NIS2 advice has an incentive problem
Whoever determines that you are in scope often sells the audit too. What annexes 1 and 2 of the BSI Act actually list, why the supply chain argument is upside down, and how to check for yourself.
My impression is that NIS2 advice in Germany has an incentive problem. Whoever establishes that a company is in scope regularly sells it the audit as well. I no longer take that for an aberration; it is the business model, and the bill is paid by companies NIS2 does not cover at all.
An example
Last week I came across a provider marketing NIS2 audits to tax advisory firms from 3,590 EUR, complete with a statutory reference and the assertion that such firms are in scope.
Annex 1 of the BSI Act lists managed service providers and managed security service providers under 6.1.10 and 6.1.11. That is the door being relied on, and the door does exist. As I read it, it only opens where the company provides such services on the market itself. A tax practice does not, not even where it runs its own IT properly or connects its clients digitally.
For this profession the matter can be settled: legal advice, tax advice, auditing and notarial services appear in neither annex 1 nor annex 2. Under no number and under no heading.
The supply chain argument is upside down
Where the annexes lead nowhere, the sales conversation turns to the supply chain, and that argument is the wrong way round.
Being part of a regulated company's supply chain does not make you subject to NIS2. It makes you the object of your client's supplier requirements. The duty sits with them; the pressure reaches you through a contract. The difference is substantial: in one case you face a supervisory authority, with registration, reporting duties and personal liability of the management body, in the other a contract you can negotiate. An audit with no supervisory counterpart discharges none of those duties, because there are none.
I see the same pattern with trades businesses, car dealerships and medical practices. Always the same construction: a wide reading of the annexes, a reference to the supply chain, a note about management liability, and a fixed price at the end. What is sold is not security. What is sold is the relief of having the subject behind you.
For completeness, because the other side would otherwise use it against me: there are plenty of cases where the obligation genuinely applies. Manufacturing appears in annex 2, so a machine builder with fifty or more employees is covered. Healthcare providers appear in annex 1. My charge is not that companies are wrongly told they are in scope — it is that scope is asserted rather than derived. Where it applies, two sentences with the number and the threshold will show it. A provider who cannot supply those two sentences has not checked.
The damage exceeds the invoice
A mid-sized company has a security budget, and it is finite. Spent on an audit that discharges no duty, it is missing from backups, from patch levels and from multi-factor authentication — which is where incidents actually begin. The business then has a document in a cupboard and the same attack surface as before, with the added feeling of being taken care of. Compliance theatre is not neutral. It is expensive, and it costs attention that was needed elsewhere.
Assistants amplify the effect
This material is plentiful and optimised for search engines and generative systems alike. It therefore lands reliably in the answers that managing directors now fetch for a first assessment. A provider's legal opinion turns into an apparently neutral statement, with a source and a section number and everything else that creates trust.
Anyone who types "am I in scope for NIS2" into a chat window the way they would ask a friend gets an answer of a friend's quality, only more eloquently phrased. And believes it, because it sounds so certain. Hardly anyone asks the follow-up question: what is this based on, and does it hold in my case.
Checking costs nothing
Open annex 1 and annex 2 of the BSI Act and look for your own activity. Both count: for important entities, section 28(2) refers expressly to the types of entity set out in annexes 1 and 2. Whoever opens only the first is checking half the list — annex 2 covers postal and courier services, waste management, chemicals, food, manufacturing and research, among others.
Then the thresholds, in full:
An essential entity, under section 28(1) no. 4, is one that falls under a type of entity in annex 1 and has at least 250 employees — or an annual turnover above 50 million euro and additionally a balance sheet total above 43 million euro. The balance sheet condition is readily left out; it is in the statute.
An important entity, under section 28(2) no. 3, is one that falls under a type of entity in annexes 1 or 2 and has at least 50 employees, or an annual turnover and a balance sheet total each above 10 million euro.
Operators of critical installations are covered irrespective of these thresholds.
If your business model appears in neither annex, then it does not appear there, and a customer who is in scope themselves does not change that.
What remains are supplier requirements from contracts, and those belong in a negotiation rather than an audit. A TISAX questionnaire, a data processing annex or a security schedule in a framework agreement are concrete requirements with concrete effort attached, and that effort is as a rule considerably smaller than an audit against a law that does not apply to you.
What we take from this ourselves
We are a provider too, and this criticism applies to our own business model just as much. That is why we keep the scope assessment separate from everything that follows it. You get a written assessment from us citing the relevant number in the annexes and the thresholds, and where the result is that you are not in scope, that is the result. We have said that sentence more often than the other one over the past year.
Ask your provider when they last told a prospect they were not in scope. The answer tells you more about the advice than any reference list.
Source: the BSI Act as amended by the German NIS2 implementation act, section 28 and annexes 1 and 2.