#TPRM x #DefenseSector: Where Civilian Cyber Law Reaches Further Into Defense Than Most Suppliers Expect
Every regulated sector's third-party risk framework asks whether a supplier is financially sound and operationally capable. Defense TPRM must ask a further question with no real equivalent in banking, energy or healthcare: who ultimately owns, controls or can influence this supplier, and could that influence be exercised by a foreign state? That question is moving from a niche concern f√or cleared contractors to a compliance obligation across the defense industrial base. On 7 May 2026, the US Department of Defense proposed significantly expanding Foreign Ownership, Control and Influence disclosure requirements to any contractor or subcontractor, at any tier, holding a DoD contract above five million dollars, whether or not classified information is involved.
NIS2's text is precise: Article 2(7) excludes only public administration entities carrying out activities in national security, public security, defence or law enforcement - ministries and government agencies, not private companies.
A separate, optional provision allows Member States to exempt entities providing services exclusively to those excluded public bodies, but this is narrow, discretionary and rarely applies to a supplier with commercial or dual-use customers. Private defense manufacturers and software vendors were never covered by a blanket "defence exemption" - a private defense company that serves civilian markets, or whose products are dual-use, sits inside NIS2's covered sectors and compliance obligations.
The same logic runs through the EU AI Act. Article 2(3) exempts AI systems placed on the market "exclusively" for military, defence or national security purposes. A drone manufacturer selling the same platform to an army and a border-security agency cannot invoke the exemption for the civilian-facing sale, and a system built for civilian use that is later adopted for military purposes retains its civilian obligations.
Across both instruments, military exemptions are defined by entity type and exclusive end-use, not industry label. The "defence exemption" many suppliers assume applies is in reality narrower than believed - or in NIS2's case, was never available to them as a private company. NIS2 covers an estimated 160,000-plus entities across the EU, classified as Essential or Important, with Essential entities facing fines of up to €10 million or 2 percent of global turnover.
For a European defence supplier that built its compliance programme around a blanket military exemption, the reality that private-company status was never a basis for exclusion under NIS2, while dual-use revenue or non-exclusive military end-use forecloses the AI Act's narrower exemption, represents a governance gap unlikely to surface until a supervisory authority or prime's due diligence tests it.
For defense-sector third-party risk functions, the implication is a widening compliance perimeter: rather than accepting a supplier's self-declared "defence exemption," due diligence needs to verify whether that supplier is a public administration body engaged exclusively in excluded activities - the basis on which NIS2's carve-out applies - or a civilian-regulated private entity.
Organisations that build this verification into supplier onboarding now will be better positioned as NIS2 enforcement matures across the EU's defence-adjacent industrial base.