+49 6430 9227117
New · 09/2026 Free 17 pages · 14 chapters ≈ 20 min read

NIS2 doesn't ask if you maintain.
It asks if you can prove it.

The practical guide for CIO, CISO and compliance: which of the ten mandatory measures in Art. 21 reach into hardware operations, what evidence auditors ask for — and how to document SLAs, supply chain and accountability in the maintenance contract so they hold up in an audit.

4 of 10 mandatory measures in Art. 21 NIS2 reach directly into hardware operations
~30.000 German entities in scope of NIS2 (BSIG, in force since Dec 2025)
24h early-warning deadline under § 32 BSIG — the maintenance partner must feed in
TECH·CARE — Whitepaper · 2026

NIS2 & hardware
maintenance in audits.

Ten audit fields, twelve contract clauses — what auditors want to see and how the maintenance contract delivers it.

Art. 2110 measures
§ 38BSIG management
24/72hreporting cascade
14 chapters techcaresolutions.de

Download whitepaper

PDF, 17 pages — download starts instantly. No newsletter strings attached.

Required
Required
Please enter a valid email
Required
Required
GDPR compliant No spam, no forced newsletter
The core of the directive

Four of the ten mandatory measures hit your maintenance contract directly.

Art. 21(2) of the NIS2 Directive lists ten areas of measures every in-scope entity must implement at minimum. § 30 BSIG adopts the catalogue almost verbatim. Four areas together describe precisely the service a hardware maintenance contract delivers — which is why it is on the audit list.

  • Availability is a security objective: a storage failure without a spare can be a reportable incident — even without an attacker (Art. 6, Art. 23).
  • The maintenance partner is supply chain: physical access, remote access, parts in the environment — no supplier gets closer to the infrastructure (point d).
  • "Maintenance" is named verbatim in point e — coupled to vulnerability handling. Firmware of BMC, iLO, iDRAC and switches is part of patch management.
All ten measures in the whitepaper →

Art. 21(2) NIS2 · § 30 BSIG

direct hardware reach indirect
  • lit. c
    Business continuity · backup · recovery
  • lit. d
    Supply chain security · service providers
  • lit. e
    Acquisition, development, maintenance · vulnerabilities
  • lit. i
    Access control · asset management · personnel
  • a b f g h j
    Risk analysis · incidents · effectiveness · hygiene · crypto · MFA

Fine range § 65 BSIG

up to €10m / 2%

Reporting cascade § 32 BSIG

24h · 72h · 1 month

Sources: Directive (EU) 2022/2555 Arts. 21, 23; German NIS2UmsuCG/BSIG §§ 30, 32, 65 (in force since Dec 2025). Full mapping in ch. 4.

Target audiences

Who is this whitepaper for?

Three roles, one question: what does the auditor want to see on hardware — and who delivers it?

CIO

CIO / Head of IT

Owns availability and budget. Needs a maintenance contract that evidences restoration times instead of promising response times — and counts as evidence in the audit.

SLA · spares · reports

CISO

CISO / Information security

Must fold firmware levels, EOSL systems and third-party engineer access into vulnerability and access management — and keep the 24-hour reporting chain even in a hardware case.

OPS.1.1.3 · KEV · § 32 BSIG

Compliance

Compliance / procurement / management

Must assess the maintenance partner as a supplier, add a security annex to the contract — and put the decision before management that § 38 BSIG requires of it.

ISO 5.19–5.22 · § 38 · clauses
Contents

What's in the whitepaper

17 pages, 14 chapters, sourced throughout — legal text, BSI, ISO 27001, DORA.

17Pages
14Chapters
≈20Min read
01

Management Summary

02

NIS2 in ten minutes: who, what, from when

03

Why hardware maintenance is a NIS2 topic

04

The ten measures of Art. 21 — and their hardware relevance

05

What auditors check: the audit matrix

06

Supply chain security: the maintenance provider as supplier

07

SLA requirements under NIS2: availability is a security objective

08

Firmware, patches, vulnerabilities: OPS.1.1.3 and EOSL hardware

09

The 24h / 72h / 1-month reporting cascade

10

Media, spare parts, access: the physical controls

11

Documented accountability: § 38 BSIG

12

The maintenance contract in the audit: 12-point clause checklist

13

Conclusion

14

About TechCare & sources

Chapter 5 · core tool

The audit matrix: ten audit fields, four items per sample

Auditors do not check "NIS2 compliance" — no such certificate exists. They check whether measures are implemented, documented and effective. Typical sample: support status, last firmware update, contact at the maintenance partner, last media replacement with evidence. The whitepaper names audit question, expected evidence and reference per field.

1

Asset inventory

Model, location, support status, criticality per system recorded?

2

Criticality & risk

Failure impact assessed, protection derived from it?

3

Availability & SLA

Restoration time fixed, spares stocked, reports evidenced?

4

Supplier assessment

Maintenance partner assessed — certificates, subcontractors, sites?

5

Contract & clauses

Security annex, reporting participation, audit rights, exit covered?

6

Firmware & patches

Advisories tracked, firmware updates applied with documentation?

7

End of support (EOSL)

Systems beyond vendor support with documented risk acceptance?

8

Incidents & reporting

Hardware incidents fed into the 24h/72h cascade?

9

Media & spare parts

Erase certificates per medium, chain of custody per spare?

10

Third-party access

Site and remote access logged, MFA-secured?

Chapter 12 · working template

Twelve clauses that turn the maintenance contract into audit evidence.

Almost every contract has the three commercial points: scope, response times, reporting. The nine security-related ones are often missing — security annex, subcontractors, firmware supply, EOSL handling, reporting participation, media, spare-parts origin, access and personnel, audit rights and exit. For existing contracts an addendum is usually enough.

Commercial
3
Security-related
9
Reference frame
Art. 21 · BSI · ISO
Blueprint
DORA Art. 30
§ 38
BSIG: management approves, oversees, trains — and is personally accountable
3 mo.
deadline for BSI registration after falling in scope (§ 33 BSIG)
MUSS
BSI OPS.1.1.3: check unsupported products for secure operability
78 / day
new vulnerabilities per BSI situation report 2024 — firmware included

“The auditor rarely comes by appointment. They come as a key account with a supplier questionnaire, as an insurer, as a statutory auditor — or after an incident, when the 24-hour clock is already running.”

— From Chapter 13 · conclusion

Who is behind this whitepaper

TechCare Solutions GmbH — audit-ready hardware maintenance for the European mid-market.

Headquartered in Hahnstätten, Germany, we maintain server, storage and network hardware from all major enterprise OEMs independently of the manufacturer — including beyond End of Service Life. Our contracts are designed for NIS2, DORA, KRITIS, BAIT, TISAX and ISO 27001: SLA performance reports, incident response within 24 hours, sub-outsourcing transparency, chain of custody for spare parts, erase certificates for every medium.

A compliance officer accompanies audits as escalation instance. 24/7 service desk in German and English, certified engineers, our own parts depots.

24h
Initial incident report, deeper report in 72h
4h
On-site response SLA
28
OEMs maintained vendor-independently
6
Compliance frameworks with documentation pack
Transparency

Sources — legal text, agencies, standards

Selection of primary sources. Full list with references in the PDF. Not legal advice.

Directive (EU) 2022/2555 (NIS2) — Arts. 6, 20, 21, 22, 23

German NIS2UmsuCG / BSIG — §§ 28, 30–33, 38, 65 · BSI scope check

BSI IT-Grundschutz 2023: OPS.1.1.3 · OPS.2.3 · CON.6 · DER.2.1 · INF.2 · situation report 2024

ISO/IEC 27001:2022 Annex A — 5.19–5.22, 5.30, 7.10, 7.13, 7.14, 8.8

DORA (EU) 2022/2554 Arts. 28–30 · Cyber Resilience Act (EU) 2024/2847 · IR (EU) 2024/2690

CISA KEV · NIST SP 800-88 · Uptime Institute Outage Analysis 2024 · ENISA Threat Landscape 2024 · Bitkom 2024

Ready for the next step?

Get the whitepaper. Hold your maintenance contract against the checklist.

After the download: a no-obligation 30-minute review of the NIS2 position of your hardware maintenance — with a concrete read on SLA evidence, supplier assessment and EOSL documentation.

Read next

Stay on the topic

Related topics