CodebahnCodebahn

NIS2 is in force. Your Git host is in your supply chain.

Between October 2024 and October 2026, eight EU member states enacted national laws transposing the NIS2 directive. Germany alone brought roughly 29,500 companies into scope. The Netherlands added over 8,000. Most of those companies have not yet asked where their source code is hosted, or under whose jurisdiction.

They will.

What NIS2 requires

NIS2 (Directive (EU) 2022/2555) is the EU’s updated cybersecurity directive. It replaces the original NIS directive from 2016 and expands the scope from critical infrastructure operators to a far broader set of sectors: energy, transport, health, digital infrastructure, ICT service management, public administration, manufacturing, food, chemicals, waste, postal services, and more. The European Commission’s overview covers the full scope. ENISA’s implementation guidance covers the technical measures.

Article 21(2)(d) requires essential and important entities to implement “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers.”

Article 21(3) adds that entities must consider the vulnerabilities specific to each direct supplier and service provider, the overall quality of their cybersecurity practices, and the results of coordinated risk assessments.

This is not a certification checkbox. It is an obligation to know your supply chain.

Why your Git host is in scope

Source code is an asset. The service that stores, processes, and builds it is a supplier. If you are subject to NIS2, your supplier assessment needs to cover your Git hosting provider, the same way it covers your cloud provider or your CI pipeline.

The questions your assessment will ask are straightforward:

Most Git hosting providers are US-incorporated. That is not disqualifying on its own, but it is a fact your assessment needs to address, especially after the third collapse of the EU-US data transfer framework in June 2026. The CLOUD Act is the reason jurisdiction matters here, not just data location.

Where the laws stand

NIS2 is a directive, not a regulation. Each member state transposes it into national law with its own name, timeline, and supervisory authority. The supply chain obligations come from the directive itself and do not vary by country.

CountryNational lawIn force
BelgiumLoi du 26 avril 2024Oct 2024
ItalyD.Lgs. 138/2024Oct 2024
FinlandKyberturvallisuuslakiApr 2025
DenmarkNIS-2-lovenJul 2025
GermanyNIS2UmsuCGDec 2025
SwedenCybersäkerhetslagenJan 2026
NetherlandsCyberbeveiligingswetAug 2026
AustriaNISG 2026Oct 2026

France, Spain, and Ireland have not yet enacted their transpositions; all three were referred to the CJEU in July 2026 for failure to transpose on time. Norway applies NIS1 under the EEA agreement (Digitalsikkerhetsloven); NIS2 incorporation is in progress.

The full table with links to each country’s national authority is on our NIS2 page.

What we did about it

Codebahn is a Swedish company on EU-only infrastructure. Every sub-processor is EU-incorporated. There is no US entity anywhere in the chain.

We publish the answers a supplier assessment needs: sub-processor list, DPA, security addendum, and a dedicated NIS2 page mapping our answers to Article 21. Financial entities under DORA have a separate register page with the specific fields their templates require.

We do not have SOC 2 or ISO 27001. If your assessment requires a signed audit report today, we are not your vendor yet. If what it requires is transparency about jurisdiction, data location, and sub-processors, everything is published.

What Article 21 requires from your Git host. NIS2 supplier assessment. DORA register. Security. Pricing.

Open an account Or email hello@codebahn.net with questions.

This is not legal advice. NIS2 transposition status, law names, and in-force dates are verified as of September 2026 and may change as legislation is amended. Verify current status with qualified counsel. Country-level scope numbers are from public estimates by national authorities.