Glossary
Supply Chain Security
One of the 10 Article 21 measures, requiring entities to assess and manage cybersecurity risk from suppliers and service providers.
Explained in depth: The 10 NIS2 security requirements
NIS2 makes an organisation partly responsible for the security practices of its direct suppliers — a significant expansion compared to the original NIS Directive. In practice this means a supplier register, risk-based assessment criteria and security clauses in contracts, all of which have to be documented.