Skip to content

Supply Chain Security

LEGAL BASIS

§30(2) No. 4 BSIG – Supply chain security including security-related aspects of the relationships with direct suppliers or service providers

Vendor Overview

All external service providers and vendors are categorized:

CategoryExamplesRisk Assessment
InfrastructureHosting, server operationsHigh – availability
Cloud servicesObject storage, DNSHigh – confidentiality
Software suppliersThird-party libraries, SaaSMedium – supply chain risk
Support partnersMaintenance, consultingLow – limited access

Assessment Criteria

Before engagement and during the annual review, service providers are assessed against the following criteria:

CriterionDescription
Security certificationsISO 27001, SOC 2, BSI C5 or equivalent
Location / jurisdictionEU jurisdiction preferred, third-country transfers only with guarantees
Incident response capabilityDocumented process, reporting timelines compatible with §32 BSIG
Contract designSecurity requirements, audit rights, termination clauses
SubcontractorsTransparency regarding further subcontractors

Contractual Security Requirements

Contracts with service providers include:

  • Minimum information security requirements
  • Obligation to immediately report security incidents
  • Audit and inspection rights
  • Data retention and deletion provisions
  • Exit strategy and data return

Review Cycle

ActivityInterval
Re-assessment of critical providersAnnually
Contract reviewOn renewal / change
Event-driven reviewOn security incident or material change

Perspective as a Supplier

BAUER GROUP is on both sides of the supply chain: it sets requirements for its own service providers and is at the same time a supplier to regulated customers. These customers pass their requirements under §30(2) No. 4 BSIG on to BAUER GROUP by contract – for example as a security annex to the contract, a supplier questionnaire or an obligation to report security incidents. Applicability & Size Classes describes the possible scenarios and explains why a supply relationship alone does not give rise to a NIS2 obligation of its own. BAUER GROUP's own classification is set out under BAUER GROUP Classification.

Dependency Management

For software dependencies:

  • Automated dependency monitoring (Dependabot)
  • Assessment of vulnerabilities in third-party libraries
  • Preference for actively maintained projects with a transparent security process

CRA Synergy

Software supply chain management (SBOM, signing, dependency policy) is described in the CRA Supply Chain Documentation. NIS2 supplements this with IT service provider and infrastructure vendor assessment.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT