NIS2 supplier assessment for Git hosting
If your organisation falls under NIS2 (Directive (EU) 2022/2555), you need to assess the security of every service provider in your supply chain. That includes where your source code is hosted, who operates the infrastructure, and under whose jurisdiction.
This page explains how Codebahn answers those questions. We publish it rather than waiting to be asked, because you should be able to assess us before a call rather than after one.
For a plain-language overview of the directive, see the European Commission's NIS2 page.
What NIS2 requires from your suppliers
Article 21(2)(d) of NIS2 requires essential and important entities to implement "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers."
Article 21(3) adds that entities must take into account the vulnerabilities specific to each direct supplier and service provider, the overall quality of products and cybersecurity practices of their suppliers and service providers (including their secure development procedures), and the results of coordinated security risk assessments carried out under Article 22(1).
In practice, this means you need to know where a service provider is incorporated, where data is processed and stored, which sub-processors are involved, and what happens if the provider is disrupted or compelled to produce data.
How Codebahn answers
| Question | Answer |
|---|---|
| Legal entity | Hackerman AB, incorporated in Sweden. Org. nr 559079-1918, EUID SEBOLREG.5590791918 |
| Jurisdiction | Swedish and EU law. Courts of Gothenburg |
| Data at rest | Scaleway, Paris (France). Encrypted backups at Hetzner, Falkenstein (Germany) |
| Data processing | France only |
| Sub-processors | All EU-incorporated. Published list with 30 days' notice before changes |
| CLOUD Act exposure | None. No US entity, parent, or sub-processor anywhere in the chain |
| Incident notification | Within 48 hours (DPA 8.1, addendum 5.1) |
| Authority cooperation | We cooperate fully with your competent and resolution authorities (Terms 17.2) |
| Exit and data return | One-click export, standard format, any time. 90 days' notice before we end the service |
| Certifications | None yet. No SOC 2, no ISO 27001. See Security |
Compliance documentation
These are the documents a supplier assessment typically pulls from. All are published; none require a request or an NDA.
- Data Processing Agreement
- Sub-processor list
- Security and exit addendum (Assurance and Custom)
- Security overview
- Privacy policy
- Terms of Service (section 17 covers regulated customers)
- DORA register of information (financial entities)
NIS2 across member states
NIS2 is an EU directive. Each member state transposes it into national law, which means the local name, timeline, and supervisory authority vary by country. The supply chain security obligations are the same across all transpositions: they come from the directive, not from national additions.
If you are evaluating Codebahn under one of these laws, the answers above apply.
| Country | National law | Status | Authority |
|---|---|---|---|
| Belgium | Loi du 26 avril 2024 (cadre pour la cybersécurité) | In force since 18 Oct 2024 | CCB |
| Italy | Decreto Legislativo 4 settembre 2024, n. 138 | In force since 16 Oct 2024 | ACN |
| Finland | Kyberturvallisuuslaki (124/2025) | In force since 8 Apr 2025 | Traficom |
| Denmark | Lov nr. 434 af 6. maj 2025 (NIS-2-loven) | In force since 1 Jul 2025 | Digitaliseringsstyrelsen |
| Germany | NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG) | In force since 6 Dec 2025 | BSI |
| Sweden | Cybersäkerhetslagen (SFS 2025:1506) | In force since 15 Jan 2026 | Riksdagen |
| Netherlands | Cyberbeveiligingswet (Cbw) | In force since 15 Aug 2026 | NCSC-NL |
| Austria | Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) | In force since 1 Oct 2026 | NIS Büro |
| France | Projet de loi relatif à la résilience des infrastructures critiques | Not yet enacted | ANSSI |
| Spain | Proyecto de Ley de coordinación y gobernanza de la ciberseguridad | Not yet enacted | INCIBE |
| Ireland | National Cyber Security Bill | Not yet enacted | NCSC Ireland |
Norway applies NIS1 under the EEA agreement (Digitalsikkerhetsloven). NIS2 incorporation into the EEA agreement is in progress. Table verified September 2026. Dates and names may change as legislation is amended.
Where we are the wrong supplier
We hold no SOC 2 or ISO 27001. We cannot offer on-site audit rights or participate in threat-led penetration testing.
If your supplier assessment requires any of these, we are the wrong choice today, and it is better to learn that on this page than in month three of a procurement. If what you need is written commitments rather than an audit report, the Assurance plan publishes them.
If you are a financial entity under DORA, the DORA register page has the specific fields your register needs.
Questions about NIS2 compliance: hello@codebahn.net.