Supply Chain Security Under NIS2

NIS2 measure area four extends your responsibility to your suppliers. How to build supplier risk assessment, contractual requirements and continuous oversight.

Of the ten mandatory NIS2 measures, the fourth, supply chain security, is the one that catches most organisations off guard. Not because it is hard to understand, but because it imposes a responsibility that did not previously exist: your accountability for your own security extends to suppliers who access your systems or deliver services into them.

What exactly is required

The law requires entities in scope to manage the security risks arising from their relationships with suppliers and service providers. That translates into three concrete obligations:

  1. Assess suppliers' security posture and the risk they represent.
  2. Enforce security requirements, typically through contracts.
  3. Monitor the supplier relationship throughout the contract lifecycle.

Scope has an important consequence: you remain accountable even if your supplier is not itself in NIS2 scope. A ten-person software development firm holding administrative access to your systems is your risk.

Start with a supplier inventory

The same rule applies as with assets: you cannot manage a risk you do not know about. Most organisations have no complete, current list of who has access to what.

A usable supplier register records:

  • supplier name, service description, contract reference,
  • what data they access, and at what sensitivity,
  • what systems they access, with what privileges, over what channel,
  • whether they have remote access, and how it is controlled,
  • whether they are replaceable within a reasonable timeframe (concentration risk),
  • the business impact if the service fails.

Procurement and IT often keep separate lists, and neither is complete. Shadow IT shows up here too: cloud services introduced by individual departments on a corporate card, with no contract and no security assessment.

Classify by risk

Not every supplier warrants the same treatment. An office supplies vendor is not the same risk as your managed service provider. A simple three-tier classification is sufficient for most organisations:

Tier Characteristics Expectation
Critical Administrative access, sensitive data, hard to replace Detailed assessment, audit rights, annual review, incident notification obligation
Significant Limited access or important service Questionnaire self-assessment, certifications on file, biennial review
Standard No system access, easily replaced Baseline contractual clauses

Base the classification on access and impact, not contract value. The most dangerous suppliers are often the cheapest: a small integrator who has been dialling in over VPN to maintain a piece of equipment for years.

What belongs in the contract

NIS2 expects enforcement, which in practice means contractual instruments. For critical suppliers, include:

Incident notification obligation, with a specific deadline. Make it stricter than your own 24-hour regulatory deadline, if your supplier tells you after 72 hours, you have already breached the law. A reasonable expectation is notification within 24 hours of an incident affecting you.

Baseline security requirements. MFA on access, logging of access, revocation when their staff leave, encryption of your data.

Audit or evidence rights. Either the right to audit on site, or presentation of a valid certification (ISO 27001, SOC 2), or a completed security questionnaire annually.

Transparency of subcontracting. To whom may they delegate work, and do the same terms apply there.

Exit terms. Data return and deletion, revocation of access, handover obligations.

Existing contracts need reviewing too. Most critical supplier contracts predate NIS2. The clauses have to be introduced at renewal or amendment, which means knowing when they expire. Put that in the register as well.

Get remote access under control

In practice this is the single largest concrete risk, and also the fastest to fix. The typical situation: every supplier connects with their own tooling: one over TeamViewer, one with their own VPN, one with a permanent site-to-site tunnel.

The goal is a single controlled entry point:

  • A central remote access solution that all external parties pass through.
  • Mandatory MFA, without exception.
  • On-demand activation, access closed by default, opened on request for a time window.
  • Session recording for critical systems.
  • Least privilege, the supplier reaches only what they must work on.

In OT environments this matters even more: remote channels used by machine builders and equipment suppliers are the most common routes onto the plant network.

Continuous oversight, not a one-off tick

The law requires risk management across the full contract lifecycle. A one-time onboarding assessment is not enough.

A sustainable rhythm:

  • Critical suppliers: annual reassessment, tracking certification expiry, a record of incidents they report.
  • Change management: if a supplier's access expands or they gain rights to a new system, reassess.
  • Exit process: actual revocation of access at contract end, this is what almost everyone forgets. It is worth running a quarterly review of active external accounts.

Measure whether it works

NIS2 measure area six requires measuring effectiveness. For supply chain, some usable indicators:

  • what percentage of critical suppliers hold a current security assessment,
  • how many contracts contain the mandatory clauses,
  • how long it takes for a departing supplier's access to be revoked,
  • how many active external accounts exist with no live contract.

That last indicator tends to produce the biggest surprise on first measurement.

What to do now

Starting from zero, this order delivers the fastest risk reduction:

  1. Build the supplier inventory, mapping access.
  2. Risk classification, the critical tier is typically 10–15% of suppliers.
  3. Audit active external access, and immediately revoke anything without a live contract.
  4. Channel remote access through a single MFA-protected point.
  5. Develop a contractual clause set and build it into renewals.
  6. Establish an annual review process with named owners.

The first three steps are achievable in a few weeks and cover most of the risk on their own. This is the area where compliance and actual security point most clearly in the same direction.

Our NIS2 compliance checklist walks through all ten measures, and our regulatory compliance service covers implementation tailored to industrial environments.

Back to Insights
Related content

Related content

Questions on this topic?

Our specialists are happy to discuss what this means in your organisation's environment.