Industry Insight

Choosing a Secure Offshore Engineering Partner in the Nordics

A practical guide to GDPR data transfers, NIS2 supply-chain security, and IEC 62443 secure development

Eastgate Software Engineering

April 2026

Eastgate Software - German Engineering Standards. Enterprise-Grade Results.

Industry Insight

Choosing a Secure Offshore Engineering Partner in the Nordics

A practical guide to GDPR data transfers, NIS2 supply-chain security, and IEC 62443 secure development

Offshore engineering adds another layer to security and compliance reviews. Nordic enterprises need to know how a partner will protect personal data, manage cyber risk across the delivery chain, and develop secure software for industrial environments.

This guide explains what to assess under GDPR, how NIS2 shapes supplier due diligence for organizations within its scope, and when IEC 62443-4-1 is relevant. It also outlines the contracts, security controls, and supporting evidence to request before choosing an engineering partner.

Eastgate Software Engineering April 2026
Choosing a Secure Offshore Engineering Partner in the Nordics white paper cover

What Should Nordic Companies Check Before Choosing an Engineering Partner?

Nordic companies in regulated industries must check several rules before they hire an offshore engineering partner. First, GDPR sets rules for handling personal data and sending it outside the EU and EEA. In addition, NIS2 requires covered organisations to manage cyber risks linked to their suppliers. Finally, when a project involves industrial control systems, IEC 62443 sets out a secure way to develop software.

However, not every rule applies to every project. The right checks depend on the data being used, the rules that cover the client, and the type of system being built. Therefore, this guide explains what to check and which records to request. It also shows how we at Eastgate Software help Nordic clients prepare for security and procurement reviews.

What GDPR Safeguards Do Nordic Enterprises Need for Offshore Engineering?

The first area to review is GDPR. If the project involves personal data, start with these five checks:

1

Safeguards for International Data Transfers

When personal data moves from the EU or EEA to Vietnam, the transfer needs a valid safeguard under GDPR. In many engineering projects, this means using the European Commission's Standard Contractual Clauses. However, the correct SCC module depends on the roles of both parties.

2

Data Processing Agreement

If the engineering partner processes personal data for the client, both parties need a Data Processing Agreement under GDPR Article 28. The agreement should explain what data is used, why it is used, how long it is kept, and how it is protected.

3

Sub-Processor Transparency and Approval

The partner should list any sub-processors that may handle project data. It must also follow the approval process set out in the DPA before making changes. Check your cloud providers when they process or store the client's personal data.

4

Technical and Organizational Safeguards

The partner must use safeguards that match the level of risk. These may include encryption, access controls, audit logs, backups, and incident response procedures. ISO 27001 certification can support the review, but it does not prove GDPR compliance on its own.

5

Support for Individual Rights

The client may need help responding to requests to access, correct, delete, restrict, or export personal data. Therefore, the partner should document where data is stored and how it can be found, changed, returned, or removed.

Before delivery begins, Eastgate can provide a DPA, the appropriate Standard Contractual Clauses, and documentation of its technical and organizational safeguards. This helps Nordic clients complete their legal, security, and procurement reviews without unnecessary delays.

How Does NIS2 Affect Engineering Supply Chains in the Nordics?

NIS2, or the second Network and Information Systems Directive, is an updated EU law on cybersecurity. This law affects organizations' direct suppliers because they must manage risks across their supply chains.

After reviewing personal data under GDPR, the next step is to review security across the delivery chain. NIS2 requires each covered organization to use controls that match its risks. Therefore, clients need proof that an engineering partner is capable of protecting and managing the situations when something bad happens.

NIS2 Area What It Means for the Client Our Evidence
Risk Management A covered organization must find and manage risks to its networks and services. This includes risks that come from external partners. ISO 27001 risk records, a supplier review process, and documented project risk reviews.
Supply-Chain Security Clients must assess security risks in their relationships with direct suppliers and service providers. Therefore, an offshore engineering partner may be part of this review. A secure development process aligned with IEC 62443-4-1, a software bill of materials, and dependency and vulnerability scans.
Incident Reporting After a major incident, a covered organisation may need to send an early warning within 24 hours. An incident notice may then be due within 72 hours. Therefore, partners must alert the client quickly. An incident response plan, a two-hour initial alert target for critical incidents, and records from incident-response exercises.
Governance and Accountability Senior management must approve and oversee the organisation's cyber security controls. As a result, buyers need clear proof of ownership and supplier controls. A named Chief Information Security Officer, a clear governance structure, and ISO 27001 surveillance audit reports.
Core Security Controls Controls should match the level of risk. They may include MFA, encryption, access control, backups, patching, and secure communications. MFA required across all development systems, vulnerability scan reports, patch management SLA documentation.

Heads up: Norway is part of the EEA but not the EU. As a result, NIS2 does not apply there automatically. At the time of writing, the directive remains under review for inclusion in the EEA Agreement. Norway is also preparing its national implementation. Therefore, Norwegian organizations should follow current local law while preparing for future rules based on NIS2.

When Is IEC 62443 Relevant to Nordic Engineering Projects?

After GDPR and NIS2, the next step is to check whether IEC 62443 is relevant. IEC 62443 is a series of standards from the International Electrotechnical Commission. It helps organizations protect industrial automation and control systems.

However, the right standard depends on the system, the partner's role, and the terms of the contract. The examples below show when Nordic teams are most likely to use it.

ITS & Transport

IEC 62443 is often relevant when software controls or supports physical transport assets. Examples include traffic lights, tunnel controls, roadside equipment, and some traffic management systems. However, V2X and C-ITS work is not covered by default.

Energy & Utilities

The standard is often relevant to systems that monitor or control power grids, water plants, and district heating. It may cover the products, systems, and services used within these operational settings.

Manufacturing

IEC 62443 is often relevant to factory automation, SCADA, and other industrial control systems. MES software may also be relevant when it connects to or controls operational technology.

Smart Buildings & Infrastructure

The standard may be relevant when a building management or smart infrastructure system acts as an industrial control system or connects directly to one. However, a network connection alone does not make IEC 62443 the right standard.

Public Sector Digital Services

Most public-sector digital services do not fall under IEC 62443. It becomes relevant only when a service develops, operates, or connects to an industrial control system. Being covered by NIS2 does not make IEC 62443 apply automatically.

Eastgate IEC 62443 experience: Eastgate has 12 years of experience delivering ITS platforms for Siemens Mobility and Yunex Traffic, with ongoing work for Autobahn GmbH. Our teams use secure development processes aligned with IEC 62443-4-1 when a project calls for them. Even so, each project must be reviewed based on its scope, contract, and Eastgate's role.

What Evidence Should Nordic Procurement Teams Request From an Engineering Partner?

Once you know which rules apply, ask the partner for proof. Use this checklist during your review. However, not every item is required for every project. Pick the ones that fit the data, systems, risks, vendor role, and contract.

0 of 24

Items completed

Work through each category and tick items as you complete them. Your progress saves in this browser.

Nothing left to do here. Turn off "Hide completed items" to review the items.

Nothing left to do here. Turn off "Hide completed items" to review the items.

Nothing left to do here. Turn off "Hide completed items" to review the items.

Nothing left to do here. Turn off "Hide completed items" to review the items.

Nothing left to do here. Turn off "Hide completed items" to review the items.

How Does ACDC Support Secure and Traceable Nordic Delivery?

The checklist above shows what proof a client should request. The next question is how the team creates that proof during delivery. ACDC stands for Agent-Centric Development Cycle. It combines AI-assisted work with clear specifications, tests, and human review.

Together, these steps make the work easier to track and control. However, ACDC does not prove compliance on its own. The result still depends on the project scope, contract terms, security controls, and records created during delivery.

Spec-Driven Design

First, the team records what the client needs. It also defines the acceptance criteria and key rules for security and data. As a result, everyone can see the link between the client's request, the approved design, and the finished feature.

Test-Driven Development

Before implementation begins, the team defines tests and expected results. Engineers then check each AI-assisted output against those tests. This helps the team find errors early and records how each feature was checked.

Human Review and Approval

A senior engineer approves every AI-generated output before merge. The reviewer checks the logic, security, data, and fit with the approved design. Therefore, responsibility stays with the engineering team while each change follows the project's review process.

Common Questions from Nordic Technology Leaders

Does GDPR require a Data Processing Agreement for every offshore engineering vendor? +

Yes, if the engineering partner processes personal data on behalf of the regulated entity. In practice, most software development engagements involve at least some personal data, such as user records, test data, or logs. A DPA under GDPR Article 28 is mandatory in these cases. For the data transfer itself (EU/EEA to Vietnam), Standard Contractual Clauses are the standard mechanism. Eastgate has both ready to execute for any Nordic engagement.

Does NIS2 apply to offshore engineering teams delivering software to Nordic entities? +

Yes, under NIS2's supply chain security provisions. NIS2 explicitly covers the security of supply chains, including software suppliers and managed service providers. A Nordic entity regulated under NIS2 (essential or important entity) must assess and manage the cybersecurity risks posed by its engineering partners. This includes offshore partners delivering production code. The regulated entity cannot delegate its NIS2 obligations, only the engineering work.

When does IEC 62443 apply to an engineering vendor in the Nordic context? +

IEC 62443 applies when the software being developed will operate in or interface with an industrial control system, operational technology environment, or critical infrastructure. In the Nordic context, this includes transport management systems, energy grid software, SCADA interfaces, and building management systems connected to OT networks. If your project touches any of these, your engineering partner's development lifecycle should be aligned with IEC 62443-4-1.

What is the blended EU+Vietnam delivery model and how does it work for Nordic compliance? +

The blended model pairs a Nordic or EU-based technical lead (client-facing, accountability, stakeholder management) with a Vietnam-based engineering team (implementation, testing, delivery). For GDPR, this means the processing jurisdiction is primarily Vietnam, requiring SCCs and a DPA. For NIS2, the Vietnam team is a supply chain element that must be included in the regulated entity's supplier risk assessment. Eastgate's ISO 27001 certification and documented compliance posture is designed to support exactly this due diligence.

How does Eastgate handle GDPR data transfers from Nordic clients? +

We use Standard Contractual Clauses for any project involving personal data transfer from the EU/EEA to our Vietnam delivery hub, with the module chosen to match each party's role. Our ISO 27001 certified delivery environment provides the technical and organisational measures required under GDPR. A signed DPA and SCCs are available before engagement begins. We do not use personal data from client projects for any purpose other than the contracted delivery work.

Read the Full White Paper

Detailed framework, implementation methodology, and actionable insights - available instantly with your business email.

About Eastgate Software

Eastgate Software is a strategic engineering partner headquartered in Hanoi, Vietnam, with offices in Aachen, Germany and Tokyo, Japan. With 200+ engineers, 93% team retention, and 12+ years of delivery excellence, we build mission-critical systems for clients including Siemens Mobility and Yunex Traffic.

Our ACDC (Agent-Centric Development Cycle) methodology combines German engineering discipline with Vietnamese engineering talent to deliver enterprise-grade results across Intelligent Transportation, FinTech, Retail, and Manufacturing.

Contact: [email protected] | (+84) 246.276.3566 | eastgate-software.com

Let's Work Together

Tell us what you're building. Our engineers will respond within 1 business day with a concrete next step - no sales script, no obligation.