Your build pipeline is in the supply chain
NIS2 and CI supply chain security
NIS2 puts supply chain security obligations on essential and important entities. A CI runner sits directly in that supply chain.
Frankfurt
Germany
Paris
France
Amsterdam
Netherlands
Stockholm
Sweden
Milan
Italy
Dublin
Ireland
Directive (EU) 2022/2555 — NIS2 — extends EU cybersecurity obligations to a much wider set of sectors than its predecessor, and puts explicit weight on supply chain security and on the security of the relationships with direct suppliers.
If you are an essential or important entity, the platform that executes your build code with access to your source and your deployment credentials is squarely a direct supplier worth assessing.
What is usually asked for
- Isolation model — can one tenant's job affect another's
- Access control and identity — SSO, SCIM, and who internally can reach what
- Audit trail — an immutable record of configuration and access changes
- Incident notification terms and timelines
- Egress control — what a compromised build step can reach
- Supplier's own sub-processor chain
What runnerhut provides
- One job, one microVM with its own kernel; destroyed and wiped at job end
- SAML/OIDC SSO with SCIM provisioning and enforced login
- Append-only audit log with SIEM export and 13-month retention
- Default-deny egress policy with per-destination allowlisting and logging
- SOC 2 Type 2 report and annual penetration test summary, under NDA
- Published, versioned sub-processor list
Sources
- Directive (EU) 2022/2555 (NIS2) — https://eur-lex.europa.eu/eli/dir/2022/2555/oj
Your next build could be twice as fast, at half the price
Start free. Migrating away is the same one line, and we publish that diff too.