Last updated: 4 October 2026
Quick answer: NIS2 supply chain security, under Article 21(2)(d), requires essential and important entities to manage cybersecurity risks in their relationships with direct suppliers and service providers. That means assessing each supplier’s vulnerabilities and security practices, setting security requirements in contracts, monitoring suppliers over time and keeping a supplier register.
Many of the most damaging cyber incidents start outside the victim’s own network: a compromised software update, a managed service provider with excessive access, or a cloud outage that takes down critical services. NIS2 responds by making supply chain security one of the minimum cybersecurity risk-management measures every in-scope entity must take.
This guide explains what the Directive and its Implementing Regulation require, how to tier suppliers by risk, which contract clauses to include, and how to monitor suppliers without drowning in questionnaires. It includes a contract clause checklist.
What does NIS2 supply chain security require?
Article 21 of Directive (EU) 2022/2555 (NIS2) requires entities to take appropriate and proportionate measures to manage risks to their network and information systems. Supply chain security is one of the listed minimum measures.
- Article 21(2)(d): measures must include “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”.
- Article 21(3): when deciding which supply chain measures are appropriate, entities must take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures. They must also take into account the results of coordinated risk assessments carried out under Article 22(1).
- Article 21(2)(e): a related measure covers security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure.
Accountability sits with the top. Under Article 20, management bodies must approve these measures and oversee their implementation, and infringements of Article 21 can lead to fines under Article 34 of at least EUR 10 million or 2% of worldwide turnover for essential entities, and EUR 7 million or 1.4% for important entities, whichever is higher.
What are coordinated supply chain risk assessments?
They are EU-level assessments of specific critical ICT supply chains. Under Article 22(1), the NIS Cooperation Group, together with the Commission and ENISA, may carry out coordinated security risk assessments of specific critical ICT services, systems or products supply chains, taking into account technical and, where relevant, non-technical risk factors.
Non-technical factors can include the risk of undue influence by a third country over a supplier. Where such an assessment exists for a product or service you rely on, Article 21(3) expects you to take its results into account when choosing and managing suppliers.
This area is set to grow. In January 2026 the Commission proposed a revised Cybersecurity Act with a Union-level ICT supply chain risk framework, alongside targeted NIS2 amendments that would stop Member States adding national supply chain obligations where EU-level technical requirements exist. Both are still proposals, so plan against the current rules while tracking their progress.
What does the Implementing Regulation add?
For digital infrastructure and digital service providers, including cloud computing, data centre, managed service and managed security service providers, Commission Implementing Regulation (EU) 2024/2690 sets out detailed technical and methodological requirements. Section 5 of its Annex deals with supply chain security and requires entities to:
- establish, implement and apply a supply chain security policy governing relations with direct suppliers and service providers;
- set criteria for selecting and contracting suppliers, such as their cybersecurity practices, their ability to meet security specifications, the quality and resilience of their ICT products and services, and, where applicable, the ability to diversify sources and limit vendor lock-in;
- take into account the results of Article 22 coordinated risk assessments where applicable;
- specify security requirements in contracts, including incident notification, audit rights, vulnerability handling, subcontracting conditions and obligations at the end of the contract;
- review the policy and monitor changes in suppliers’ cybersecurity practices at planned intervals; and
- maintain an up-to-date registry of direct suppliers and service providers, including contact points and the ICT products, services and processes each provides.
Entities outside the Regulation’s scope are covered by national transposition, but the Annex is a useful benchmark. ENISA’s NIS2 technical implementation guidance, published in June 2025, adds practical advice and examples of evidence for each requirement.
How mature are supply chain practices today?
Most organisations have a policy, but fewer have the resources to run it. ENISA’s Good Practices for Supply Chain Cybersecurity report, published in June 2023, found that 86% of surveyed organisations implemented ICT/OT supply chain cybersecurity policies, but only 47% allocated budget to it and 76% had no dedicated roles and responsibilities for it.
On evaluation methods, 61% required security certification from suppliers, 43% used security rating services and 37% carried out due diligence or risk assessments. Only 9% said they did not evaluate supply chain security risks in any way. The gap is less about awareness and more about consistent, resourced execution.
How should you tier suppliers under NIS2?
Tier suppliers by the impact they could have on your services, then apply controls in proportion. Article 21(1) requires measures that are appropriate and proportionate, so not every supplier needs the same scrutiny.
| Tier | Typical suppliers | Assessment | Contract controls | Review frequency |
|---|---|---|---|---|
| Critical | Cloud hosting, managed service and security providers, core software, suppliers with privileged access | Detailed questionnaire, evidence review (for example ISO 27001 or SOC 2 reports), remote or on-site audit where justified | Full security schedule: incident notification, audit rights, subcontracting approval, vulnerability handling, exit and data return | At least annually and after significant incidents or changes |
| High | Suppliers processing sensitive data or connected to production systems | Standard questionnaire with key evidence | Security clauses, incident notification, right to request evidence | Annually |
| Medium | Business applications with limited data or access | Short questionnaire or certification check | Standard security and confidentiality clauses | Every two years or on renewal |
| Low | No access to systems or sensitive data | Basic due diligence at onboarding | Standard terms | On renewal |
This is an illustrative model; set tier criteria in your supply chain security policy and apply them consistently.
Common mistake: tiering by contract value rather than by access and dependency. A low-cost remote support tool with privileged access to every server can be far more critical than an expensive marketing platform.
Which contract clauses should NIS2 supplier contracts include?
For critical and high-tier suppliers, contracts should turn your security expectations into enforceable obligations. Use this checklist as a starting point with your legal team:
- cybersecurity requirements the supplier must meet, referencing your policies or recognised standards;
- staff awareness, training and, where appropriate, background checks;
- notification of incidents affecting your services within a defined time, with the detail you need for your own NIS2 reporting;
- your right to audit, or to receive independent assurance reports;
- vulnerability handling and patching obligations for products and services supplied;
- conditions for subcontracting, including approval and flow-down of security requirements;
- access control commitments, such as least privilege and multi-factor authentication for remote access;
- obligations at the end of the contract, including return or secure deletion of information and exit support.
In practice: align supplier incident notification deadlines with your own reporting cascade. NIS2 Article 23 requires an early warning to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident, so a supplier that can take a week to tell you creates a compliance problem. Our NIS2 incident reporting guide covers the full 24-hour, 72-hour and one-month cascade.
How do you monitor suppliers after onboarding?
Monitoring is where most programmes fall down. Build it into operations rather than treating it as an annual questionnaire exercise.
- Keep the supplier register current, including contact points and the ICT products and services each supplier provides.
- Reassess critical suppliers at planned intervals and after significant incidents, ownership changes or major service changes.
- Review service level and security reports, and track supplier-related incidents.
- Record findings and remediation actions, and escalate unresolved high risks to the risk owner.
- Report supplier risk to management, since the board must oversee Article 21 measures.
A vendor and third-party risk management workflow keeps the register, questionnaires, evidence and remediation in one place, and links supplier risks to your enterprise risk register. When a supplier incident occurs, an incident management workflow helps you meet the NIS2 reporting timeline.
To see how a supplier tiering model works with your own vendors, start your 14-day free trial of Enactia’s AI-powered GRC platform.
How does NIS2 supply chain security relate to DORA and ISO 27001?
The requirements overlap heavily, so one supplier programme can serve several frameworks. ISO 27001 Annex A includes supplier relationship controls (5.19 to 5.23), and financial entities follow DORA’s more prescriptive ICT third-party risk rules, including a register of information on ICT service arrangements.
Mapping these requirements once with cross-framework control mapping avoids sending the same supplier three questionnaires. Our guides to the DORA register of information and to the overlap between DORA, NIS2 and the EU AI Act explain how to structure that.
Key takeaways
- Article 21(2)(d) makes supply chain security a minimum NIS2 measure, focused on direct suppliers and service providers.
- Assess supplier-specific vulnerabilities, product quality and secure development practices, and consider EU coordinated risk assessments.
- Tier suppliers by access and dependency, not spend, and apply proportionate controls.
- Put security, incident notification, audit and exit obligations into contracts for critical suppliers.
- Keep a current supplier register and monitor suppliers at planned intervals, with board-level reporting.
Frequently asked questions
Does NIS2 cover fourth parties and subcontractors?
Article 21(2)(d) focuses on direct suppliers and service providers. However, risks from their subcontractors reach you through those direct relationships. The practical approach is to require critical suppliers to flow down security requirements, notify or seek approval for key subcontractors, and disclose material dependencies, so you can manage fourth-party risk through contracts.
Are suppliers of NIS2 entities directly regulated by NIS2?
Not automatically. A supplier is only directly regulated if it falls within NIS2 scope itself, for example as a managed service provider or cloud provider of sufficient size. Otherwise, suppliers feel NIS2 indirectly through contract requirements, questionnaires and audits imposed by their in-scope customers.
Is a supplier’s ISO 27001 certificate enough for NIS2?
It is strong evidence but not a complete answer. Check that the certificate scope covers the services you buy, review the Statement of Applicability where possible, and confirm contract terms for incident notification, audit rights and exit. For critical suppliers, supplement certification with targeted questions on risks specific to your use of the service.
How often should NIS2 supplier assessments be repeated?
NIS2 does not set a fixed interval. The Implementing Regulation requires monitoring and review at planned intervals for entities in its scope. A common approach is at least annual review for critical suppliers, less frequent review for lower tiers, and immediate reassessment after significant incidents, ownership changes or major changes to the service.
What if a critical supplier refuses to accept our security clauses?
Record the refusal, assess the residual risk and decide whether to accept, mitigate or avoid it. Mitigation might include compensating controls such as restricted access, extra monitoring or a secondary supplier. The decision should be approved by the risk owner and visible to management, since the board oversees Article 21 measures.
Building a supply chain programme that lasts
NIS2 supply chain security is not a one-off questionnaire campaign. It is a continuous process: know your suppliers, tier them by risk, write security into contracts, monitor what changes and report to the board. Organisations that build this into procurement and operations find it easier to show supervisors that their measures are appropriate and proportionate.
If you would like help setting up supplier tiering, assessments and monitoring for NIS2, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
