Cover Image for NIS2 Supply Chain Security: Why Email Encryption Also Affects Your Suppliers

NIS2 Supply Chain Security: Why Email Encryption Also Affects Your Suppliers

NIS2 requires secure communication in the supply chain. Learn why email encryption also affects suppliers and how the message portal closes the gap.

4 minNIS2 & Compliance

NIS2 Supply Chain Security: Why Email Encryption Also Affects Your Suppliers

The supply chain is cybersecurity's open flank. NIS2 addresses this directly: §30 para. 2 No. 5 BSIG requires supply chain security – including communication. This has far-reaching consequences for email communication with partners, suppliers, and service providers.

§30 No. 5 BSIG: What Does the Law Say?

Security in the supply chain including security-related aspects of the relationships between individual entities and their direct suppliers or service providers.

Specifically, this means:

  • The security of communication channels to partners must be guaranteed
  • Suppliers must be evaluated from a security perspective
  • Email communication in the supply chain must be encrypted and traceable

In a typical supply chain, sensitive data flows via email:

  • Quotes and contracts with confidential terms
  • Technical specifications and engineering drawings
  • Invoices and payment data (target of BEC attacks)
  • Access credentials for systems and portals
  • Personal data (GDPR-relevant)

The problem: Many suppliers – especially SMEs – have no encryption infrastructure of their own. Emails are sent unencrypted and can be intercepted in transit.

Non-NIS2 Companies Are Also Indirectly Affected

A common misconception: "We have fewer than 50 employees, NIS2 doesn't apply to us."

Wrong. NIS2-affected companies are required to assess their supply chain security. This means:

  • Customers may require security evidence for email communication
  • Contracts may contain encryption obligations
  • In the event of an incident at the supplier, the NIS2-affected company is still liable

Bottom line: If your customers fall under NIS2, you as a supplier are de facto co-regulated.

The Core Problem: Encryption Requires Infrastructure on Both Sides

Classic email encryption with S/MIME or PGP only works when both sides have the infrastructure:

  • The sender needs a certificate or key
  • The recipient also needs a certificate or key
  • Keys must be exchanged and kept up to date

In practice, this fails for most supplier relationships. The result: Emails are sent unencrypted despite NIS2 obligations.

The Solution: The Message Portal

Conbool solves exactly this problem with the Secure Message Portal:

How it works:

  1. You send an email to your supplier – encrypted via the gateway
  2. If the recipient has no S/MIME certificate or PGP key, the portal automatically kicks in
  3. The message is stored encrypted on the gateway
  4. The recipient receives a notification with a link to the portal
  5. After secure authentication, they can read the message in their browser
  6. They can reply encrypted directly – without any software of their own

Benefits:

  • No setup required on the recipient's end
  • Encryption works even with partners without their own infrastructure
  • Complete audit trail for compliance evidence
  • Integrable into your corporate identity

Practical Example: Automotive Supplier Faces NIS2 Audit

A mid-sized automotive supplier with 120 employees is audited by their OEM customer. The OEM, as an essential entity, is subject to NIS2 requirements and must demonstrate supply chain security.

What gets audited:

  • How does the supplier communicate sensitive data?
  • Are emails with engineering drawings encrypted?
  • Is there an audit trail for communication?
  • What measures against phishing are implemented?

With Conbool: All points are covered. SecureMail encrypts automatically, MailGuard protects against threats, audit logs provide the evidence. The audit is passed.

Without Conbool: Sensitive emails go out unencrypted, there are no audit logs, phishing protection is limited to the standard spam filter. The audit is not passed – in the worst case, the business relationship is at stake.

Conbool as the Bridge Between NIS2 and the Supply Chain

Conbool solves the supply chain dilemma:

  • Automatic Encryption: S/MIME and PGP where possible, message portal as universal fallback
  • No Effort for Partners: Recipients need no software or certificates of their own
  • Complete Evidence: Audit logs document every encrypted communication
  • Easy Setup: Minutes instead of months, no complex integration

Encrypted supply chain communication doesn't have to be complicated. With the right tool, it works automatically – for both sides.

Try free for 30 days →


Further reading:

Weitere Artikel

Die neuesten Beiträge aus unserem Blog.