Skip to content

NIS2: Network Connectivity as an Overlooked Risk Factor

In a nutshell: Network operators are critical suppliers under NIS2 and must be included in supply chain assessments because they directly influence operational availability.

Since December 2025, NIS2 has applied without transition period — yet many organisations overlook network connectivity as a critical supply chain vulnerability. The measures catalogue addresses this, but practice focuses on endpoints and servers rather than the physical lines to the outside world.

The NIS2 Implementation Act (NIS2UmsuCG) entered into force immediately on 6 December 2025. It obligates approximately 29,500 entities across 18 sectors to implement a binding catalogue of risk management measures in accordance with § 30 BSIG. The BSI acts as supervisory authority; the registration deadline for affected organisations was March 2026.

The measures catalogue under § 30 BSIG covers typical cybersecurity domains: risk analysis, access control, cryptography, incident response. However, two provisions direct focus outward — to operational continuity through backup and crisis management, and to supply chain security. Here a practical gap emerges: cybersecurity programmes concentrate on endpoints, servers, identities and applications, while physical network connectivity is assumed as a given. This taken-for-granted assumption is the blind spot.

According to the wording of § 30 para. 2 no. 4 BSIG, network operators are to be classified as suppliers who have influence on availability. They meet the central criterion: if the line goes down, operations cease. Not the formal category as a supplier, but the functional role is decisive. The legislator underlined this by removing the former threshold of 100,000 customers — the BSI can now oversee smaller, regional providers as well. A robust assessment includes geographic and legal exposure: in which jurisdiction is the operator situated, over which routes and countries does physical traffic flow, and are there dependencies on single handover points without mitigation options?

Concrete scenarios illustrate the risk: the damage to Baltic Sea data cables in November 2024 disrupted two routes nearly simultaneously. The cause remained unclear; suspicion fell on a dragging ship anchor. Over the following twelve months, a series of further cable damages occurred in the Baltic Sea, whereupon NATO launched a monitoring mission in early 2025. Such physical failure scenarios must be explicitly addressed in NIS2 risk assessment — they are part of supply chain security and therefore part of the mandatory measures catalogue.


Source: www.it-daily.net · Published 18 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: