[{"data":1,"prerenderedAt":314},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"solution-en-nis2-vendor-compliance":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":11,"entities":263,"extension":266,"faq":267,"keywords":286,"meta":291,"navigation":292,"ogImage":293,"path":10,"persona":294,"publishedAt":293,"regulation":295,"relatedFeatures":296,"relatedPages":299,"seo":302,"shortTitle":9,"slug":303,"sources":304,"stem":310,"tldr":311,"updatedAt":312,"__hash__":313},"solutions_en\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance.md","NIS2 Vendor Compliance: Mapping and Evidence | CISAPP","CISAPP",{"type":108,"value":109,"toc":256},"minimark",[110,115,129,148,152,234,238,241],[111,112,114],"h2",{"id":113},"what-does-nis2-require-on-vendors","What does NIS2 require on vendors?",[116,117,118,128],"p",{},[119,120,121,122,127],"strong",{},"Article 21 of the NIS2 directive requires ",[123,124,126],"a",{"href":125},"\u002Fen\u002Fglossary\u002Fnis2-essential-entity","essential entities"," and important entities to secure their supply chain, including the relationship with their direct suppliers."," The requirement is not to audit everyone, but to demonstrate a proportionate, documented approach.",[130,131,132],"key-takeaways",{},[133,134,135,139,142,145],"ul",{},[136,137,138],"li",{},"The supply chain is an integral part of the Article 21 measures.",[136,140,141],{},"Three artefacts are consistently expected: inventory, dated assessments, traceable decisions.",[136,143,144],{},"Incidents reported by a vendor feed the Article 23 significant incident process.",[136,146,147],{},"A company outside the NIS2 scope is affected in practice, through its regulated customers' requirements.",[111,149,151],{"id":150},"what-to-produce-for-a-review","What to produce for a review",[153,154,156],"comparison-table",{"caption":155},"NIS2 supply chain requirements and matching artefacts",[157,158,159,175],"table",{},[160,161,162],"thead",{},[163,164,165,169,172],"tr",{},[166,167,168],"th",{},"Requirement",[166,170,171],{},"Expected artefact",[166,173,174],{},"Where it lives in CISAPP",[176,177,178,190,201,212,223],"tbody",{},[163,179,180,184,187],{},[181,182,183],"td",{},"Identify critical third parties",[181,185,186],{},"Inventory with justified criticality",[181,188,189],{},"Vendor record + dependency mapping",[163,191,192,195,198],{},[181,193,194],{},"Assess proportionately",[181,196,197],{},"Dated questionnaires and evidence received",[181,199,200],{},"Assessment campaigns",[163,202,203,206,209],{},[181,204,205],{},"Monitor over time",[181,207,208],{},"Scheduled reassessments, recurring scans",[181,210,211],{},"SecOps score, certificate alerts",[163,213,214,217,220],{},[181,215,216],{},"Trace decisions",[181,218,219],{},"Compensating measures, remediation plans",[181,221,222],{},"Risk register",[163,224,225,228,231],{},[181,226,227],{},"Report incidents",[181,229,230],{},"24 h \u002F 72 h \u002F final report timeline",[181,232,233],{},"Significant incident tracking",[111,235,237],{"id":236},"from-vendor-questionnaire-to-regulatory-export","From vendor questionnaire to regulatory export",[116,239,240],{},"Without a dedicated platform, NIS2 compliance on the vendor side means re-keying answers into a regulatory tracking spreadsheet. CISAPP removes that step: the vendor's answer feeds the NIS2 framework directly, with a score tied to Article 21 measures and evidence exports in the format regulators expect.",[116,242,243,244,246,247,250,251,255],{},"See also the ",[123,245,54],{"href":55}," page, the ",[123,248,249],{"href":14},"supply chain cybersecurity"," solution and the ",[123,252,254],{"href":253},"\u002Fen\u002Fglossary\u002Fvendor-due-diligence","vendor due diligence"," glossary entry.",{"title":257,"searchDepth":258,"depth":258,"links":259},"",2,[260,261,262],{"id":113,"depth":258,"text":114},{"id":150,"depth":258,"text":151},{"id":236,"depth":258,"text":237},[264,265],"Essential entity","Vendor due diligence","md",[268,271,274,277,280,283],{"q":269,"a":270},"Does NIS2 impose obligations on my vendors?","NIS2 requires entities in scope to manage the risk in their supply chain, which means assessing and monitoring their critical vendors. The directive does not bind vendors outside its scope directly, but those requirements are passed down to them contractually.",{"q":272,"a":273},"Do you have to assess every vendor?","No. Article 21 imposes a risk-based approach: effort must be proportionate to the criticality of the third party. What is expected at review is the justification of that proportionality, not a volume of assessments.",{"q":275,"a":276},"What evidence does a NIS2 review expect on the supply chain?","An inventory of third parties with justified criticality, dated assessments with the evidence received, and a record of decisions taken: compensating measures, remediation plans with deadlines, or walking away from the vendor.",{"q":278,"a":279},"How does CISAPP connect vendor assessment and NIS2?","Every vendor assessment campaign feeds the NIS2 framework directly: the answer received is tied to the relevant Article 21 measure, to the risk in the register and to the dependency map, with regulator-ready exports.",{"q":281,"a":282},"What if a vendor refuses to answer the questionnaire?","The refusal is itself information to record. The options are to rely on alternative evidence (certification, audit report, Trust Center), to impose compensating measures, or to qualify the risk and have it formally accepted.",{"q":284,"a":285},"Does a non-EU vendor change the obligations?","The obligations remain yours: the regulated entity must demonstrate control of its supply chain wherever the third party sits. A non-EU vendor does add data transfer questions under the GDPR.",[287,288,289,290],"NIS2 vendor compliance","NIS2 supply chain","supply chain NIS2","NIS2 vendor audit",{},true,null,"entreprise","nis2",[297,200,298],"Regulatory frameworks","Dependency mapping",[300,301],"tprm-saas","supply-chain-cybersecurity",{"title":105,"description":11},"nis2-vendor-compliance",[305],{"label":306,"url":307,"publisher":308,"date":309},"Directive (EU) 2022\u002F2555 (NIS2), Articles 21 and 23","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2022\u002F2555\u002Foj","EUR-Lex","2022-12-14","en\u002Fsolutions\u002Fnis2-vendor-compliance","Article 21 of NIS2 requires regulated entities to secure their supply chain. In practice that means three things: an inventory of third parties with justified criticality, dated assessments proportionate to that criticality, and traceable decisions. CISAPP ties those three to the NIS2 framework and produces the expected exports.","2026-08-16","i9MBfplwL9U2KsKOetSyxWGd-20-dSR-bldnz5FDWqk",1791391138831]