CodebahnCodebahn

NIS2 supplier assessment for Git hosting

Last updated: 29 September 2026

If your organisation falls under NIS2 (Directive (EU) 2022/2555), you need to assess the security of every service provider in your supply chain. That includes where your source code is hosted, who operates the infrastructure, and under whose jurisdiction.

This page explains how Codebahn answers those questions. We publish it rather than waiting to be asked, because you should be able to assess us before a call rather than after one.

For a plain-language overview of the directive, see the European Commission's NIS2 page.

What NIS2 requires from your suppliers

Article 21(2)(d) of NIS2 requires essential and important entities to implement "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers."

Article 21(3) adds that entities must take into account the vulnerabilities specific to each direct supplier and service provider, the overall quality of products and cybersecurity practices of their suppliers and service providers (including their secure development procedures), and the results of coordinated security risk assessments carried out under Article 22(1).

In practice, this means you need to know where a service provider is incorporated, where data is processed and stored, which sub-processors are involved, and what happens if the provider is disrupted or compelled to produce data.

How Codebahn answers

QuestionAnswer
Legal entityHackerman AB, incorporated in Sweden. Org. nr 559079-1918, EUID SEBOLREG.5590791918
JurisdictionSwedish and EU law. Courts of Gothenburg
Data at restScaleway, Paris (France). Encrypted backups at Hetzner, Falkenstein (Germany)
Data processingFrance only
Sub-processorsAll EU-incorporated. Published list with 30 days' notice before changes
CLOUD Act exposureNone. No US entity, parent, or sub-processor anywhere in the chain
Incident notificationWithin 48 hours (DPA 8.1, addendum 5.1)
Authority cooperationWe cooperate fully with your competent and resolution authorities (Terms 17.2)
Exit and data returnOne-click export, standard format, any time. 90 days' notice before we end the service
CertificationsNone yet. No SOC 2, no ISO 27001. See Security

Compliance documentation

These are the documents a supplier assessment typically pulls from. All are published; none require a request or an NDA.

NIS2 across member states

NIS2 is an EU directive. Each member state transposes it into national law, which means the local name, timeline, and supervisory authority vary by country. The supply chain security obligations are the same across all transpositions: they come from the directive, not from national additions.

If you are evaluating Codebahn under one of these laws, the answers above apply.

CountryNational lawStatusAuthority
BelgiumLoi du 26 avril 2024 (cadre pour la cybersécurité)In force since 18 Oct 2024CCB
ItalyDecreto Legislativo 4 settembre 2024, n. 138In force since 16 Oct 2024ACN
FinlandKyberturvallisuuslaki (124/2025)In force since 8 Apr 2025Traficom
DenmarkLov nr. 434 af 6. maj 2025 (NIS-2-loven)In force since 1 Jul 2025Digitaliseringsstyrelsen
GermanyNIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG)In force since 6 Dec 2025BSI
SwedenCybersäkerhetslagen (SFS 2025:1506)In force since 15 Jan 2026Riksdagen
NetherlandsCyberbeveiligingswet (Cbw)In force since 15 Aug 2026NCSC-NL
AustriaNetz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026)In force since 1 Oct 2026NIS Büro
FranceProjet de loi relatif à la résilience des infrastructures critiquesNot yet enactedANSSI
SpainProyecto de Ley de coordinación y gobernanza de la ciberseguridadNot yet enactedINCIBE
IrelandNational Cyber Security BillNot yet enactedNCSC Ireland

Norway applies NIS1 under the EEA agreement (Digitalsikkerhetsloven). NIS2 incorporation into the EEA agreement is in progress. Table verified September 2026. Dates and names may change as legislation is amended.

Where we are the wrong supplier

We hold no SOC 2 or ISO 27001. We cannot offer on-site audit rights or participate in threat-led penetration testing.

If your supplier assessment requires any of these, we are the wrong choice today, and it is better to learn that on this page than in month three of a procurement. If what you need is written commitments rather than an audit report, the Assurance plan publishes them.

If you are a financial entity under DORA, the DORA register page has the specific fields your register needs.

Questions about NIS2 compliance: hello@codebahn.net.