NIS2 supply chain: how to assess your suppliers
You can have your own security impeccable and still suffer a breach because of a supplier. That is the reality that the NIS2 supply chain directive puts on the table: your security is only as strong as the weakest link among your third parties. In the regulated projects I lead, this is one of the points demanding the most new effort.
What NIS2 requires regarding suppliers
NIS2 obliges the affected entities to manage the security risks arising from their supply chain. Securing your own is not enough: you have to assess the security of suppliers, especially those providing critical services, and require an adequate level from them. Responsibility is no longer delegated; it is shared and supervised.
This links with the NIS2 penalties: a failure originating in a poorly managed third party can bring consequences for the main entity.
How to assess your suppliers
Classify by criticality
Not all suppliers deserve the same scrutiny. Classifying them according to their access to critical systems and data makes it possible to concentrate effort where the risk is real. An office supplies provider is not a cloud provider.
Demand evidence, not promises
Asking for certifications, audit results or security questionnaires turns trust into something verifiable. It connects with cybersecurity risk management: assessing third parties is extending your risk analysis beyond your own walls.
Contracts with security clauses
Security obligations must be put in writing: required levels, right to audit and incident notification duties. A well-drafted contract is the most effective tool for governing the NIS2 supply chain.
Governing third-party risk continuously
Assessment is not a one-off act, but a living process. Suppliers change, and with them their risk. Keeping an up-to-date register of third parties and their security level is exactly the kind of control I have integrated into the compliance tool I develop, because doing it in scattered spreadsheets neither scales nor withstands an audit.
Documenting due diligence without slowing the business
When I started applying NIS2 in real projects, I discovered that the biggest risk was not the lack of controls, but the lack of evidence. You can require a supplier to encrypt data or notify incidents, but if you do not document that requirement and its fulfilment, in an audit it is as if it never happened. That is why I now work with a living file for each critical third party: contract with security clauses, latest questionnaire answered, technical evidence and the date of the next review.
That file lets me answer in minutes the question that sooner or later comes from management or the regulator: do we know who touches our data and with what guarantees? Keeping it up to date costs less than it seems if you integrate it into the procurement flow, so that no supplier goes into production without having passed through the security filter. Due diligence thus stops being an annual formality and becomes a condition of entry.
Anticipating emerging risks in the chain
The supply chain is not static: it changes with every subcontractor your supplier brings in and with every new technology it deploys. That is why I assess not only the current state, but the trajectory. A supplier that invests in security, that publishes its certifications and that communicates its incidents transparently gives me much more confidence than another impeccable on paper but opaque in practice. Maturity is demonstrated with sustained facts, not with a one-off snapshot.
Among those emerging risks there is one worth putting on the table now with critical suppliers: the transition to cryptography resistant to quantum computers. Data exfiltrated encrypted today could be decrypted in the future, so I ask my third parties about their roadmap on this matter, a topic I develop in my article on post-quantum cryptography for companies. Incorporating this dimension into supplier assessment is, today, a clear sign of long-term vision.
A practical tip I repeat to teams: classify your suppliers by criticality before assessing them. It makes no sense to apply the same level of requirement to the service that processes sensitive customer data as to the one that manages the office catering. Concentrate the audit effort where a failure would have a real impact on continuity or compliance, and simplify the rest. This proportionality is, moreover, what the very spirit of NIS2 expects from mature, sustainable risk management over time.
Conclusion: your security includes that of others
NIS2 and the supply chain remind us that security no longer ends at your own perimeter. Governing suppliers with judgement, evidence and solid contracts is not bureaucracy: it is protecting the organisation from the risk that comes in through a third party’s door. And, increasingly, it is an unavoidable legal obligation.
Frequently asked questions about NIS2 and the supply chain
It obliges the affected entities to manage the security risks arising from their suppliers, especially assessing those that provide critical services and requiring an adequate level from them. Responsibility is shared and supervised, not delegated.
By classifying it by criticality according to its access to systems and data, demanding verifiable evidence (certifications, audits, questionnaires) instead of promises, and including security clauses in the contracts.
The required security levels, the right to audit and the incident notification duties. A well-drafted contract is the most effective tool for governing supply chain risk.
No. It is a living process: suppliers change and with them their risk. You have to keep an up-to-date register of third parties and their security level to govern the risk continuously and withstand an audit.
Do you have to apply this under DORA, NIS2 or ENS? Tell me about it.
Book 20 minutes