
NIS2 requires secure communication in the supply chain. Learn why email encryption also affects suppliers and how the message portal closes the gap.
The supply chain is cybersecurity's open flank. NIS2 addresses this directly: §30 para. 2 No. 5 BSIG requires supply chain security – including communication. This has far-reaching consequences for email communication with partners, suppliers, and service providers.
Security in the supply chain including security-related aspects of the relationships between individual entities and their direct suppliers or service providers.
Specifically, this means:
In a typical supply chain, sensitive data flows via email:
The problem: Many suppliers – especially SMEs – have no encryption infrastructure of their own. Emails are sent unencrypted and can be intercepted in transit.
A common misconception: "We have fewer than 50 employees, NIS2 doesn't apply to us."
Wrong. NIS2-affected companies are required to assess their supply chain security. This means:
Bottom line: If your customers fall under NIS2, you as a supplier are de facto co-regulated.
Classic email encryption with S/MIME or PGP only works when both sides have the infrastructure:
In practice, this fails for most supplier relationships. The result: Emails are sent unencrypted despite NIS2 obligations.
The latest posts from our blog.

An Email Security Gateway is the central line of defense for business email communication. This guide explains how it works, what threats it blocks, and why it is essential for NIS2 and GDPR…

Choosing the right Email Security Gateway is critical for business communication security. This comparison shows the most important criteria and typical pitfalls.

Proper configuration of a Secure Email Gateway determines security and user experience. These 10 best practices help IT teams achieve optimal setup.
Conbool solves exactly this problem with the Secure Message Portal:
How it works:
Benefits:
A mid-sized automotive supplier with 120 employees is audited by their OEM customer. The OEM, as an essential entity, is subject to NIS2 requirements and must demonstrate supply chain security.
What gets audited:
With Conbool: All points are covered. SecureMail encrypts automatically, MailGuard protects against threats, audit logs provide the evidence. The audit is passed.
Without Conbool: Sensitive emails go out unencrypted, there are no audit logs, phishing protection is limited to the standard spam filter. The audit is not passed – in the worst case, the business relationship is at stake.
Conbool solves the supply chain dilemma:
Encrypted supply chain communication doesn't have to be complicated. With the right tool, it works automatically – for both sides.
Further reading: