Does NIS2 apply to my offshore development vendor?
NIS2 does not apply directly to a development vendor outside the EU โ it applies to you, and it makes your suppliers your problem. The directive (EU 2022/2555) requires in-scope entities to manage cybersecurity risk across their supply chain, which means an Indian, Ukrainian or Balkan development partner is not regulated by Brussels but is squarely inside the risk perimeter you are accountable for. Your regulator will not ask your vendor for evidence. It will ask you.
That distinction shapes everything practical about how European companies buy offshore engineering in 2026. You cannot outsource the obligation, so you have to contract for it. Broadly the same logic that European buyers already learned with GDPR: the controller stays responsible, and the paperwork has to carry the duty down the chain.
Which companies are in scope?
NIS2 widened the old NIS regime considerably. Two tiers exist, and the size threshold generally starts at 50 employees or EUR 10 million turnover, with some sectors captured regardless of size.
| Essential entities | Important entities | |
|---|---|---|
| Examples of sectors | Energy, transport, banking, health, drinking water, digital infrastructure, ICT service management, public administration, space | Postal and courier, waste, chemicals, food, manufacturing of medical devices and machinery, digital providers, research |
| Supervision | Proactive: inspections and audits without cause | Reactive: supervision after evidence of non-compliance |
| Maximum administrative fines | At least EUR 10 million or 2% of global annual turnover, whichever is higher | At least EUR 7 million or 1.4% of global annual turnover, whichever is higher |
| Management accountability | Management bodies must approve and oversee risk measures and can be held personally liable | Same duty applies |
Note the second-order effect that catches most software companies: even if you are not in scope yourself, your enterprise customers are, and their supply-chain duty lands on you as a contractual requirement. Many European B2B software firms first meet NIS2 through a customer questionnaire rather than a regulator, and then have to pass the same questions on to their own development partner.
Transposition into national law ran late across the bloc โ several member states, Germany among them, missed the October 2024 deadline and adopted their implementing acts afterwards. The obligations themselves are now the operative reality regardless, and the direction of travel is uniform: assess your suppliers, document it, and be able to prove it.
What does supply-chain security actually require?
Article 21 lists the risk-management measures in-scope entities must take, and supply-chain security is explicit among them: the security of the relationship with direct suppliers and service providers, taking account of each supplier's specific vulnerabilities and the overall quality of their products and security practices. In operational terms, for a development partner, that translates into five things you must be able to evidence.
- You assessed them before signing โ a documented security review, not a logo on a slide.
- You defined the controls โ access, encryption, endpoint management, secure development practice, subcontracting limits.
- You can detect and be told about incidents โ with a notification window tight enough to meet your own reporting clock.
- You review periodically โ annually as a minimum, and after any material change.
- Your management body signed it off โ accountability sits at board level under Article 20.
What should the vendor security assessment cover?
| Area | What to ask for | What a weak answer looks like |
|---|---|---|
| Certification | Current ISO 27001 certificate with scope statement, or SOC 2 Type II report | "We follow ISO 27001 principles" with no certificate |
| Access control | SSO, MFA everywhere, least privilege, quarterly access reviews, documented joiner-mover-leaver process | Shared accounts, or access granted by ticket with no review |
| Endpoints | Company-managed laptops, disk encryption, EDR, patch SLA. Explicit position on personal devices | Engineers use their own machines for client code |
| Secure development | Mandatory code review, dependency and secret scanning in CI, documented vulnerability SLA by severity | Security testing described as an annual penetration test only |
| Data handling | No production personal data in development environments; documented masking or synthetic data | Production dumps copied to developer laptops for debugging |
| Subcontracting | Named subcontractors, flow-down of the same obligations, your right to object | General permission to subcontract at the vendor's discretion |
| Incident response | Written plan, named contact, tested at least annually, contractual notification within hours | "We will inform you promptly" |
| Business continuity | Backup and restore testing evidence, RTO and RPO, resilience of their own delivery sites | Backups exist, restores never tested |
Run this once and reuse it across every supplier. The mistake that makes compliance expensive is treating each vendor as a fresh research project rather than a repeatable questionnaire with an owner and a review date.
How do incident-reporting duties reach an offshore team?
NIS2 sets a demanding clock for significant incidents: an early warning to the CSIRT or competent authority within 24 hours of becoming aware, an incident notification with an initial assessment within 72 hours, and a final report within one month. You cannot meet a 24-hour duty if your development partner tells you about a compromised build pipeline the following week.
So the contract must compress their timeline inside yours. In practice that means vendor notification to you within a small number of hours of detection, a named 24/7 contact on both sides, an obligation to preserve logs and evidence rather than quietly remediate, and a duty to cooperate with your investigation and regulatory filings at their cost. Rehearse it once a year with a tabletop exercise that includes the offshore team, in their working hours, so the escalation path is muscle memory rather than a clause nobody has read.
How is this different from GDPR?
GDPR protects personal data; NIS2 protects the continuity and security of services and networks. They overlap heavily in practice but have different triggers, different regulators and different clocks โ GDPR gives 72 hours for a personal-data breach notification, NIS2 wants an early warning in 24. Your outsourcing contract needs both sets of terms, and they should be consistent with each other. The processor terms, transfer mechanism and IP position for an Indian partner are covered in our guide to GDPR, IP and contracts when outsourcing software development to India; the NIS2 obligations sit alongside them rather than replacing anything.
Data residency deserves separate thought, particularly if the engagement involves AI systems processing customer data. Where the model runs and where inference data lands is now a procurement question in its own right, which we cover in EU-hosted LLMs and data residency.
What about the UK and Switzerland?
The UK is outside NIS2 and continues under its own network and information systems regime, with reform in progress; UK buyers should treat NIS2 as a strong template and as a likely contractual requirement from EU customers rather than as domestic law. Swiss firms face their own sectoral reporting duties and the revised Federal Act on Data Protection, discussed in our Switzerland outsourcing guide. In every case the practical control set is the same; only the filing obligations differ.
Does NIS2 make offshore development riskier?
No โ it makes undocumented offshore development riskier. A mature vendor with ISO 27001 certification, managed endpoints, enforced code review and a tested incident-response plan is frequently a stronger link in the chain than a local subcontractor working from personal laptops with no scanning in CI. Geography is a poor proxy for security posture; evidence is the proxy that matters, and it is the one a regulator will ask you to produce.
The buyers who handle this well fold the security assessment into vendor selection rather than bolting it on afterwards โ the sequence set out in our guide to choosing an outsourcing partner in Europe. If you need an engineering partner that arrives with the certification, the access model and the incident process already in place, ILMTEC provides senior dedicated engineering teams to European companies and will complete your security questionnaire before the commercial conversation rather than after it.
This article is general information about a regulatory framework, not legal advice. Confirm your own scope classification and national transposition with qualified counsel.