Key points at a glance

  • NIS2 turns the software supply chain into a compliance issue. Article 21 of the EU NIS2 Directive (EU) 2022/2555 requires organizations to assess and document the security posture of service providers and suppliers.
  • Trust is no longer enough. Decision-makers need evidence they can use in compliance documentation. Self-declarations and verbal assurances are not sufficient.
  • Conceptboard is registered with the German Federal Office for Information Security (BSI) as a provider of digital collaboration solutions under NIS2. External certifications make security auditable: ISO 27001, ISO 27017 and ISO 27018 are independently audited.
  • Data stays in Germany. Cloud hosting is provided by IONOS in Frankfurt, STACKIT in Baden-Württemberg and AWS in Frankfurt. All three are ISO 27001 certified and hold the BSI C5 attestation for the underlying infrastructure. There are no third-country data transfers. On-premises deployments run on the customer’s own infrastructure.
  • This article is part of our NIS-2 and digital sovereignty series:
    • IS-2 and third-party providers: why software is part of your compliance
    • NIS-2 and verifiability: what you can demand from your software providers
    • Digital sovereignty: where it is really decided

The gap that often becomes visible late

Many software providers now communicate security prominently: encryption, access controls, certifications and security pages. Under NIS2, a further question matters: are these statements strong enough to support a compliance file?

The difference lies in the structure behind the claims:

  • Is there a standardised process for security questionnaires?
  • Can supplier security agreements be signed?
  • Are there named contacts and repeatable responses that will still be consistent months later?

For decision-makers, this matters because the software provider becomes part of their own compliance documentation. In that context, a polished security statement is not enough. The evidence behind it is what counts.

What you need when questions arise

If NIS2 turns supply chain risk into a documentation requirement, the practical implication is straightforward: you need verifiable building blocks that can be incorporated into your own compliance documentation.

These typically include:

  • external certifications and independent audits,
  • clearly defined responsibilities for security enquiries,
  • a documented process for security questionnaires, supplier assessments, and audits.

For decision-makers, this is relevant because a software provider effectively becomes an extension of the organisation’s own risk management. The stronger and more transparent the provider’s evidence, the easier it is to justify internal decisions.

The evidence Conceptboard can provide

To make this more concrete, it helps to look at the evidence Conceptboard can provide in this context.

Registration under NIS2

Conceptboard is registered with the BSI as an important entity under NIS2 in accordance with the German NIS2 implementation act (NIS2UmsuCG). This means Conceptboard is itself subject to the relevant requirements of the directive.

Independent certifications

Conceptboard’s ISO certifications are audited by independent bodies:

  • ISO 27001 covers the information security management system, including risk assessment, incident response and security policies.
  • ISO 27017 addresses cloud-specific security controls beyond ISO 27001.
  • ISO 27018 covers the protection of personal data in the cloud and is directly relevant for GDPR compliance.

Hosting in Germany on BSI C5-attested infrastructure

All data in Conceptboard’s cloud offering is hosted on servers in Germany: IONOS in Frankfurt, STACKIT in Baden-Württemberg and AWS in Frankfurt. All three providers are ISO 27001 certified and hold the BSI C5 attestation for the underlying infrastructure. There are no third-country data transfers.

Technical and organizational measures

Technical measures include encryption of data in transit and at rest, role-based access control and single sign-on (SSO). Administrators can enforce multi-factor authentication (MFA) through their own corporate identity provider, such as Azure AD or Okta. Regular vulnerability assessments and an active bug bounty programme complement these measures.

Structured handling of security enquiries

Security questionnaires are answered in a structured way. Supplier security agreements can be signed. Conceptboard is available in cloud hosting, on dedicated servers and for on-premises operation. The organisation chooses the hosting model; the underlying security architecture remains consistent.

What this means for your own compliance documentation

Organisations that use Conceptboard and fall under NIS2 have a provider whose security posture can be demonstrated to supervisory authorities and internal audit functions. Not through self-declaration, but through external certifications, BSI registration and documented processes.

This does not mean that Conceptboard is automatically “more secure” than any other tool. It is a structural difference that matters when decisions must be documented.

Conceptboard fulfils the relevant requirements for a provider of digital collaboration solutions in the NIS2 context. Your organization’s compliance remains your responsibility. But a provider with demonstrable evidence offers a different foundation from one that cannot provide it.

The question worth asking

Review your digital toolset. For every service that has access to workflows, documents or communication, one question matters: what evidence can this provider provide, and where are the gaps?
The answer is more than a technical detail. It can affect documentation, accountability and liability.

What comes next in the series

The next part of this series looks at what you can demand from your software providers: “NIS-2 and verifiability: what you can demand from your software providers

If you would like to review Conceptboard’s security status for your compliance documentation, we answer security questionnaires and are available for supplier audits at: informationsecurity@conceptboard.com.

Make your digital strategy sovereign and compliance-ready

Explore sovereign digital collaboration
 

This article does not constitute legal advice. Whether and to what extent NIS2 applies to your organization must be assessed on a case-by-case basis.