SaaSFort
Mittelstand NIS2 BSI MTA-STS Germany supply chain

Email Transport Security: The Cheapest NIS2 Evidence a Mittelstand Supplier Can Produce

Two DNS records and a static file. Externally verifiable, mapped to Article 21(2)(h), and almost no competitor has it.

ST
SaaSFort Team
· 5 min read · 801 words

A German industrial supplier with 180 employees is not in scope for NIS2 directly. Its customers are, and that is enough.

NIS2 Article 21(2)(d) obliges essential and important entities to manage supply chain risk, including the security of their direct suppliers. The practical consequence flows downhill as a questionnaire, an annex to a contract renewal, or a request for evidence with a deadline attached.

Most suppliers in this position face the same problem: a real compliance ask, no security team, and no budget line for one. The right move is to find controls with the highest ratio of demonstrable evidence to effort.

Email transport security is the clearest example available in 2026.

Why this control specifically

Four properties make it unusual.

It is cheap. Two DNS records and one static file on any HTTPS host. An afternoon, not a project.

It is externally verifiable. Your customer’s security team can confirm it themselves with one command, without a call, without trusting you. Evidence that does not require trust is worth disproportionately more in a supplier assessment.

It maps cleanly. NIS2 Article 21(2)(h) on cryptography, ISO/IEC 27001:2022 A.8.24 and A.5.14, and BSI TR-03108 in a German supervisory context.

Almost nobody has it. Published measurements put MTA-STS adoption across the top million domains below one percent. Controls that are both cheap and rare are unusual, and this is one.

The gap it closes

SPF, DKIM and DMARC are widely deployed and widely misunderstood as covering email security in general. They authenticate the sender: they prevent someone sending mail that appears to come from your domain.

They do not encrypt anything. SMTP negotiates encryption through a STARTTLS advertisement that is itself unauthenticated, so an attacker positioned on the network path can remove it and force plaintext delivery. DMARC still passes. The mail is simply readable in transit.

For a supplier exchanging drawings, specifications, pricing and contracts by email, that is the confidentiality exposure that matters, and it is the one nobody has measured.

The deployment

Two DNS records:

_mta-sts.ihredomain.de.   IN TXT "v=STSv1; id=20261001120000"
_smtp._tls.ihredomain.de. IN TXT "v=TLSRPTv1; rua=mailto:[email protected]"

One file, served at https://mta-sts.ihredomain.de/.well-known/mta-sts.txt:

version: STSv1
mode: testing
mx: mail.ihredomain.de
max_age: 604800

The subdomain needs a valid certificate. Any static hosting provides one. Microsoft 365 tenants list the *.mail.protection.outlook.com pattern in the mx field.

Note mode: testing. Start there, read the TLS-RPT reports for two to four weeks, fix anything they surface, then change one word to enforce.

The trap worth naming

mode: testing reports failures and delivers the mail anyway. A domain left in testing has the appearance of the control and none of the protection.

This is the most common outcome, because nobody schedules the switch. Put the date in a calendar when you deploy, not afterwards. If a customer asks which mode you are in and the answer is testing, the honest response is the deployment date for enforce, not a vague claim.

What to send the customer

A supplier response that carries weight looks roughly like this:

Inbound mail transport is protected by MTA-STS (RFC 8461) in enforce mode, requiring sending servers to use authenticated TLS. This addresses STARTTLS downgrade, which SPF, DKIM and DMARC do not cover, as those authenticate the sender rather than the connection. TLS-RPT (RFC 8460) is enabled and the daily reports are reviewed.

Verifiable independently: dig TXT _mta-sts.ihredomain.de curl https://mta-sts.ihredomain.de/.well-known/mta-sts.txt

Mapping: NIS2 Art. 21(2)(h), ISO/IEC 27001:2022 A.8.24 and A.5.14, BSI TR-03108.

Short, specific, checkable. It demonstrates that you understand a distinction the questionnaire itself usually fails to make, which is the impression that carries into the rest of the assessment.

What comes after

Once this is live, the same afternoon-scale logic applies to two more controls that are equally cheap and equally rare:

  • HSTS with preload, if not already in place.
  • Hybrid post-quantum key agreement, one line on the TLS terminator, which pre-answers a question that regulated customers have started asking.

DANE is the stronger mail control and requires DNSSEC on your zone. Treat it as the follow-on project rather than as a reason to delay the pair you can deploy now.

Where this fits in the broader obligation

Supply chain evidence requests will not stop at email. What the supply chain clause actually requires of suppliers.

The general principle worth carrying forward: prefer controls whose evidence is an observation rather than an assertion. A dated, independently reproducible measurement costs your customer nothing to verify, which is precisely why it satisfies them faster than a policy document.

The short version

Two DNS records, one file, one afternoon. Start in testing, read the reports, switch to enforce.

The result is externally verifiable NIS2 evidence in a control area where almost no competing supplier has anything to show.

Ready to put this into practice?

Two ways to start — pick what fits. Free Scan if you want to see your security grade in 60s with no commitment. Free 14-day Growth trial if you're ready to monitor multiple domains, export NIS2 reports, and download Deal Reports — no credit card required.

No credit card · Cancel anytime · GDPR-ready · EU-hosted

Continue reading