NIS2 Supply Chain Security: Why Email Encryption Also Affects Your Suppliers
The supply chain is cybersecurity's open flank. NIS2 addresses this directly: §30 para. 2 No. 5 BSIG requires supply chain security – including communication. This has far-reaching consequences for email communication with partners, suppliers, and service providers.
§30 No. 5 BSIG: What Does the Law Say?
Security in the supply chain including security-related aspects of the relationships between individual entities and their direct suppliers or service providers.
Specifically, this means:
- The security of communication channels to partners must be guaranteed
- Suppliers must be evaluated from a security perspective
- Email communication in the supply chain must be encrypted and traceable
Why Email Is the Weakest Link in the Supply Chain
In a typical supply chain, sensitive data flows via email:
- Quotes and contracts with confidential terms
- Technical specifications and engineering drawings
- Invoices and payment data (target of BEC attacks)
- Access credentials for systems and portals
- Personal data (GDPR-relevant)
The problem: Many suppliers – especially SMEs – have no encryption infrastructure of their own. Emails are sent unencrypted and can be intercepted in transit.
Non-NIS2 Companies Are Also Indirectly Affected
A common misconception: "We have fewer than 50 employees, NIS2 doesn't apply to us."
Wrong. NIS2-affected companies are required to assess their supply chain security. This means:
- Customers may require security evidence for email communication
- Contracts may contain encryption obligations
- In the event of an incident at the supplier, the NIS2-affected company is still liable
Bottom line: If your customers fall under NIS2, you as a supplier are de facto co-regulated.
The Core Problem: Encryption Requires Infrastructure on Both Sides
Classic email encryption with S/MIME or PGP only works when both sides have the infrastructure:
- The sender needs a certificate or key
- The recipient also needs a certificate or key
- Keys must be exchanged and kept up to date
In practice, this fails for most supplier relationships. The result: Emails are sent unencrypted despite NIS2 obligations.
The Solution: The Message Portal
Conbool solves exactly this problem with the Secure Message Portal:
How it works:
- You send an email to your supplier – encrypted via the gateway
- If the recipient has no S/MIME certificate or PGP key, the portal automatically kicks in
- The message is stored encrypted on the gateway
- The recipient receives a notification with a link to the portal
- After secure authentication, they can read the message in their browser
- They can reply encrypted directly – without any software of their own
Benefits:
- No setup required on the recipient's end
- Encryption works even with partners without their own infrastructure
- Complete audit trail for compliance evidence
- Integrable into your corporate identity
Practical Example: Automotive Supplier Faces NIS2 Audit
A mid-sized automotive supplier with 120 employees is audited by their OEM customer. The OEM, as an essential entity, is subject to NIS2 requirements and must demonstrate supply chain security.
What gets audited:
- How does the supplier communicate sensitive data?
- Are emails with engineering drawings encrypted?
- Is there an audit trail for communication?
- What measures against phishing are implemented?
With Conbool: All points are covered. SecureMail encrypts automatically, MailGuard protects against threats, audit logs provide the evidence. The audit is passed.
Without Conbool: Sensitive emails go out unencrypted, there are no audit logs, phishing protection is limited to the standard spam filter. The audit is not passed – in the worst case, the business relationship is at stake.
Conbool as the Bridge Between NIS2 and the Supply Chain
Conbool solves the supply chain dilemma:
- Automatic Encryption: S/MIME and PGP where possible, message portal as universal fallback
- No Effort for Partners: Recipients need no software or certificates of their own
- Complete Evidence: Audit logs document every encrypted communication
- Easy Setup: Minutes instead of months, no complex integration
Encrypted supply chain communication doesn't have to be complicated. With the right tool, it works automatically – for both sides.
Further reading:


