Glossary · NIS2
Supply Chain Security
One of the 10 Article 21 measures, requiring entities to assess and manage cybersecurity risk from suppliers and service providers.
Explained in depth: The 10 NIS2 security requirements
Article 21(2)(d) requires entities to address security-related aspects of the relationships with their direct suppliers and service providers, taking into account each supplier's vulnerabilities, product quality, and cybersecurity practices, including their secure development procedures. In practice this means supplier risk assessments, security requirements in contracts, and ongoing monitoring of critical vendors. NIS2 also foresees coordinated EU-level risk assessments of critical supply chains. The obligation extends the reach of NIS2 beyond in-scope entities: a small software vendor outside NIS2's scope will still feel the directive through the contractual demands of its in-scope customers.
Why it matters
Supply chain attacks are among the most common root causes of major incidents. Auditors increasingly ask for a vendor register with risk classifications, contract clauses covering incident notification, and evidence of supplier reviews. Expect NIS2 clauses to appear in procurement whether you are in scope or not.
