows the incident. In this report, the affected company must specify which systems and vendor connections have been compromised. Without a consolidated vendor view, the initial report may need to be revised within the 72-hour confirmation period due to new vendor connections that were not mentioned initially.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">This is not a theoretical risk. In the first incidents since the regulation came into force, it was evident that incomplete initial reports are not only considered incomplete but also as a sign of an underdeveloped security organization. The consequence is not necessarily a fine, but a more intensive follow-up audit, which is significantly more resource-intensive than the initial audit.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The vendor list is not only an audit tool but also an incident response tool. In organizations that strategically address this topic, the list is given a permanent place in the crisis management playbook and is tested annually. This exercise takes a day and significantly reduces the risk of an incomplete initial report.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>How is the vendor list specifically structured?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The NIS2-compliant vendor list includes at least four fields per vendor: commercial identity (name, contract volume), technical identity (which systems or data are affected), NIS2 classification (essential or important), and the last review date. More complex lists may include a risk score scale from 1 to 5, escalation contact for the vendor, and the vendor&#8217;s last penetration test or ISMS audit evidence. A good initial draft typically has 30 lines, while a mature list may have 100 to 200.<\/p>\n<\/details>\n<details>\n<summary><strong>Is the DSGVO processor list sufficient as a basis?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">It is a useful basis but not sufficient. The DSGVO list includes vendors processing personal data, which is only part of the NIS2 scope. NIS2 also requires vendors with access to business-critical systems without personal data, such as OT maintenance service providers or network providers. In practice, this means: The DSGVO list typically covers 60 to 70 percent of the NIS2-relevant vendors, the rest must be supplemented from procurement and ITSM processes.<\/p>\n<\/details>\n<details>\n<summary><strong>What happens if the BSI auditor finds an incomplete list?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The immediate consequence is a request with a deadline of two to four weeks. If this request is not met, the process escalates to a more detailed audit, where further evidence on security management will be requested. Only if deficiencies are identified in the detailed audit does a fine become a threat. An incomplete list alone is not the trigger for a fine, but it is the entry point to an escalation path that can become costly.<\/p>\n<\/details>\n<details>\n<summary><strong>What role do external auditors play in the preparation?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">External auditors are valuable in the preparation phase but are not always necessary. For particularly critical assets (bwE), an external audit report is mandatory within three years at the latest. For important assets (wE), self-assessment is permitted. Companies classified as wE in the DACH region can challenge the initial audit with internal preparation and seek targeted external advice for vendor classification methodology.<\/p>\n<\/details>\n<details>\n<summary><strong>How often should the vendor list be updated?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">At least annually, but in practice, whenever there is a significant contract change or new system integration. Most organizations establish a quarterly review period to add new vendors and remove expired contracts. This frequency is sufficient for audit purposes and aligns with standard IT security steering cycles, so no additional meetings are required.<\/p>\n<\/details>\n<p style=\"text-align:right;color:#868e96;font-size:0.85em;margin-top:48px;\"><em>Source Title Image: Pexels \/ zeynep (px:36488985)<\/em><\/p>\n<div style=\"margin:40px 0;padding:0;border-top:2px solid #004a59;\">\n<p style=\"margin:0;padding:16px 0 8px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#69d8ed;\">Editor&#8217;s Reading Tips<\/p>\n<ul style=\"list-style:none;margin:0;padding:0;\">\n<li style=\"padding:10px 0;border-bottom:1px solid #eee;\"><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was\/\" style=\"color:#1a1a1a;text-decoration:none;\">NIS2 Enforcement affects 29,500 German companies<\/a><\/li>\n<li style=\"padding:10px 0;border-bottom:1px solid #eee;\">Supervisory authorities target SMEs with 72-hour reporting requirement<\/li>\n<li style=\"padding:10px 0;\"><a href=\"https:\/\/web.archive.org\/web\/*\/https:\/\/www.securitytoday.de\/2026\/04\/24\/healthcare-data-leak-500000-patient-records-96-hours-nis2-dsgvo-april-2026\/\" style=\"color:#1a1a1a;text-decoration:none;\">Healthcare Data Leak: 96 hours to report<\/a><\/li>\n<\/ul>\n<\/div>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was-dach-unternehmen-bei-der-eigenen-compliance-jetzt-pruefen-muessen-cover-hero-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">NIS2 Enforcement 2026: BSI Audit Phase &#038; DACH Checklist<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/gdpr-fines-2026-why-regulators-are-now-targeting-smes\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/dsgvo-bussgeld-2026-cover-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">GDPR Fines 2026: Why Regulators Are Now Targeting SMEs<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/24\/500000-patient-data-96-hours-anonymous-incident-report-dach-hospital-group\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/04\/healthcare-incident-report-500000-patientendaten-96-stunden-nis2-dsgvo-april-2026-ai-cover-hero-250x140.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">500,000 Patient Data in 96 Hours: DACH Hospital Anonymous Report<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/06\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-microsoft-intelligent-purview-mai-2026-d-93905415.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">When Staff Feed Customer Data to ChatGPT<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/sap-bpc-the-sql-backdoor-in-quarterly-earnings\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-sap-bpc-bw-cve-2026-27681-sql-injection-5938106-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">SAP BPC: The SQL Backdoor in Quarterly Earnings<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/the-40-question-where-the-ai-budget-really-comes-from\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-ki-infrastruktur-budget-reallokation-202-98081579-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">The 40% Question: Where the AI Budget Really Comes From<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"NIS2 audits have been checking supply\u2011chain evidence concretely since May\u202f2026.","protected":false},"author":10,"featured_media":14737,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"","_yoast_wpseo_title":"NIS2 Audit: How the Vendor List Crumbles in Two Hours","_yoast_wpseo_metadesc":"Since May 2026, NIS2 audits verify supply\u2011chain evidence. See where DACH SMEs can\u2019t compile a vendor list in two hours.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/nis2-audit-lieferketten-vendor-liste-evidenz-2026-cover-hero.png","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/nis2-audit-lieferketten-vendor-liste-evidenz-2026-cover-hero.png","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[259],"tags":[],"class_list":["post-14274","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en"],"evm_reading_time_minutes":10,"wpml_language":"en","wpml_translation_of":14252,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/14274","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=14274"}],"version-history":[{"count":9,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/14274\/revisions"}],"predecessor-version":[{"id":21376,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/14274\/revisions\/21376"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/14737"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=14274"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=14274"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=14274"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}