Regulations

NIS2 Compliance for Your Vendor Supply Chain

Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.

TL;DR

NIS2 (Directive (EU) 2022/2555) requires essential and important entities to implement ten families of risk management measures, including supply chain security, and to report significant incidents in three steps: early warning within 24 hours, incident notification within 72 hours, final report within one month. CISAPP structures those obligations and ties every piece of evidence to a vendor, a risk and a control.

What is NIS2 and who is in scope?

NIS2 is Directive (EU) 2022/2555, imposing a common cybersecurity baseline on entities operating in critical sectors of the European Union. It distinguishes essential entities — supervised proactively — from important entities, supervised after the fact. Both carry the same substantive obligations.

An organisation outside the scope can still be affected in practice: its regulated customers must manage their supply chain and therefore pass their requirements down through contracts and questionnaires.

What does Article 21 require?

Article 21 lists ten families of measures every regulated entity must implement under a risk-based approach:

The ten Article 21 measure families and their impact on vendor management
Measure familyImpact on vendor management
Risk analysis and information system security policiesThird parties included in risk analysis
Incident handlingIncidents reported by a vendor taken into account
Business continuity and crisis managementIdentification of vendor SPOFs
Supply chain securityCore of the requirement: assessing and monitoring third parties
Security in acquisition, development and maintenanceSecurity requirements in contracts and procurement
Assessing the effectiveness of measuresEvidence of periodic vendor reassessment
Cyber hygiene and trainingExpected to extend to providers with access
Cryptography and encryptionRequirements imposed on third parties handling data
Human resources security and access controlManaging external provider access
Multi-factor authentication and secured communicationsCommon contractual requirement on third parties

How do you evidence supply chain compliance?

The requirement is not to audit every vendor, but to demonstrate a proportionate, documented approach. Three artefacts are consistently expected during a review:

  1. An inventory of third parties with a justified criticality level, not a purchasing list.
  2. Dated assessments, proportionate to criticality, with the evidence received (vendor due diligence).
  3. Traceable decisions: compensating measures, remediation plans with deadlines, or walking away.

How CISAPP structures NIS2 tracking

CISAPP pre-wires the NIS2 framework and connects it to vendor assessment campaigns: every piece of evidence ties back to a third party, a risk in the register and an Article 21 measure. Incidents reported by a vendor feed significant incident tracking, and exports are generated in the format expected by regulators and auditors.

See also the NIS2 vendor compliance solution and the DORA page for financial entities.

FAQ

NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It replaces the 2016 NIS directive, significantly widens the set of entities in scope, harmonises risk management and incident reporting obligations, and makes management bodies accountable.

Sources

  1. Directive (EU) 2022/2555 (NIS2) — consolidated text — EUR-Lex, 2022-12-14

Ready for the regulations that apply to you

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account