NIS2 measure area four extends your responsibility to your suppliers. How to build supplier risk assessment, contractual requirements and continuous oversight.
Of the ten mandatory NIS2 measures, the fourth, supply chain security, is the one that catches most organisations off guard. Not because it is hard to understand, but because it imposes a responsibility that did not previously exist: your accountability for your own security extends to suppliers who access your systems or deliver services into them.
The law requires entities in scope to manage the security risks arising from their relationships with suppliers and service providers. That translates into three concrete obligations:
Scope has an important consequence: you remain accountable even if your supplier is not itself in NIS2 scope. A ten-person software development firm holding administrative access to your systems is your risk.
The same rule applies as with assets: you cannot manage a risk you do not know about. Most organisations have no complete, current list of who has access to what.
A usable supplier register records:
Procurement and IT often keep separate lists, and neither is complete. Shadow IT shows up here too: cloud services introduced by individual departments on a corporate card, with no contract and no security assessment.
Not every supplier warrants the same treatment. An office supplies vendor is not the same risk as your managed service provider. A simple three-tier classification is sufficient for most organisations:
| Tier | Characteristics | Expectation |
|---|---|---|
| Critical | Administrative access, sensitive data, hard to replace | Detailed assessment, audit rights, annual review, incident notification obligation |
| Significant | Limited access or important service | Questionnaire self-assessment, certifications on file, biennial review |
| Standard | No system access, easily replaced | Baseline contractual clauses |
Base the classification on access and impact, not contract value. The most dangerous suppliers are often the cheapest: a small integrator who has been dialling in over VPN to maintain a piece of equipment for years.
NIS2 expects enforcement, which in practice means contractual instruments. For critical suppliers, include:
Incident notification obligation, with a specific deadline. Make it stricter than your own 24-hour regulatory deadline, if your supplier tells you after 72 hours, you have already breached the law. A reasonable expectation is notification within 24 hours of an incident affecting you.
Baseline security requirements. MFA on access, logging of access, revocation when their staff leave, encryption of your data.
Audit or evidence rights. Either the right to audit on site, or presentation of a valid certification (ISO 27001, SOC 2), or a completed security questionnaire annually.
Transparency of subcontracting. To whom may they delegate work, and do the same terms apply there.
Exit terms. Data return and deletion, revocation of access, handover obligations.
In practice this is the single largest concrete risk, and also the fastest to fix. The typical situation: every supplier connects with their own tooling: one over TeamViewer, one with their own VPN, one with a permanent site-to-site tunnel.
The goal is a single controlled entry point:
In OT environments this matters even more: remote channels used by machine builders and equipment suppliers are the most common routes onto the plant network.
The law requires risk management across the full contract lifecycle. A one-time onboarding assessment is not enough.
A sustainable rhythm:
NIS2 measure area six requires measuring effectiveness. For supply chain, some usable indicators:
That last indicator tends to produce the biggest surprise on first measurement.
Starting from zero, this order delivers the fastest risk reduction:
The first three steps are achievable in a few weeks and cover most of the risk on their own. This is the area where compliance and actual security point most clearly in the same direction.
Our NIS2 compliance checklist walks through all ten measures, and our regulatory compliance service covers implementation tailored to industrial environments.
Full NIS2 directive compliance readiness: gap analysis, implementation roadmap, documentation and audit…
Regulatory Compliance (OT-specific service. NIS2, IEC 62443, ISO 27019) verifiable compliance instead of risk.
A practical NIS2 checklist: determining whether you are in scope, the ten mandatory measures, incident…
Our specialists are happy to discuss what this means in your organisation's environment.