[{"data":1,"prerenderedAt":379},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"regulation-en-nis2":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":56,"entities":328,"extension":331,"faq":332,"keywords":351,"meta":356,"navigation":357,"ogImage":358,"path":55,"persona":359,"publishedAt":358,"regulation":360,"relatedFeatures":361,"relatedPages":365,"seo":368,"shortTitle":54,"slug":360,"sources":369,"stem":375,"tldr":376,"updatedAt":377,"__hash__":378},"regulations_en\u002Fen\u002Fregulations\u002Fnis2.md","NIS2 Compliance for Your Vendor Supply Chain | CISAPP","CISAPP",{"type":108,"value":109,"toc":320},"minimark",[110,115,129,132,151,155,158,266,270,277,303,307,310],[111,112,114],"h2",{"id":113},"what-is-nis2-and-who-is-in-scope","What is NIS2 and who is in scope?",[116,117,118,122,123,128],"p",{},[119,120,121],"strong",{},"NIS2 is Directive (EU) 2022\u002F2555, imposing a common cybersecurity baseline on entities operating in critical sectors of the European Union."," It distinguishes ",[124,125,127],"a",{"href":126},"\u002Fen\u002Fglossary\u002Fnis2-essential-entity","essential entities"," — supervised proactively — from important entities, supervised after the fact. Both carry the same substantive obligations.",[116,130,131],{},"An organisation outside the scope can still be affected in practice: its regulated customers must manage their supply chain and therefore pass their requirements down through contracts and questionnaires.",[133,134,135],"key-takeaways",{},[136,137,138,142,145,148],"ul",{},[139,140,141],"li",{},"NIS2 applies to essential and important entities in the Annex I and II sectors, above the size thresholds set by the directive.",[139,143,144],{},"Article 21 explicitly requires supply chain security, including the relationship with direct suppliers.",[139,146,147],{},"Article 23 sets a three-step reporting timeline: 24 hours, 72 hours, then a final report within one month.",[139,149,150],{},"Management accountability is part of the directive: approving measures and following training are obligations, not good practice.",[111,152,154],{"id":153},"what-does-article-21-require","What does Article 21 require?",[116,156,157],{},"Article 21 lists ten families of measures every regulated entity must implement under a risk-based approach:",[159,160,162],"comparison-table",{"caption":161},"The ten Article 21 measure families and their impact on vendor management",[163,164,165,178],"table",{},[166,167,168],"thead",{},[169,170,171,175],"tr",{},[172,173,174],"th",{},"Measure family",[172,176,177],{},"Impact on vendor management",[179,180,181,190,198,210,218,226,234,242,250,258],"tbody",{},[169,182,183,187],{},[184,185,186],"td",{},"Risk analysis and information system security policies",[184,188,189],{},"Third parties included in risk analysis",[169,191,192,195],{},[184,193,194],{},"Incident handling",[184,196,197],{},"Incidents reported by a vendor taken into account",[169,199,200,203],{},[184,201,202],{},"Business continuity and crisis management",[184,204,205,206],{},"Identification of ",[124,207,209],{"href":208},"\u002Fen\u002Fglossary\u002Fvendor-spof","vendor SPOFs",[169,211,212,215],{},[184,213,214],{},"Supply chain security",[184,216,217],{},"Core of the requirement: assessing and monitoring third parties",[169,219,220,223],{},[184,221,222],{},"Security in acquisition, development and maintenance",[184,224,225],{},"Security requirements in contracts and procurement",[169,227,228,231],{},[184,229,230],{},"Assessing the effectiveness of measures",[184,232,233],{},"Evidence of periodic vendor reassessment",[169,235,236,239],{},[184,237,238],{},"Cyber hygiene and training",[184,240,241],{},"Expected to extend to providers with access",[169,243,244,247],{},[184,245,246],{},"Cryptography and encryption",[184,248,249],{},"Requirements imposed on third parties handling data",[169,251,252,255],{},[184,253,254],{},"Human resources security and access control",[184,256,257],{},"Managing external provider access",[169,259,260,263],{},[184,261,262],{},"Multi-factor authentication and secured communications",[184,264,265],{},"Common contractual requirement on third parties",[111,267,269],{"id":268},"how-do-you-evidence-supply-chain-compliance","How do you evidence supply chain compliance?",[116,271,272,273,276],{},"The requirement is not to audit every vendor, but to ",[119,274,275],{},"demonstrate a proportionate, documented approach",". Three artefacts are consistently expected during a review:",[278,279,280,286,297],"ol",{},[139,281,282,285],{},[119,283,284],{},"An inventory of third parties"," with a justified criticality level, not a purchasing list.",[139,287,288,291,292,296],{},[119,289,290],{},"Dated assessments",", proportionate to criticality, with the evidence received (",[124,293,295],{"href":294},"\u002Fen\u002Fglossary\u002Fvendor-due-diligence","vendor due diligence",").",[139,298,299,302],{},[119,300,301],{},"Traceable decisions",": compensating measures, remediation plans with deadlines, or walking away.",[111,304,306],{"id":305},"how-cisapp-structures-nis2-tracking","How CISAPP structures NIS2 tracking",[116,308,309],{},"CISAPP pre-wires the NIS2 framework and connects it to vendor assessment campaigns: every piece of evidence ties back to a third party, a risk in the register and an Article 21 measure. Incidents reported by a vendor feed significant incident tracking, and exports are generated in the format expected by regulators and auditors.",[116,311,312,313,316,317,319],{},"See also the ",[124,314,315],{"href":10},"NIS2 vendor compliance"," solution and the ",[124,318,42],{"href":43}," page for financial entities.",{"title":321,"searchDepth":322,"depth":322,"links":323},"",2,[324,325,326,327],{"id":113,"depth":322,"text":114},{"id":153,"depth":322,"text":154},{"id":268,"depth":322,"text":269},{"id":305,"depth":322,"text":306},[329,330],"Essential entity","TPRM","md",[333,336,339,342,345,348],{"q":334,"a":335},"What is the NIS2 directive?","NIS2 is Directive (EU) 2022\u002F2555 on measures for a high common level of cybersecurity across the Union. It replaces the 2016 NIS directive, significantly widens the set of entities in scope, harmonises risk management and incident reporting obligations, and makes management bodies accountable.",{"q":337,"a":338},"Who is in scope of NIS2?","Entities in the sectors listed in Annexes I and II that meet the size thresholds (in principle 50 employees or EUR 10 million turnover), split between essential and important entities. Some entities are in scope regardless of size, such as qualified trust service providers and central public administration entities.",{"q":340,"a":341},"What does NIS2 require from vendors?","The directive does not directly bind vendors outside its scope, but Article 21 requires regulated entities to manage the security of their supply chain. In practice those requirements are passed down through contracts and questionnaires, and vendors must be able to evidence their security posture.",{"q":343,"a":344},"What are the incident reporting deadlines?","Article 23 sets three steps: an early warning within 24 hours of becoming aware of the incident, an incident notification within 72 hours including an initial assessment, and a final report within one month. The competent authority may also request an intermediate report.",{"q":346,"a":347},"What penalties apply?","The directive sets administrative fine caps of at least EUR 10 million or 2% of worldwide turnover for essential entities, and at least EUR 7 million or 1.4% for important entities, whichever is higher. Management bodies can also be held liable for breaches.",{"q":349,"a":350},"Does CISAPP cover NIS2 Article 21 measures?","Yes. The NIS2 module structures the tracking of Article 21 security measures, significant incident management and supply-chain vendor risk in a dedicated framework, with formatted exports for regulators and auditors.",[315,352,353,354,355],"NIS2 supply chain","NIS2 software","third-party risk NIS2","NIS2 Article 21",{},true,null,"entreprise","nis2",[362,363,364],"Regulatory frameworks","Risk register","Vendor mapping",[366,367],"dora","iso-27001",{"title":105,"description":56},[370],{"label":371,"url":372,"publisher":373,"date":374},"Directive (EU) 2022\u002F2555 (NIS2) — consolidated text","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2022\u002F2555\u002Foj","EUR-Lex","2022-12-14","en\u002Fregulations\u002Fnis2","NIS2 (Directive (EU) 2022\u002F2555) requires essential and important entities to implement ten families of risk management measures, including supply chain security, and to report significant incidents in three steps: early warning within 24 hours, incident notification within 72 hours, final report within one month. CISAPP structures those obligations and ties every piece of evidence to a vendor, a risk and a control.","2026-08-16","IbLkRlkCRk6rUZ4HmWcQRQGjoQHI2PcKNfjDnQOH1Ig",1791391138736]