Europe Outsourcing

NIS2 and Offshore Development: Supply-Chain Due Diligence for EU Buyers

ILMTEC
ILMTEC Team
ILMTEC Engineering
Aug 8, 2026
7 min read
NIS2 and Offshore Development: Supply-Chain Due Diligence for EU Buyers
The short answer

NIS2 makes the in-scope EU company responsible for the security of its suppliers, including offshore development vendors. The directive does not bind your Indian partner directly, so the obligations must be carried into your contract: security assessment before signing, defined controls, incident notification fast enough to meet your own 24-hour early warning duty, and audit rights.

Does NIS2 apply to my offshore development vendor?

NIS2 does not apply directly to a development vendor outside the EU โ€” it applies to you, and it makes your suppliers your problem. The directive (EU 2022/2555) requires in-scope entities to manage cybersecurity risk across their supply chain, which means an Indian, Ukrainian or Balkan development partner is not regulated by Brussels but is squarely inside the risk perimeter you are accountable for. Your regulator will not ask your vendor for evidence. It will ask you.

That distinction shapes everything practical about how European companies buy offshore engineering in 2026. You cannot outsource the obligation, so you have to contract for it. Broadly the same logic that European buyers already learned with GDPR: the controller stays responsible, and the paperwork has to carry the duty down the chain.

Which companies are in scope?

NIS2 widened the old NIS regime considerably. Two tiers exist, and the size threshold generally starts at 50 employees or EUR 10 million turnover, with some sectors captured regardless of size.

Essential entitiesImportant entities
Examples of sectorsEnergy, transport, banking, health, drinking water, digital infrastructure, ICT service management, public administration, spacePostal and courier, waste, chemicals, food, manufacturing of medical devices and machinery, digital providers, research
SupervisionProactive: inspections and audits without causeReactive: supervision after evidence of non-compliance
Maximum administrative finesAt least EUR 10 million or 2% of global annual turnover, whichever is higherAt least EUR 7 million or 1.4% of global annual turnover, whichever is higher
Management accountabilityManagement bodies must approve and oversee risk measures and can be held personally liableSame duty applies

Note the second-order effect that catches most software companies: even if you are not in scope yourself, your enterprise customers are, and their supply-chain duty lands on you as a contractual requirement. Many European B2B software firms first meet NIS2 through a customer questionnaire rather than a regulator, and then have to pass the same questions on to their own development partner.

Transposition into national law ran late across the bloc โ€” several member states, Germany among them, missed the October 2024 deadline and adopted their implementing acts afterwards. The obligations themselves are now the operative reality regardless, and the direction of travel is uniform: assess your suppliers, document it, and be able to prove it.

What does supply-chain security actually require?

Article 21 lists the risk-management measures in-scope entities must take, and supply-chain security is explicit among them: the security of the relationship with direct suppliers and service providers, taking account of each supplier's specific vulnerabilities and the overall quality of their products and security practices. In operational terms, for a development partner, that translates into five things you must be able to evidence.

  • You assessed them before signing โ€” a documented security review, not a logo on a slide.
  • You defined the controls โ€” access, encryption, endpoint management, secure development practice, subcontracting limits.
  • You can detect and be told about incidents โ€” with a notification window tight enough to meet your own reporting clock.
  • You review periodically โ€” annually as a minimum, and after any material change.
  • Your management body signed it off โ€” accountability sits at board level under Article 20.

What should the vendor security assessment cover?

AreaWhat to ask forWhat a weak answer looks like
CertificationCurrent ISO 27001 certificate with scope statement, or SOC 2 Type II report"We follow ISO 27001 principles" with no certificate
Access controlSSO, MFA everywhere, least privilege, quarterly access reviews, documented joiner-mover-leaver processShared accounts, or access granted by ticket with no review
EndpointsCompany-managed laptops, disk encryption, EDR, patch SLA. Explicit position on personal devicesEngineers use their own machines for client code
Secure developmentMandatory code review, dependency and secret scanning in CI, documented vulnerability SLA by severitySecurity testing described as an annual penetration test only
Data handlingNo production personal data in development environments; documented masking or synthetic dataProduction dumps copied to developer laptops for debugging
SubcontractingNamed subcontractors, flow-down of the same obligations, your right to objectGeneral permission to subcontract at the vendor's discretion
Incident responseWritten plan, named contact, tested at least annually, contractual notification within hours"We will inform you promptly"
Business continuityBackup and restore testing evidence, RTO and RPO, resilience of their own delivery sitesBackups exist, restores never tested

Run this once and reuse it across every supplier. The mistake that makes compliance expensive is treating each vendor as a fresh research project rather than a repeatable questionnaire with an owner and a review date.

How do incident-reporting duties reach an offshore team?

NIS2 sets a demanding clock for significant incidents: an early warning to the CSIRT or competent authority within 24 hours of becoming aware, an incident notification with an initial assessment within 72 hours, and a final report within one month. You cannot meet a 24-hour duty if your development partner tells you about a compromised build pipeline the following week.

So the contract must compress their timeline inside yours. In practice that means vendor notification to you within a small number of hours of detection, a named 24/7 contact on both sides, an obligation to preserve logs and evidence rather than quietly remediate, and a duty to cooperate with your investigation and regulatory filings at their cost. Rehearse it once a year with a tabletop exercise that includes the offshore team, in their working hours, so the escalation path is muscle memory rather than a clause nobody has read.

How is this different from GDPR?

GDPR protects personal data; NIS2 protects the continuity and security of services and networks. They overlap heavily in practice but have different triggers, different regulators and different clocks โ€” GDPR gives 72 hours for a personal-data breach notification, NIS2 wants an early warning in 24. Your outsourcing contract needs both sets of terms, and they should be consistent with each other. The processor terms, transfer mechanism and IP position for an Indian partner are covered in our guide to GDPR, IP and contracts when outsourcing software development to India; the NIS2 obligations sit alongside them rather than replacing anything.

Data residency deserves separate thought, particularly if the engagement involves AI systems processing customer data. Where the model runs and where inference data lands is now a procurement question in its own right, which we cover in EU-hosted LLMs and data residency.

What about the UK and Switzerland?

The UK is outside NIS2 and continues under its own network and information systems regime, with reform in progress; UK buyers should treat NIS2 as a strong template and as a likely contractual requirement from EU customers rather than as domestic law. Swiss firms face their own sectoral reporting duties and the revised Federal Act on Data Protection, discussed in our Switzerland outsourcing guide. In every case the practical control set is the same; only the filing obligations differ.

Does NIS2 make offshore development riskier?

No โ€” it makes undocumented offshore development riskier. A mature vendor with ISO 27001 certification, managed endpoints, enforced code review and a tested incident-response plan is frequently a stronger link in the chain than a local subcontractor working from personal laptops with no scanning in CI. Geography is a poor proxy for security posture; evidence is the proxy that matters, and it is the one a regulator will ask you to produce.

The buyers who handle this well fold the security assessment into vendor selection rather than bolting it on afterwards โ€” the sequence set out in our guide to choosing an outsourcing partner in Europe. If you need an engineering partner that arrives with the certification, the access model and the incident process already in place, ILMTEC provides senior dedicated engineering teams to European companies and will complete your security questionnaire before the commercial conversation rather than after it.

This article is general information about a regulatory framework, not legal advice. Confirm your own scope classification and national transposition with qualified counsel.

ILMTEC Service
Hire Vetted Engineers
Senior India-based engineers embedded in your team.

Frequently Asked Questions

Topics
NIS2
Software Outsourcing
Supply Chain Security
Compliance
Offshore Development

Found this useful? Share it

Hire Vetted Engineers

Ready to put this into production?

ILMTEC delivers in 6-week cycles. Book a free consultation or explore the service.

Explore Hire Vetted Engineers
Chat on WhatsApp