NIS-2 and third-party providers: why software is part of your compliance
“Will we meet NIS2?” – this question comes up in many status meetings. The answer is often a checklist: risk management documented, BSI registration completed, incident response processes defined. What appears far less often on that list is the software people use every day: collaboration platforms, project management solutions and digital whiteboards. These tools are part of what NIS2 treats as the supply chain: external providers and services integrated into an organization’s digital infrastructure. NIS2 extends that far.

Key points at a glance
- NIS2 turns the software supply chain into a compliance issue. Article 21 of the EU NIS2 Directive (EU) 2022/2555 requires organizations to assess and document the security posture of service providers and suppliers.
- Trust is no longer enough. Decision-makers need evidence they can use in compliance documentation. Self-declarations and verbal assurances are not sufficient.
- Conceptboard is registered with the German Federal Office for Information Security (BSI) as a provider of digital collaboration solutions under NIS2. External certifications make security auditable: ISO 27001, ISO 27017 and ISO 27018 are independently audited.
- Data stays in Germany. Cloud hosting is provided by IONOS in Frankfurt, STACKIT in Baden-Württemberg and AWS in Frankfurt. All three are ISO 27001 certified and hold the BSI C5 attestation for the underlying infrastructure. There are no third-country data transfers. On-premises deployments run on the customer’s own infrastructure.
- This article is part of our NIS-2 and digital sovereignty series:
- IS-2 and third-party providers: why software is part of your compliance
- NIS-2 and verifiability: what you can demand from your software providers
- Digital sovereignty: where it is really decided
The gap that often becomes visible late
Many software providers now communicate security prominently: encryption, access controls, certifications and security pages. Under NIS2, a further question matters: are these statements strong enough to support a compliance file?
The difference lies in the structure behind the claims:
- Is there a standardised process for security questionnaires?
- Can supplier security agreements be signed?
- Are there named contacts and repeatable responses that will still be consistent months later?
For decision-makers, this matters because the software provider becomes part of their own compliance documentation. In that context, a polished security statement is not enough. The evidence behind it is what counts.
What you need when questions arise
If NIS2 turns supply chain risk into a documentation requirement, the practical implication is straightforward: you need verifiable building blocks that can be incorporated into your own compliance documentation.
These typically include:
- external certifications and independent audits,
- clearly defined responsibilities for security enquiries,
- a documented process for security questionnaires, supplier assessments, and audits.
For decision-makers, this is relevant because a software provider effectively becomes an extension of the organisation’s own risk management. The stronger and more transparent the provider’s evidence, the easier it is to justify internal decisions.
The evidence Conceptboard can provide
To make this more concrete, it helps to look at the evidence Conceptboard can provide in this context.
Registration under NIS2
Conceptboard is registered with the BSI as an important entity under NIS2 in accordance with the German NIS2 implementation act (NIS2UmsuCG). This means Conceptboard is itself subject to the relevant requirements of the directive.
Independent certifications
Conceptboard’s ISO certifications are audited by independent bodies:
- ISO 27001 covers the information security management system, including risk assessment, incident response and security policies.
- ISO 27017 addresses cloud-specific security controls beyond ISO 27001.
- ISO 27018 covers the protection of personal data in the cloud and is directly relevant for GDPR compliance.
Hosting in Germany on BSI C5-attested infrastructure
All data in Conceptboard’s cloud offering is hosted on servers in Germany: IONOS in Frankfurt, STACKIT in Baden-Württemberg and AWS in Frankfurt. All three providers are ISO 27001 certified and hold the BSI C5 attestation for the underlying infrastructure. There are no third-country data transfers.
Technical and organizational measures
Technical measures include encryption of data in transit and at rest, role-based access control and single sign-on (SSO). Administrators can enforce multi-factor authentication (MFA) through their own corporate identity provider, such as Azure AD or Okta. Regular vulnerability assessments and an active bug bounty programme complement these measures.
Structured handling of security enquiries
Security questionnaires are answered in a structured way. Supplier security agreements can be signed. Conceptboard is available in cloud hosting, on dedicated servers and for on-premises operation. The organisation chooses the hosting model; the underlying security architecture remains consistent.
What this means for your own compliance documentation
Organisations that use Conceptboard and fall under NIS2 have a provider whose security posture can be demonstrated to supervisory authorities and internal audit functions. Not through self-declaration, but through external certifications, BSI registration and documented processes.
This does not mean that Conceptboard is automatically “more secure” than any other tool. It is a structural difference that matters when decisions must be documented.
Conceptboard fulfils the relevant requirements for a provider of digital collaboration solutions in the NIS2 context. Your organization’s compliance remains your responsibility. But a provider with demonstrable evidence offers a different foundation from one that cannot provide it.
The question worth asking
Review your digital toolset. For every service that has access to workflows, documents or communication, one question matters: what evidence can this provider provide, and where are the gaps?
The answer is more than a technical detail. It can affect documentation, accountability and liability.
What comes next in the series
The next part of this series looks at what you can demand from your software providers: “NIS-2 and verifiability: what you can demand from your software providers”
If you would like to review Conceptboard’s security status for your compliance documentation, we answer security questionnaires and are available for supplier audits at: informationsecurity@conceptboard.com.
Make your digital strategy sovereign and compliance-ready
This article does not constitute legal advice. Whether and to what extent NIS2 applies to your organization must be assessed on a case-by-case basis.

