Skip to content

Your build pipeline is in the supply chain

NIS2 and CI supply chain security

NIS2 puts supply chain security obligations on essential and important entities. A CI runner sits directly in that supply chain.

Frankfurt
Germany
Paris
France
Amsterdam
Netherlands
Stockholm
Sweden
Milan
Italy
Dublin
Ireland

Directive (EU) 2022/2555 — NIS2 — extends EU cybersecurity obligations to a much wider set of sectors than its predecessor, and puts explicit weight on supply chain security and on the security of the relationships with direct suppliers.

If you are an essential or important entity, the platform that executes your build code with access to your source and your deployment credentials is squarely a direct supplier worth assessing.

What is usually asked for

  • Isolation model — can one tenant's job affect another's
  • Access control and identity — SSO, SCIM, and who internally can reach what
  • Audit trail — an immutable record of configuration and access changes
  • Incident notification terms and timelines
  • Egress control — what a compromised build step can reach
  • Supplier's own sub-processor chain

What runnerhut provides

  • One job, one microVM with its own kernel; destroyed and wiped at job end
  • SAML/OIDC SSO with SCIM provisioning and enforced login
  • Append-only audit log with SIEM export and 13-month retention
  • Default-deny egress policy with per-destination allowlisting and logging
  • SOC 2 Type 2 report and annual penetration test summary, under NDA
  • Published, versioned sub-processor list

Sources

  • Directive (EU) 2022/2555 (NIS2) — https://eur-lex.europa.eu/eli/dir/2022/2555/oj

Your next build could be twice as fast, at half the price

Start free. Migrating away is the same one line, and we publish that diff too.