NIS2 Article 21(2)(d) requires essential and important entities to address security in their supply chain — specifically including the security of relationships between each entity and its direct suppliers or service providers. This creates contractual requirements that flow in both directions: NIS2-regulated entities must impose security obligations on their suppliers, and suppliers selling to regulated entities must be prepared to accept them.
The NIS2 Supply Chain Security Requirement
NIS2 Article 21(2)(d) includes supply chain security as one of the mandatory risk management measures. The Recitals and ENISA guidance clarify what this means in practice:
- Essential and important entities must assess the security posture of their direct ICT suppliers
- This assessment must consider overall security practices, the existence of vulnerability disclosure policies, and patch management practices
- The entity must address supply chain risks in its ICT risk management framework
- Contracts with direct ICT suppliers must address the security requirements flowing from this assessment
This does not mean entities must audit every supplier to the same depth. A risk-based approach applies: the depth of due diligence and contractual requirements should reflect the criticality of the supplier to the entity's core operations.
What NIS2 Supply Chain Contracts Must Address
For Essential and Important Entities (the Buyers)
When contracting with ICT suppliers, NIS2-regulated entities should include:
Security requirements:
- Minimum security standards the supplier must maintain (aligned with NIS2 Article 21 requirements)
- Incident notification obligations — timeline and scope for notifying the customer of security incidents
- Vulnerability management — how the supplier identifies and patches vulnerabilities in the services provided
- Access control — how the supplier controls access to the entity's data and systems
Audit and assessment rights:
- Right to conduct or commission security assessments of the supplier
- Right to request evidence of security controls (certifications, penetration test results)
- Right of regulators to access supplier information in the context of a supervisory review
Sub-contractor management:
- Disclosure of sub-contractors with access to the entity's data or systems
- Obligation on the supplier to impose equivalent security requirements on sub-contractors
- Notification before sub-contractor changes
Incident cooperation:
- How the supplier supports the entity's incident response if the supplier's service is involved
- Whether the supplier's incident logs and forensic data are accessible to the entity
- Timeline for root cause analysis following incidents
Termination and exit:
- Data return or deletion on termination
- Exit assistance to avoid dependency on a single supplier creating security continuity risks
What Suppliers Must Be Prepared to Accept
If your product is sold to organisations in NIS2-regulated sectors (energy, transport, finance, health, digital infrastructure), your customers will impose supply chain security requirements. Based on the NIS2 framework and the compliance programmes of regulated entities, expect customers to require:
In your contracts:
- Incident notification within 24 hours (some customers require 4 hours for critical incidents)
- Sub-processor/sub-contractor disclosure with change notification
- Audit rights — including right to conduct or commission third-party security assessments
- Security standards commitments aligned with NIS2 Article 21 categories: access control, cryptography, vulnerability management, BCP
- Data location specification
- Cooperation with the customer's competent authority
In your due diligence responses:
- Evidence of security certification (ISO 27001, SOC 2)
- Current penetration test evidence
- Incident response process documentation
- Business continuity plan summary
- Sub-processor/sub-contractor list
Tiered Supply Chain Approach
NIS2 does not require every supplier to be audited at the same depth. A tier-based approach is both practical and appropriate:
Tier 1 — Critical suppliers: Suppliers with access to the entity's most sensitive data or whose failure would immediately disrupt critical operations
- Full security questionnaire
- Contractual security requirements as above
- Annual review or on-site assessment for highest-criticality suppliers
- Evidence of ISO 27001 or equivalent required
Tier 2 — Important suppliers: Suppliers providing services relevant to operations but not immediately critical
- Abbreviated security questionnaire
- Contractual incident notification and sub-processor disclosure
- Evidence of security practice (SOC 2, penetration testing)
Tier 3 — Standard suppliers: Commodity suppliers with no access to sensitive data
- Standard security questionnaire
- Basic contract terms
- No detailed security assessment required
Sector-Specific Supply Chain Requirements
Some NIS2-regulated sectors have additional supply chain contract requirements layered on top of the base NIS2 requirements:
Financial services: DORA supply chain obligations (Register of Information, Article 30 contract clauses, concentration risk monitoring) apply alongside NIS2. Financial entities satisfy NIS2 through DORA as lex specialis.
Energy: ENTSO-E and national energy regulatory frameworks may add grid security requirements to supply chain contracts.
Health: National health system procurement rules and clinical safety regulations may add requirements beyond NIS2 supply chain provisions.
Digital infrastructure / cloud: Cloud providers themselves may be essential entities under NIS2, subject to both the buyer and supplier NIS2 obligations simultaneously.
Practical Steps for Suppliers
-
Build a standard security addendum for enterprise contracts covering the NIS2 supply chain requirements above — this accelerates the qualification process for regulated customers
-
Maintain a current sub-processor list with a change notification process — this is required both under NIS2 supply chain requirements and GDPR
-
Achieve ISO 27001 or SOC 2 certification — regulated entities increasingly require evidence of structured security practice, not just contractual commitments
-
Document your incident notification process — you need a defined process for notifying customers of incidents affecting their services, with specific timelines
-
Prepare for audit cooperation — have a defined process for responding to customer security assessments, including what information you will and will not share