In Part 1 of this series, we explored what happens when digital identity wallets leave the safety of pilots and enter enterprise Identity and Access Management (IAM) environments. The conclusion was uncomfortable but unavoidable: trust only becomes meaningful when systems are expected to fail safely, be audited, and — if necessary — be replaced.
Germany has now demonstrated what that principle looks like beyond identity.
By activating one of the most far-reaching powers embedded in the NIS2 Directive, Germany has turned European supply-chain governance from theory into operational reality. Under its new national implementation act, the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI) can prohibit the use of specific ICT components — and require their removal or replacement — if they are deemed to introduce unacceptable security or supply-chain risk.
This is not a procurement guideline.
It is not a recommendation.
It is enforceable authority over live systems.
And it fundamentally changes what “resilience” means under NIS2.
The Power Few Talked About — Until Now
Since NIS2 was adopted, much of the discussion has focused on expanded scope, stricter reporting timelines, and higher penalties. Those elements matter, but they are not where the directive’s real leverage lies.
NIS2 was designed to address a deeper structural weakness in Europe’s digital economy: the fact that many organisations cannot clearly explain — let alone control — the dependencies that keep their operations running.
Article 21 of NIS2 makes this explicit, placing responsibility on management bodies to ensure appropriate measures for risk analysis, supplier governance, and continuity. The directive does not merely ask whether an organisation has policies. It asks whether risk is understood, governed, and survivable.
Germany has now operationalised that intent.
By enabling the BSI to prohibit ICT components on security or supply-chain grounds, Germany has activated the directive’s most disruptive capability: the ability to remove trust from infrastructure, not just identities.
What “Prohibit” Really Means in Practice
The significance of Germany’s move lies in what the power applies to — and how.
The BSI can now assess whether hardware, software, or cloud services introduce unacceptable risk due to factors such as:
- opaque or fragile supply chains
- vendor lock-in with no viable alternatives
- jurisdictional or geopolitical exposure
- insufficient security assurances or update control
If a component fails that assessment, the response is not limited to blocking future procurement. The authority extends to requiring organisations to remove or replace the component entirely, even if it is already deployed in operational environments.
This is the moment where resilience stops being rhetorical.
Historically, problematic technology might be tolerated because replacing it would be “too disruptive”. Under Germany’s implementation of NIS2, disruption is no longer a sufficient argument. If a component is deemed non-permitted, organisations must adapt.
From Identity Trust to Infrastructure Trust
There is a direct conceptual line between digital identity entering enterprise IAM and regulators asserting authority over ICT components.
In both cases, trust frameworks collide with operational reality.
In Part 1, the question was whether enterprises could rely on identity wallets without understanding how they fail, how they are revoked, or how access continues without them. In Part 2, the same question is applied one layer deeper: can organisations continue to operate if a critical component is removed by regulatory decision?
The uncomfortable truth is that many cannot.
Modern enterprises are built on layers of inherited dependencies — libraries, platforms, cloud services, embedded software — that are poorly documented and rarely stress-tested. They function because nothing challenges them. NIS2 is designed to challenge them.
Compliance Is Not Resilience
Germany’s move exposes a dangerous misconception: that NIS2 compliance can be achieved primarily through documentation, policies, and reporting structures.
Those elements are necessary, but they do not confer control.
An organisation that cannot identify where a prohibited component is deployed, what systems depend on it, and how it could be replaced is not resilient — regardless of how well-written its risk assessments may be.
This is why NIS2 explicitly targets management accountability. Boards are no longer insulated by technical complexity. If a regulator intervenes, governance decisions become operational decisions.
Resilience, under NIS2, must be demonstrable.
The End of Assumed Replaceabilit
For years, “replaceability” has been treated as an abstract design principle rather than a tested capability. Architectures are described as modular. Suppliers are described as interchangeable. Exit strategies exist on paper.
Germany’s implementation of NIS2 forces a reckoning:
replaceable in theory is not replaceable under pressure.
If removing a component would halt operations, disrupt safety, or break regulatory obligations, then that component is not merely a supplier — it is a point of systemic risk.
NIS2 does not prohibit such dependencies outright. But it makes them visible, accountable, and — when necessary — actionable.
Why Germany Matters — and Why Others Will Follow
Germany is not unique in having this power. Other EU member states have transposed NIS2 with similar legal foundations. What Germany has done is establish precedent.
By demonstrating that component prohibition is a legitimate regulatory tool — not an extreme interpretation — Germany lowers the threshold for others to act. Once one major economy uses the mechanism, it becomes part of the enforcement landscape.
For organisations operating across borders, this introduces a new complexity: a component permitted in one jurisdiction may be prohibited in another. Resilience planning can no longer be done nationally. It must be European in scope.
Digital Sovereignty Without the Slogan
There is also a broader strategic dimension to Germany’s move.
By asserting the right to prohibit ICT components based on supply-chain risk, the state is exercising influence over questions of dependency, control, and trust within digital infrastructure. This aligns with wider European discussions around digital sovereignty — but without the rhetoric.
NIS2 does not mandate where technology must come from. It demands that organisations understand what they rely on, why, and at what risk. Component bans are a blunt instrument, but they are effective precisely because they force that conversation early.
What Organisations Should Be Doing Now
With NIS2 enforcement approaching across Europe, Germany’s action should be treated as a signal, not an exception.
Organisations in scope should be able to answer, with evidence:
- Which ICT components are critical to operations?
- Where are they deployed?
- What would break if they were removed?
- How quickly could alternatives be activated?
- Are exit strategies contractual, technical, and tested?
Answering these questions is not the responsibility of IT alone. It requires coordination across security, procurement, legal, and executive leadership. That is exactly the governance model NIS2 was designed to enforce.
From Trust Frameworks to Trust Test
The common thread between digital identity wallets entering enterprise IAM and Germany activating NIS2’s supply-chain powers is simple: trust frameworks only matter when they are tested.
Identity that cannot be revoked is not trustworthy.
Infrastructure that cannot be replaced is not resilient.
Governance that exists only on paper is not governance.
Germany has applied that logic to ICT components. Others will apply it elsewhere.
NIS2 is no longer about proving compliance. It is about surviving scrutiny.
And as Europe moves into 2026, the organisations that fare best will be those that treated trust not as an assumption — but as something that must endure removal, replacement, and regulation.





Leave a Reply