Regulations
NIS2 Compliance for Your Vendor Supply Chain
Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.
TL;DR
NIS2 (Directive (EU) 2022/2555) requires essential and important entities to implement ten families of risk management measures, including supply chain security, and to report significant incidents in three steps: early warning within 24 hours, incident notification within 72 hours, final report within one month. CISAPP structures those obligations and ties every piece of evidence to a vendor, a risk and a control.
What is NIS2 and who is in scope?
NIS2 is Directive (EU) 2022/2555, imposing a common cybersecurity baseline on entities operating in critical sectors of the European Union. It distinguishes essential entities — supervised proactively — from important entities, supervised after the fact. Both carry the same substantive obligations.
An organisation outside the scope can still be affected in practice: its regulated customers must manage their supply chain and therefore pass their requirements down through contracts and questionnaires.
What does Article 21 require?
Article 21 lists ten families of measures every regulated entity must implement under a risk-based approach:
| Measure family | Impact on vendor management |
|---|---|
| Risk analysis and information system security policies | Third parties included in risk analysis |
| Incident handling | Incidents reported by a vendor taken into account |
| Business continuity and crisis management | Identification of vendor SPOFs |
| Supply chain security | Core of the requirement: assessing and monitoring third parties |
| Security in acquisition, development and maintenance | Security requirements in contracts and procurement |
| Assessing the effectiveness of measures | Evidence of periodic vendor reassessment |
| Cyber hygiene and training | Expected to extend to providers with access |
| Cryptography and encryption | Requirements imposed on third parties handling data |
| Human resources security and access control | Managing external provider access |
| Multi-factor authentication and secured communications | Common contractual requirement on third parties |
How do you evidence supply chain compliance?
The requirement is not to audit every vendor, but to demonstrate a proportionate, documented approach. Three artefacts are consistently expected during a review:
- An inventory of third parties with a justified criticality level, not a purchasing list.
- Dated assessments, proportionate to criticality, with the evidence received (vendor due diligence).
- Traceable decisions: compensating measures, remediation plans with deadlines, or walking away.
How CISAPP structures NIS2 tracking
CISAPP pre-wires the NIS2 framework and connects it to vendor assessment campaigns: every piece of evidence ties back to a third party, a risk in the register and an Article 21 measure. Incidents reported by a vendor feed significant incident tracking, and exports are generated in the format expected by regulators and auditors.
See also the NIS2 vendor compliance solution and the DORA page for financial entities.
FAQ
NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It replaces the 2016 NIS directive, significantly widens the set of entities in scope, harmonises risk management and incident reporting obligations, and makes management bodies accountable.
Sources
- Directive (EU) 2022/2555 (NIS2) — consolidated text — EUR-Lex, 2022-12-14
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours