# NIS2 is in force. Your Git host is in your supply chain.

Between October 2024 and October 2026, eight EU member states enacted national laws transposing the NIS2 directive. Germany alone brought roughly 29,500 companies into scope. The Netherlands added over 8,000. Most of those companies have not yet asked where their source code is hosted, or under whose jurisdiction.

They will.

## What NIS2 requires

[NIS2](https://eur-lex.europa.eu/eli/dir/2022/2555) (Directive (EU) 2022/2555) is the EU's updated cybersecurity directive. It replaces the [original NIS directive](https://eur-lex.europa.eu/eli/dir/2016/1148/oj) from 2016 and expands the scope from critical infrastructure operators to a far broader set of sectors: energy, transport, health, digital infrastructure, ICT service management, public administration, manufacturing, food, chemicals, waste, postal services, and more. The [European Commission's overview](https://digital-strategy.ec.europa.eu/en/policies/nis2-directive) covers the full scope. [ENISA's implementation guidance](https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance) covers the technical measures.

Article 21(2)(d) requires essential and important entities to implement "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers."

Article 21(3) adds that entities must consider the vulnerabilities specific to each direct supplier and service provider, the overall quality of their cybersecurity practices, and the results of coordinated risk assessments.

This is not a certification checkbox. It is an obligation to know your supply chain.

## Why your Git host is in scope

Source code is an asset. The service that stores, processes, and builds it is a supplier. If you are subject to NIS2, your supplier assessment needs to cover your Git hosting provider, the same way it covers your cloud provider or your CI pipeline.

The questions your assessment will ask are straightforward:

- Where is the provider incorporated?
- Where is data processed and stored?
- Which sub-processors are involved, and where are they incorporated?
- Is the provider subject to the CLOUD Act or other non-EU data access laws?
- What happens if the provider is disrupted?
- How fast are you notified of an incident?

Most Git hosting providers are US-incorporated. That is not disqualifying on its own, but it is a fact your assessment needs to address, especially after the [third collapse of the EU-US data transfer framework](/blog/the-third-collapse/) in June 2026. The [CLOUD Act](/blog/cloud-act-eu-git/) is the reason jurisdiction matters here, not just data location.

## Where the laws stand

NIS2 is a directive, not a regulation. Each member state transposes it into national law with its own name, timeline, and supervisory authority. The supply chain obligations come from the directive itself and do not vary by country.

| Country | National law | In force |
|---|---|---|
| Belgium | Loi du 26 avril 2024 | Oct 2024 |
| Italy | D.Lgs. 138/2024 | Oct 2024 |
| Finland | Kyberturvallisuuslaki | Apr 2025 |
| Denmark | NIS-2-loven | Jul 2025 |
| Germany | NIS2UmsuCG | Dec 2025 |
| Sweden | Cybersäkerhetslagen | Jan 2026 |
| Netherlands | Cyberbeveiligingswet | Aug 2026 |
| Austria | NISG 2026 | Oct 2026 |

France, Spain, and Ireland have not yet enacted their transpositions; all three were [referred to the CJEU](https://digital-strategy.ec.europa.eu/en/policies/nis2-directive) in July 2026 for failure to transpose on time. Norway applies NIS1 under the EEA agreement ([Digitalsikkerhetsloven](https://nsm.no/aktuelt/ny-digitalsikkerhetslov-i-norge)); NIS2 incorporation is in progress.

The full table with links to each country's national authority is on our [NIS2 page](/nis2/).

## What we did about it

Codebahn is a Swedish company on EU-only infrastructure. Every sub-processor is EU-incorporated. There is no US entity anywhere in the chain.

We publish the answers a supplier assessment needs: [sub-processor list](/docs/subprocessors/), [DPA](/dpa/), [security addendum](/security-addendum/), and a [dedicated NIS2 page](/nis2/) mapping our answers to Article 21. Financial entities under DORA have a [separate register page](/dora/) with the specific fields their templates require.

We do not have SOC 2 or ISO 27001. If your assessment requires a signed audit report today, we are not your vendor yet. If what it requires is transparency about jurisdiction, data location, and sub-processors, everything is published.

[What Article 21 requires from your Git host](/nis2-git-hosting/). [NIS2 supplier assessment](/nis2/). [DORA register](/dora/). [Security](/security/). [Pricing](/pricing/).

<div style="margin-top: var(--sp-12); margin-bottom: var(--sp-12);">
  <a href="/user/sign_up" class="cb-btn primary">Open an account</a>
  <span style="display: inline-block; margin-left: var(--sp-4); color: var(--muted); font-size: var(--fs-small);">
    Or email <a href="mailto:hello@codebahn.net">hello@codebahn.net</a> with questions.
  </span>
</div>

<p style="color: var(--faint); font-size: var(--fs-micro); border-top: var(--hairline) solid var(--rule); padding-top: var(--sp-4);">
  This is not legal advice. NIS2 transposition status, law names, and in-force dates are verified as of September 2026 and may change as legislation is amended. Verify current status with qualified counsel. Country-level scope numbers are from public estimates by national authorities.
</p>
