NIS2 and verifiability: what you can demand from your software providers
Not long ago, the standard question for a software provider was: "Is your tool secure?" The answer was almost always yes. Encryption, access controls and data centers in Europe sounded convincing and were rarely questioned in detail. Under NIS2, the question has changed. It is now: "What can we present to a supervisory authority if we use this tool?

Key points at a glance
The question has changed. The central question today is: what evidence can we provide if we use this tool?
- Liability makes verifiability mandatory. Section 38 of the German NIS2UmsuCG makes decision-makers personally responsible, including for the choice of digital solutions.
- Self-attestation is not enough. External certifications, documented processes and structured responses to security questionnaires are the standard to aim for.
- Conceptboard is set up for this requirement: registered with the BSI, certified to ISO 27001, ISO 27017 and ISO 27018, and equipped to answer security questionnaires.
- Verifiability is not a bonus. For organizations under NIS2, it is a precondition for defensible provider selection.
When trust is no longer sufficient
Trust remains a reasonable basis for business relationships. Under NIS2, however, selecting a collaboration solution also requires documentation. Decisions must be capable of being justified to supervisory bodies if questions arise. Section 38 of the NIS2UmsuCG makes management boards and executives personally responsible for implementing risk management measures. This includes the assessment and monitoring of third-party providers. In practice, this means that the choice of digital work tools must be documented. It is no longer only an operational decision; it is part of the organisation’s risk management.
What verifiability means in practice
Verifiability means that a provider can answer legitimate security and compliance enquiries in a structured, substantive and repeatable way. This does not require full disclosure of all internal details. It does require clear processes, defined responsibilities and evidence that can withstand scrutiny.
Three elements make the difference:
External certifications and independent audits
A security page can provide orientation. For documentation purposes, what matters most is what has been independently tested, such as ISO certifications with regular audits.
Documented processes for security enquiries
A provider that responds to a security enquiry only by suggesting a call does not yet demonstrate a process. A provider that responds in a structured way, completes questionnaires and signs supplier security agreements does. For decision-makers, that difference is material.
A defined contact for audits
When a supervisory authority asks questions, the organisation needs someone on the provider side who can respond. A clearly defined contact for audits and compliance enquiries is therefore part of verifiability.
What this means for selecting providers
For decision-makers under NIS2, verifiability becomes a fixed selection criterion. It concerns not only the technology itself, but also how well a provider can support documentation and audit situations.
Three quick questions help as an initial filter when choosing a collaboration platform:
- Are there external certifications or audit reports that have been independently verified?
- Is there a documented process for security questionnaires and supplier audits?
- Is there a clearly named contact for compliance enquiries?
If these points can be answered, the decision becomes easier to justify and document.
How Conceptboard meets these requirements
The following overview summarizes the evidence Conceptboard provides in this context.
- BSI registration under NIS2: Conceptboard is registered with the BSI as an important entity under NIS2. This means Conceptboard is itself subject to the directive’s relevant requirements.
- ISO 27001, ISO 27017 and ISO 27018 certifications: These certifications are audited by independent bodies and cover information security management, cloud-specific security controls and the protection of personal data.
- Structured processing of security questionnaires: Security questionnaires are answered systematically. Supplier security agreements can be signed.
- Defined contact for audits and security enquiries: A dedicated contact point is available for audits and security-related questions at: informationsecurity@conceptboard.com.
What comes next in the series
The next part of this series looks at how digital sovereignty takes shape in day-to-day operations. Next article: “Digital sovereignty: where it is really decided.”
If you would like to review Conceptboard’s security status for your compliance documentation, we answer security questionnaires and are available for supplier audits at: informationsecurity@conceptboard.com.
Make your digital strategy sovereign and compliance-ready
This article does not constitute legal advice. Whether and to what extent NIS2 applies to your organization must be assessed on a case-by-case basis.

