{"id":1279,"date":"2026-08-20T20:34:40","date_gmt":"2026-08-20T18:34:40","guid":{"rendered":"https:\/\/sbit-hospitality.com\/?p=1279"},"modified":"2026-08-27T16:26:20","modified_gmt":"2026-08-27T14:26:20","slug":"nis2-supply-chain-cascade-hospitality","status":"publish","type":"post","link":"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/","title":{"rendered":"You are correctly not in NIS2 scope. Everyone around you is."},"content":{"rendered":"<div class=\"core-content paragraph-content\">\n<p class=\"eyebrow wp-block-paragraph\">Chapter 01<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h2 class=\"wp-block-heading\">Bol&#8217;s own systems were not breached. Bol is still running the playbook.<\/h2>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"lede wp-block-paragraph\">On 1 August 2026 Bol was informed that CEVA Logistics, the warehousing partner behind its distribution centre in Waalwijk, had suffered a cyberattack. Unauthorised parties gained access to systems used to process orders from that site. Names, addresses, postcodes, email addresses, phone numbers, order numbers and track and trace data may have been accessed. Payment details, passwords and login credentials were not. Bol&#8217;s own systems were not breached. Bol and De Bijenkorf, which uses the same partner, notified affected customers on 5 August.<\/p>\n<\/div>\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">The breach was at the supplier. The notification obligation, the regulator conversation, the media coverage and the board attention all landed on the customer of that supplier.<\/p>\n<\/div><\/blockquote>\n\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">Bol has been transparent about what happened. Notification to the Autoriteit Persoonsgegevens on 3 August, within forty-eight hours. External investigation. Coordinated customer communication. Board-level oversight. This is not a company scrambling. This is a company running a rehearsed playbook. Worth being precise about which clock was running: notifying the Autoriteit Persoonsgegevens is a GDPR obligation under Article 33. NIS2 carries its own, separate reporting schedule. Bol is in scope under NIS2 as a provider of an online marketplace under Annex II, which means it runs both regimes at once. That is what the rehearsal is for.<\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">The scale behind that notification became clear over the following week. The attack on CEVA began on 29 July and affected eight warehouses across Europe. Ten organisations have filed breach reports with the Autoriteit Persoonsgegevens in connection with it. Alongside Bol and De Bijenkorf they include ING, Ajax, the eyewear brand Ace &amp; Tate, and Valve, the company behind Steam. One compromised logistics provider, and the notification obligation landed on a bank, a football club, two retailers and a games platform in the same week.<\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">For hospitality operators reading the news, the interesting question is not what Bol did. It is what happens to organisations that sit outside the formal NIS2 scope but end up caught in the same operational and regulatory cascade. That is the question this piece exists to answer.<\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"eyebrow wp-block-paragraph\">Chapter 02<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h2 class=\"wp-block-heading\">You are correctly not in scope. That is not the good news your board thinks it is.<\/h2>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"lede wp-block-paragraph\">NIS2 scope is a two-factor test. The sector, as listed in Annex I (essential entities) or Annex II (important entities). And the size, measured against thresholds drawn from the EU SME definition. As a rule both factors have to apply, subject to Article 2(2), which puts certain entity types in scope irrespective of size.<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h3 class=\"wp-block-heading\">Sector filter, first<\/h3>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">Annex I covers energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration and space. Annex II adds postal and courier services, waste management, chemicals, food processing and wholesale, several categories of manufacturing, research organisations, and digital providers of online marketplaces, search engines and social networks. Accommodation is not on either list. Neither is hotel management, hospitality services or any related sub-sector.<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h3 class=\"wp-block-heading\">Size filter, second<\/h3>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">If your organisation qualifies under one of the sector categories, size decides which bracket. You are a medium-sized enterprise, and so an important entity, from 50 staff, or below 50 staff if turnover or balance sheet total exceeds 10 million euro. You exceed the medium ceilings, and so become an essential entity under Annex I, at 250 staff or more, or if turnover exceeds 50 million euro and the balance sheet total exceeds 43 million euro. Exceeding those ceilings in an Annex II sector still leaves you an important entity. If your organisation does not qualify under a sector, the size filter never comes into play at all. A hotel group with 5,000 employees and 500 million euro in revenue remains outside the formal scope of NIS2. This is a stable fact.<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h3 class=\"wp-block-heading\">What the sector filter cannot decide<\/h3>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">What the sector filter does not decide is whether NIS2-level obligations still show up in the hospitality operating model. The directive is only one way those obligations arrive. There are three others, and for hospitality all three matter more than the directive itself.<\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"eyebrow wp-block-paragraph\">Chapter 03<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h2 class=\"wp-block-heading\">Above you and below you, everyone is in scope.<\/h2>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"lede wp-block-paragraph\">Hospitality sits between two layers of organisations that the directive does apply to. Above you, in the customer layer, are corporations increasingly bound by essential or important entity status. Below you, in the infrastructure layer, are the cloud and SaaS providers that carry your reservation systems, payment flows, guest communications and back office. Both layers are subject to NIS2. Both layers are contractually obliged to pass the requirement forward. You are the sandwich.<\/p>\n<\/div>\n\n<div class=\"block container block-post-cards\" data-name=\"Cards\" id=\"block_96fbbf1acb0f673d100ac34c6b8a6a55\">\n    <div class=\"post-cards\">\n                    <h3 class=\"post-cards__title title h4\">Three cascades already in motion, plus the national implementation question<\/h3>\n                            <div class=\"post-cards__grid\">\n                                    <div class=\"post-cards__item\">\n                                                    <h4 class=\"post-cards__item-title\">The corporate customer cascade<\/h4>\n                                                                            <div class=\"post-cards__item-text\"><p>Corporate customers who book conferences, off-sites and business travel with your properties are increasingly essential or important entities themselves. Banks, insurers, pharma, tech, government. Article 21 requires them to assess and manage the security risk in their direct supplier relationships, and for the venue that hosts their people and their data, you are one of those direct suppliers. Their procurement questionnaires, security clauses and audit rights are already changing. The next time a large customer signs a corporate rate agreement, they are also assessing whether their exposure at your venue is compatible with their own regulatory position.<\/p>\n<\/div>\n                                            <\/div>\n                                    <div class=\"post-cards__item\">\n                                                    <h4 class=\"post-cards__item-title\">The cloud infrastructure cascade<\/h4>\n                                                                            <div class=\"post-cards__item-text\"><p>Under the old NIS Directive, cloud providers were digital service providers under Annex III, with light touch, ex post oversight. NIS2 brings cloud computing services into Annex I, digital infrastructure. Because the large providers comfortably exceed the size ceilings, they qualify as essential entities and fall under the comprehensive ex ante and ex post supervisory regime of Article 32. Their contracts are being rewritten with new shared-responsibility clauses and stricter security obligations for their customers. The reservation system, guest WiFi backend, financial ledger and payment gateway that run on that infrastructure inherit the terms of that contract. So do you.<\/p>\n<\/div>\n                                            <\/div>\n                                    <div class=\"post-cards__item\">\n                                                    <h4 class=\"post-cards__item-title\">The insurance underwriting cascade<\/h4>\n                                                                            <div class=\"post-cards__item-text\"><p>Cyber insurance premiums have risen sharply across the hospitality sector. Underwriters now require evidence of exactly the controls that NIS2 imposes on essential and important entities: multi-factor authentication, endpoint detection, tested backup and recovery, documented incident response, supplier security assessment. The controls are the same. The pricing already reflects them. Only the accompanying regulatory support is missing.<\/p>\n<\/div>\n                                            <\/div>\n                                    <div class=\"post-cards__item\">\n                                                    <h4 class=\"post-cards__item-title\">The national implementation contingency<\/h4>\n                                                                            <div class=\"post-cards__item-text\"><p>The Dutch Cyberbeveiligingswet entered into force on 15 August 2026, alongside the Wet weerbaarheid kritieke entiteiten. Its annexes mirror the directive, so accommodation stays outside, and the designation powers it grants work at the level of individual organisations within listed sectors rather than whole new sectors. Adding hospitality would take an amendment to the Act, not a ministerial decision. The sector boundary is therefore more stable than it looked. Which removes the comfortable excuse for waiting, because the other three cascades were never waiting on it.<\/p>\n<\/div>\n                                            <\/div>\n                            <\/div>\n            <\/div>\n<\/div>\n\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">The practical consequence is that NIS2-level obligations enter the hospitality operating model through the side door regardless of what the front door regulation says. Contracts with in-scope customers require them. Contracts with in-scope cloud providers require them. Insurance policies price them. The question is not whether the requirements arrive. The question is how you receive them.<\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"eyebrow wp-block-paragraph\">Chapter 04<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h2 class=\"wp-block-heading\">What \u201cacting as if in scope\u201d actually requires.<\/h2>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"lede wp-block-paragraph\">The operational answer to the sandwich position is not to argue about formal scope. It is to run the organisation as if the directive applied, because in practical terms it already does. That answer is more concrete than it sounds. Six elements make it work.<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h3 class=\"wp-block-heading\">Documented risk management<\/h3>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">Article 21(2) of NIS2 lists ten categories of technical, operational and organisational measures. Risk analysis and information system security policies. Incident handling. Business continuity. Supply chain security. Security in network and information systems acquisition and development. Policies to assess effectiveness. Cyber hygiene and training. Cryptography. Human resources security, access control and asset management. And, last, multi-factor or continuous authentication together with secured voice, video and text communications where appropriate. None of these are exotic in 2026. All of them require documentation that shows how, when, and by whom they are maintained. The dossier itself is the deliverable.<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h3 class=\"wp-block-heading\">A tested incident response plan<\/h3>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">Early warning within 24 hours and full notification within 72 hours, both counted from the moment you become aware rather than the moment the incident began, with the final report due one month after that 72-hour notification. Article 23 sets the clocks. They only work if the plan exists on paper and has been rehearsed. Tabletop exercises, defined roles, a named incident commander, an escalation tree with the actual phone numbers of the actual people who need to be reached at 2am on a Sunday. Most hospitality groups have some of this. Few have all of it. The gap is where preparedness lives.<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h3 class=\"wp-block-heading\">A supplier assessment programme<\/h3>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">This is where hospitality has to catch up fastest. Hotels typically have twenty to fifty integrations with third parties: PMS, booking channels, loyalty platforms, payment processors, guest messaging, digital keys, POS. Each is a potential CEVA equivalent. Article 21 obliges in-scope organisations to manage the risk in their direct supplier relationships, which is why this pressure reaches hospitality contractually rather than statutorily. NIS2-style supplier assessment means knowing which suppliers hold guest data, what their own security posture looks like, when they last certified, and what the contractual response protocol is when they suffer an incident. Building this programme takes time. Discovering you need it during someone else&#8217;s breach costs much more.<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h3 class=\"wp-block-heading\">Continuous monitoring with defined response<\/h3>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">Detection catches attacks that prevention misses. Response contains them before they compound. This is the layer where Managed Detection and Response, whether internal or through a partner, becomes a first-order requirement rather than an optional add-on. For hotel groups without a dedicated security operations centre, this is exactly what a managed service like Secure360 exists to provide. It is worth noting where that partner sits in the directive. Annex I lists ICT service management (business-to-business), naming managed service providers and managed security service providers explicitly. Your hotel group is outside NIS2. The provider running your security is inside it. The controls described in this chapter are the ones that provider is already obliged to run on itself.<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h3 class=\"wp-block-heading\">Board-level cybersecurity oversight<\/h3>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">NIS2 places personal accountability on board members of in-scope organisations. For hospitality boards that are not in scope, the equivalent accountability arrives through corporate customer scrutiny, insurer requirements and public incident coverage. Making cybersecurity a standing board topic, with quarterly reporting, ensures the board is informed before it needs to explain itself.<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h3 class=\"wp-block-heading\">Audit-ready documentation, always<\/h3>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">The difference between an organisation that survives regulatory or contractual scrutiny well and one that does not is rarely the underlying security. It is whether the dossier is current. Policies dated. Reviews recorded. Training logs kept. Incident tickets closed with root cause analysis. Supplier assessments filed. Under NIS2 this is called being audit ready. Outside NIS2 it is called being defendable when a customer, insurer, journalist or regulator asks.<\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"eyebrow wp-block-paragraph\">Chapter 05<\/p>\n<\/div>\n\n<div class=\"core-content heading-content\">\n<h2 class=\"wp-block-heading\">What \u201cnot being in scope\u201d actually costs.<\/h2>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"lede wp-block-paragraph\">The argument for treating NIS2 scope as decisive is that acting as if the directive applied costs money and effort that a strictly out-of-scope organisation does not have to spend. That argument is technically correct and strategically wrong. What it misses is the asymmetry of the two positions.<\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">If you are right about scope and act as if you were not, you saved effort in the short term. In the medium term you built controls that your insurance underwriter required anyway, that your corporate customers asked for anyway, that your cloud contract quietly obliged you to have anyway, and that would have kept you defendable in the incident you did not have. The upside of being right about scope is invisible and modest.<\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">If you are wrong about scope, or if a large corporate customer runs an audit, or if a supplier is breached and you are named in the coverage, you are personally exposed with a dossier that is not ready and a response plan that is not rehearsed. The downside of being wrong is measured in personal liability for board members, cancelled corporate contracts, insurance premium increases and reputation damage that outlasts the incident cycle. The downside of being wrong is invoiced during a live incident. That is asymmetric.<\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">The notifications Bol and De Bijenkorf sent on 5 August are not a story about retail. They are a preview of how the regulatory and contractual cascade actually behaves. The party that runs the playbook does not have to be the party that was breached. The party held accountable does not have to be the party that failed. In hospitality, where the number of supplier integrations exceeds most other sectors and where the guest data at stake is uniquely sensitive, the sandwich position is not neutral. It is the exposure. Acting as if scope applied is the response.<\/p>\n<\/div>\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><div class=\"core-content paragraph-content\">\n<p class=\"wp-block-paragraph\">Being out of scope is a fact about the law. It is not a fact about your exposure.<\/p>\n<\/div><\/blockquote>\n<div class=\"core-content heading-content\">\n<h3 class=\"wp-block-heading\">Sources cited<\/h3>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"source wp-block-paragraph\"><strong>[1]<\/strong> NOS, <em>Bol en de Bijenkorf waarschuwen klanten voor mogelijk datalek<\/em>, 5 August 2026. <a href=\"https:\/\/nos.nl\/artikel\/2625681-bol-en-de-bijenkorf-waarschuwen-klanten-voor-mogelijk-datalek\" rel=\"noopener\" target=\"_blank\">nos.nl<\/a><\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"source wp-block-paragraph\"><strong>[2]<\/strong> TechCrunch, <em>A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond<\/em>, 10 August 2026. <a href=\"https:\/\/techcrunch.com\/2026\/08\/10\/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond\/\" rel=\"noopener\" target=\"_blank\">techcrunch.com<\/a><\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"source wp-block-paragraph\"><strong>[3]<\/strong> Directive (EU) 2022\/2555 (NIS2), Articles 2, 3, 21, 23 and 32, and Annexes I and II. Consolidated European legislation.<\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"source wp-block-paragraph\"><strong>[4]<\/strong> Commission Recommendation 2003\/361\/EC concerning the definition of micro, small and medium-sized enterprises, Annex, Article 2.<\/p>\n<\/div>\n\n<div class=\"core-content paragraph-content\">\n<p class=\"source wp-block-paragraph\"><strong>[5]<\/strong> Cyberbeveiligingswet, in force 15 August 2026. <a href=\"https:\/\/wetten.overheid.nl\/BWBR0052872\/2026-08-15\" rel=\"noopener\" target=\"_blank\">wetten.overheid.nl<\/a><\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Bol was not breached. CEVA Logistics was. The notification obligation, the regulator conversation and the board attention landed on Bol anyway, and on nine other organisations besides. For hotel groups sitting outside the formal NIS2 scope, that cascade is the exposure.<\/p>\n","protected":false},"author":6,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[12],"class_list":["post-1279","post","type-post","status-publish","format-standard","hentry","category-secure360"],"acf":{"post_subtitle":"","post_title":"You are correctly not in NIS2 scope. Everyone around you is.","post_title_highlight":"Everyone around you is.","post_excerpt":"","post_image":1430,"quote":"You are correctly not in NIS2 scope. Everyone around you is. That determines the exposure.","quote_name":"Sandro Migliardi","quote_role":"CEO","quote_company":"Sbit Hospitality ICT Services","sources":null,"post_footer_cta":{"subtitle":"","title":"","text":"","button_1":"","button_2":""}},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NIS2 and Hotels: The Supply Chain Cascade Explained | Sbit<\/title>\n<meta name=\"description\" content=\"Your supplier was breached and the regulator still calls you. Why NIS2 obligations reach hotel groups that sit outside the directive&#039;s formal scope.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIS2 and Hotels: The Supply Chain Cascade Explained | Sbit\" \/>\n<meta property=\"og:description\" content=\"Your supplier was breached and the regulator still calls you. Why NIS2 obligations reach hotel groups that sit outside the directive&#039;s formal scope.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/\" \/>\n<meta property=\"og:site_name\" content=\"Sbit Hospitality\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-20T18:34:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-27T14:26:20+00:00\" \/>\n<meta name=\"author\" content=\"Sandro Migliardi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sandro Migliardi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sbit-hospitality.com\\\/nis2-supply-chain-cascade-hospitality\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sbit-hospitality.com\\\/nis2-supply-chain-cascade-hospitality\\\/\"},\"author\":{\"name\":\"Sandro Migliardi\",\"@id\":\"https:\\\/\\\/sbit-hospitality.com\\\/#\\\/schema\\\/person\\\/83cfa124bcf24f43bb0d7b0f2bd015c0\"},\"headline\":\"You are correctly not in NIS2 scope. Everyone around you is.\",\"datePublished\":\"2026-08-20T18:34:40+00:00\",\"dateModified\":\"2026-08-27T14:26:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sbit-hospitality.com\\\/nis2-supply-chain-cascade-hospitality\\\/\"},\"wordCount\":1846,\"articleSection\":[\"Secure360\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sbit-hospitality.com\\\/nis2-supply-chain-cascade-hospitality\\\/\",\"url\":\"https:\\\/\\\/sbit-hospitality.com\\\/nis2-supply-chain-cascade-hospitality\\\/\",\"name\":\"NIS2 and Hotels: The Supply Chain Cascade Explained | Sbit\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sbit-hospitality.com\\\/#website\"},\"datePublished\":\"2026-08-20T18:34:40+00:00\",\"dateModified\":\"2026-08-27T14:26:20+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/sbit-hospitality.com\\\/#\\\/schema\\\/person\\\/83cfa124bcf24f43bb0d7b0f2bd015c0\"},\"description\":\"Your supplier was breached and the regulator still calls you. Why NIS2 obligations reach hotel groups that sit outside the directive's formal scope.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sbit-hospitality.com\\\/nis2-supply-chain-cascade-hospitality\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sbit-hospitality.com\\\/nis2-supply-chain-cascade-hospitality\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sbit-hospitality.com\\\/nis2-supply-chain-cascade-hospitality\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sbit-hospitality.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"You are correctly not in NIS2 scope. Everyone around you is.\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sbit-hospitality.com\\\/#website\",\"url\":\"https:\\\/\\\/sbit-hospitality.com\\\/\",\"name\":\"Sbit Hospitality\",\"description\":\"Hospitality ICT Services\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sbit-hospitality.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sbit-hospitality.com\\\/#\\\/schema\\\/person\\\/83cfa124bcf24f43bb0d7b0f2bd015c0\",\"name\":\"Sandro Migliardi\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NIS2 and Hotels: The Supply Chain Cascade Explained | Sbit","description":"Your supplier was breached and the regulator still calls you. Why NIS2 obligations reach hotel groups that sit outside the directive's formal scope.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/","og_locale":"en_US","og_type":"article","og_title":"NIS2 and Hotels: The Supply Chain Cascade Explained | Sbit","og_description":"Your supplier was breached and the regulator still calls you. Why NIS2 obligations reach hotel groups that sit outside the directive's formal scope.","og_url":"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/","og_site_name":"Sbit Hospitality","article_published_time":"2026-08-20T18:34:40+00:00","article_modified_time":"2026-08-27T14:26:20+00:00","author":"Sandro Migliardi","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sandro Migliardi","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/#article","isPartOf":{"@id":"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/"},"author":{"name":"Sandro Migliardi","@id":"https:\/\/sbit-hospitality.com\/#\/schema\/person\/83cfa124bcf24f43bb0d7b0f2bd015c0"},"headline":"You are correctly not in NIS2 scope. Everyone around you is.","datePublished":"2026-08-20T18:34:40+00:00","dateModified":"2026-08-27T14:26:20+00:00","mainEntityOfPage":{"@id":"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/"},"wordCount":1846,"articleSection":["Secure360"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/","url":"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/","name":"NIS2 and Hotels: The Supply Chain Cascade Explained | Sbit","isPartOf":{"@id":"https:\/\/sbit-hospitality.com\/#website"},"datePublished":"2026-08-20T18:34:40+00:00","dateModified":"2026-08-27T14:26:20+00:00","author":{"@id":"https:\/\/sbit-hospitality.com\/#\/schema\/person\/83cfa124bcf24f43bb0d7b0f2bd015c0"},"description":"Your supplier was breached and the regulator still calls you. Why NIS2 obligations reach hotel groups that sit outside the directive's formal scope.","breadcrumb":{"@id":"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/sbit-hospitality.com\/nis2-supply-chain-cascade-hospitality\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sbit-hospitality.com\/"},{"@type":"ListItem","position":2,"name":"You are correctly not in NIS2 scope. Everyone around you is."}]},{"@type":"WebSite","@id":"https:\/\/sbit-hospitality.com\/#website","url":"https:\/\/sbit-hospitality.com\/","name":"Sbit Hospitality","description":"Hospitality ICT Services","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sbit-hospitality.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/sbit-hospitality.com\/#\/schema\/person\/83cfa124bcf24f43bb0d7b0f2bd015c0","name":"Sandro Migliardi"}]}},"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/sbit-hospitality.com\/sbit-api\/wp\/v2\/posts\/1279","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sbit-hospitality.com\/sbit-api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sbit-hospitality.com\/sbit-api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sbit-hospitality.com\/sbit-api\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/sbit-hospitality.com\/sbit-api\/wp\/v2\/comments?post=1279"}],"version-history":[{"count":6,"href":"https:\/\/sbit-hospitality.com\/sbit-api\/wp\/v2\/posts\/1279\/revisions"}],"predecessor-version":[{"id":1822,"href":"https:\/\/sbit-hospitality.com\/sbit-api\/wp\/v2\/posts\/1279\/revisions\/1822"}],"wp:attachment":[{"href":"https:\/\/sbit-hospitality.com\/sbit-api\/wp\/v2\/media?parent=1279"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sbit-hospitality.com\/sbit-api\/wp\/v2\/categories?post=1279"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}