NIS2 supply chain security is one of the ten risk management measures that essential and important entities must have in place, and it is the one that most quickly pulls procurement, legal and IT into the same conversation. Your security is only as good as the suppliers who hold your data, run your systems or ship code into your environment, and regulators now expect you to show that you manage that dependency deliberately.
This guide explains what Article 21 of the NIS2 Directive requires on suppliers, how to turn it into a supplier assessment and contract process, what evidence to keep and how the European Commission’s 2026 proposals could change the picture. The directive is implemented through national laws, so requirements vary by country. Check your national law and your authority’s guidance; nothing here is legal advice.
Free gap assessment
Where do you stand on the Article 21 measures?
Score scope, all ten measures, the management-body duties and the reporting clocks, free.
Run the free NIS2 gap assessment → or View premium report sample
What NIS2 requires on supply chain security
The NIS2 Directive, Directive (EU) 2022/2555, requires essential and important entities to take appropriate and proportionate technical, operational and organizational measures to manage the risks to their network and information systems. Article 21 lists a minimum set of measures, and one of them is supply chain security, including the security-related aspects of relationships with direct suppliers or service providers.
Article 21 also says that, when considering appropriate measures, entities must take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of their products and cybersecurity practices, including their secure development procedures. Entities must also consider the results of coordinated security risk assessments of critical supply chains carried out at EU level. See our overview of the NIS2 requirements for the full list.
Free third-party risk assessment
How much risk does this vendor bring?
Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.
Start the free vendor risk assessment → or View premium report sample
Who must comply
NIS2 applies to essential and important entities in a wide range of sectors, from energy and transport to digital infrastructure, health and manufacturing, depending on size and sector. Our guide on who NIS2 applies to explains the thresholds. If you are a supplier to such an entity, you may not be directly regulated, but you will almost certainly receive its security requirements in contracts and questionnaires.
That indirect effect is large. A company outside the scope of NIS2 can face the same questions as an in-scope company simply because its customers must manage their supply chain. Preparing a clear, evidenced answer is now a sales requirement, not just a compliance one.
Building a supplier inventory and tiering
You cannot manage what you have not listed. Build a register of every supplier and service provider with the service they provide, the data and systems they touch, the contract owner and the contract dates. Include software vendors, cloud and hosting providers, managed service providers, consultants with access and outsourced operations.
Then tier the list by risk. Criticality to your operations, access to sensitive data, privileged access to systems, substitutability and the supplier’s own security posture all matter. Tiering lets you spend effort where it counts: deep assessment for the few critical suppliers, light review for the many low-risk ones. Our guide on third-party risk management explains the wider process.
| Step | What to do | Evidence |
|---|---|---|
| Inventory | List suppliers and service providers, with the services and data involved | Supplier register |
| Tier | Rank suppliers by criticality and risk | Tiering criteria and results |
| Assess | Review security practices and known vulnerabilities for direct suppliers | Questionnaires, reports, certificates |
| Contract | Include security, incident, audit and exit terms | Signed contracts and addenda |
| Monitor | Track performance, incidents and changes | Review records, scorecards |
| Respond | Handle supplier incidents and exit plans | Incident logs, exit plans |
Assessing direct suppliers
For each tier, decide what you need to see. Low-risk suppliers might complete a short questionnaire. Critical suppliers may need independent evidence such as an ISO 27001 certificate with a relevant scope, a SOC 2 report, penetration test summaries, architecture descriptions and incident history. Read the evidence, do not just file it: check the scope, the period and the exceptions.
Ask specific questions that follow Article 21: how do they handle vulnerabilities, how do they develop software securely, what subcontractors do they use, how do they handle incidents and how quickly will they tell you? For the standards link, compare NIS2 vs ISO 27001, because an ISO 27001 certificate helps but does not automatically demonstrate that NIS2 duties are met.
Contract clauses that support NIS2 supply chain security
Contracts turn expectations into obligations. Typical clauses include security requirements proportionate to the service, prompt incident notification with a defined timeline that lets you meet your own reporting duties, cooperation in investigations, audit or assessment rights, vulnerability management, subcontractor controls, data location and return or deletion at exit, and business continuity commitments.
Connect the incident clause to your reporting duties. Because NIS2 sets short deadlines for significant incidents, a supplier that takes a week to tell you creates a problem you cannot fix afterwards; see NIS2 incident reporting. Also ask suppliers to support coordinated vulnerability disclosure.
Monitoring, incidents and exit
Assessment at onboarding is not enough. Monitor suppliers through periodic reviews, performance and incident records, news and changes of ownership or hosting location. Reassess critical suppliers at a set frequency and whenever something material changes.
Plan for failure. For each critical supplier, record how you would continue if it failed, who would lead the response and how you would transfer data and services. An exit plan that has never been read is not a plan, so test the critical ones.
Management accountability
NIS2 places responsibility on management bodies, which must approve and oversee the measures and can be held liable for failures. Supply chain risk should therefore be reported to the board or top management: the tier one list, open risks and material incidents. See NIS2 management liability and NIS2 penalties for the enforcement side, and NIS2 compliance cost for budgeting.
What the 2026 proposals could change
In January 2026 the European Commission published a package that included targeted amendments to NIS2 and a revised Cybersecurity Act. Law firm summaries report that the NIS2 proposals would add some entity categories, create a lighter category for small mid-cap companies, harmonize requirements in areas covered by Commission implementing acts and add requirements around ransomware reporting and post-quantum cryptography. The same summaries describe the package as a proposal awaiting approval by Parliament and Council with no fixed timeline.
Until a proposal is adopted and transposed, current national laws apply. Track developments, but do not delay supplier controls because of them. Your national rules and your authority’s guidance are what you will be assessed against.
Templates for supplier security
A consistent supplier process needs a policy, a register, a tiering method, questionnaires, contract clauses, review records and exit plans. The NIS2 Toolkit includes editable templates across these areas and the other NIS2 measures, so your team can put a documented process in place rather than writing each document from zero.
For the legal text, see the EUR-Lex text of Directive (EU) 2022/2555 (NIS2). Keep a record of your reasoning on proportionality, because the directive expects measures to be appropriate to your risk and size.
A worked example of NIS2 supply chain security tiering
Imagine a regional energy services company with 180 suppliers. A short scoring model asks four questions of each: does the supplier have privileged access to our systems, does it process sensitive or operational data, would its failure stop a key service for more than a day, and is it easy to replace. Suppliers that answer yes to two or more questions go into tier one. In this example, twelve suppliers reach tier one, among them the cloud platform, the remote maintenance vendor, the payroll processor and the operational technology integrator. Those twelve receive a full assessment, an incident clause with a 24-hour notice, annual review and a tested exit plan. The remaining suppliers receive a questionnaire and a standard clause. The numbers are illustrative, but the logic shows how proportionality works.
Evidence to keep for NIS2 supply chain security
Authorities and auditors will want to see the process working. Keep the supplier register with dates, the tiering method, the completed assessments and the decisions made on each, the signed contracts and addenda, the review and monitoring records, incident records involving suppliers and the exit plans. Record exceptions too: where a supplier could not meet a requirement, note who accepted the risk and why. Store the evidence in one place and assign an owner, so you can respond to a request within days.
Training procurement and business owners
Procurement staff and business owners are the people who bring new suppliers into the company. Train them to start the security review before signing, to recognize which suppliers need deeper checks and to escalate problems. A simple intake form that captures the service, the data and the access requested catches most issues early. When the process is easy to follow, people follow it, and the supplier register stays current without constant chasing by the security team.
Starting NIS2 supply chain security this quarter
Begin with the register and the tier one list, since those two steps give you the most risk reduction per hour. Then update the standard contract clauses, and plan assessments for the critical suppliers over the next quarter. By the end of that period you will have a defensible NIS2 supply chain security process that you can show to your authority, your auditors and your customers.
Common mistakes in NIS2 supply chain security
Typical errors include an incomplete supplier list, treating every supplier the same, collecting certificates without reading their scope, contracts without incident timelines, no monitoring after onboarding and no exit plan for critical suppliers. Another is focusing only on direct suppliers and forgetting the subcontractors they rely on. Ask about them, and require your suppliers to pass relevant obligations down.
NIS2 Supply Chain Security FAQ
What does NIS2 say about supply chain security?
Article 21 lists supply chain security, including security-related aspects of relationships with direct suppliers and service providers, among the minimum risk management measures.
Does NIS2 apply to my supplier?
Only if the supplier falls within the scope of the directive itself, but in-scope customers will pass requirements to it through contracts.
Is an ISO 27001 certificate enough?
It is useful evidence, but check its scope and whether it covers the services you use. It does not automatically prove every NIS2 duty is met.
Are NIS2 amendments coming?
The Commission proposed targeted amendments in January 2026. According to published summaries, they are still proposals and national laws currently apply.
What should contracts include?
Security requirements, incident notification timelines, cooperation, audit rights, subcontractor controls, data return or deletion and continuity commitments.