CIO
CIO / Head of IT
Owns availability and budget. Needs a maintenance contract that evidences restoration times instead of promising response times — and counts as evidence in the audit.
SLA · spares · reportsThe practical guide for CIO, CISO and compliance: which of the ten mandatory measures in Art. 21 reach into hardware operations, what evidence auditors ask for — and how to document SLAs, supply chain and accountability in the maintenance contract so they hold up in an audit.
Ten audit fields, twelve contract clauses — what auditors want to see and how the maintenance contract delivers it.
Your download is starting. If it doesn't, click below:
Tip: Start with Chapter 5 (audit matrix) and Chapter 12 (clause checklist) — they let you review your existing maintenance contract in 20 minutes.
Art. 21(2) of the NIS2 Directive lists ten areas of measures every in-scope entity must implement at minimum. § 30 BSIG adopts the catalogue almost verbatim. Four areas together describe precisely the service a hardware maintenance contract delivers — which is why it is on the audit list.
Art. 21(2) NIS2 · § 30 BSIG
Fine range § 65 BSIG
up to €10m / 2%Reporting cascade § 32 BSIG
24h · 72h · 1 monthSources: Directive (EU) 2022/2555 Arts. 21, 23; German NIS2UmsuCG/BSIG §§ 30, 32, 65 (in force since Dec 2025). Full mapping in ch. 4.
Three roles, one question: what does the auditor want to see on hardware — and who delivers it?
CIO
Owns availability and budget. Needs a maintenance contract that evidences restoration times instead of promising response times — and counts as evidence in the audit.
SLA · spares · reportsCISO
Must fold firmware levels, EOSL systems and third-party engineer access into vulnerability and access management — and keep the 24-hour reporting chain even in a hardware case.
OPS.1.1.3 · KEV · § 32 BSIGCompliance
Must assess the maintenance partner as a supplier, add a security annex to the contract — and put the decision before management that § 38 BSIG requires of it.
ISO 5.19–5.22 · § 38 · clauses17 pages, 14 chapters, sourced throughout — legal text, BSI, ISO 27001, DORA.
Management Summary
NIS2 in ten minutes: who, what, from when
Why hardware maintenance is a NIS2 topic
The ten measures of Art. 21 — and their hardware relevance
What auditors check: the audit matrix
Supply chain security: the maintenance provider as supplier
SLA requirements under NIS2: availability is a security objective
Firmware, patches, vulnerabilities: OPS.1.1.3 and EOSL hardware
The 24h / 72h / 1-month reporting cascade
Media, spare parts, access: the physical controls
Documented accountability: § 38 BSIG
The maintenance contract in the audit: 12-point clause checklist
Conclusion
About TechCare & sources
Auditors do not check "NIS2 compliance" — no such certificate exists. They check whether measures are implemented, documented and effective. Typical sample: support status, last firmware update, contact at the maintenance partner, last media replacement with evidence. The whitepaper names audit question, expected evidence and reference per field.
1
Model, location, support status, criticality per system recorded?
2
Failure impact assessed, protection derived from it?
3
Restoration time fixed, spares stocked, reports evidenced?
4
Maintenance partner assessed — certificates, subcontractors, sites?
5
Security annex, reporting participation, audit rights, exit covered?
6
Advisories tracked, firmware updates applied with documentation?
7
Systems beyond vendor support with documented risk acceptance?
8
Hardware incidents fed into the 24h/72h cascade?
9
Erase certificates per medium, chain of custody per spare?
10
Site and remote access logged, MFA-secured?
The whitepaper delivers the audit matrix and clause checklist. These pages deliver the concrete status for your environment — no email, no signup.
5-question self-assessment for NIS2, DORA, ISO 27001, TISAX, BAIT. Score per framework, top gaps with fix, PDF export.
Start quizSix frameworks in detail: what the audit checks, which TechCare service delivers which evidence, which documentation comes automatically.
View frameworksVendor models from 28 OEMs filterable by class + EOSL status — audit field 7 inventoried in minutes.
Browse models5-year TCO OEM vs. TechCare with SLA picker — what a tiered SLA matrix by criticality costs.
Calculate TCOAlmost every contract has the three commercial points: scope, response times, reporting. The nine security-related ones are often missing — security annex, subcontractors, firmware supply, EOSL handling, reporting participation, media, spare-parts origin, access and personnel, audit rights and exit. For existing contracts an addendum is usually enough.
“The auditor rarely comes by appointment. They come as a key account with a supplier questionnaire, as an insurer, as a statutory auditor — or after an incident, when the 24-hour clock is already running.”
— From Chapter 13 · conclusion
Headquartered in Hahnstätten, Germany, we maintain server, storage and network hardware from all major enterprise OEMs independently of the manufacturer — including beyond End of Service Life. Our contracts are designed for NIS2, DORA, KRITIS, BAIT, TISAX and ISO 27001: SLA performance reports, incident response within 24 hours, sub-outsourcing transparency, chain of custody for spare parts, erase certificates for every medium.
A compliance officer accompanies audits as escalation instance. 24/7 service desk in German and English, certified engineers, our own parts depots.
Selection of primary sources. Full list with references in the PDF. Not legal advice.
Directive (EU) 2022/2555 (NIS2) — Arts. 6, 20, 21, 22, 23
German NIS2UmsuCG / BSIG — §§ 28, 30–33, 38, 65 · BSI scope check
BSI IT-Grundschutz 2023: OPS.1.1.3 · OPS.2.3 · CON.6 · DER.2.1 · INF.2 · situation report 2024
ISO/IEC 27001:2022 Annex A — 5.19–5.22, 5.30, 7.10, 7.13, 7.14, 8.8
DORA (EU) 2022/2554 Arts. 28–30 · Cyber Resilience Act (EU) 2024/2847 · IR (EU) 2024/2690
CISA KEV · NIST SP 800-88 · Uptime Institute Outage Analysis 2024 · ENISA Threat Landscape 2024 · Bitkom 2024
After the download: a no-obligation 30-minute review of the NIS2 position of your hardware maintenance — with a concrete read on SLA evidence, supplier assessment and EOSL documentation.
Run hardware past End of Service Life — 5–10 years beyond the official OEM cut-off.
View more →DORA, NIS2, KRITIS, BAIT, TISAX, ISO 27001 — what the auditor checks, what TechCare delivers.
View more →Interactive: OEM vs. TPM maintenance over 5 years, broken down per system.
View more →