Supply chain responsibility under NIS2: why managing your suppliers Is more important than ever

The NIS2 Directive introduces new requirements for organizations that must be able to demonstrate that their cybersecurity is under control. This goes beyond securing your own organization. Under NIS2, supply chain responsibility also plays a key role. Organizations must understand the cyber risks associated with suppliers, IT service providers, cloud providers and other supply chain partners, and take appropriate measures to manage those risks.

As a result, supply chain responsibility is no longer optional. It is an essential part of NIS2 compliance. The directive affects nearly every sector, including healthcare, energy, government, transportation, manufacturing and financial services. In this article, Kiwa cybersecurity expert Rutger Fugers takes a closer look at what this means in practice for organizations across different industries and the steps they need to take to gain control of their supply chain and comply with NIS2.

What does supply chain responsibility mean under NIS2?

Under NIS2, supply chain responsibility means that organizations are responsible not only for their own information security, but must also be able to demonstrate that they have control over the cybersecurity of suppliers and other supply chain partners. This form of supply chain security is an important part of the directive. This does not mean you are liable for every cyber incident involving a supplier. However, you must be able to demonstrate that suppliers are carefully selected, assessed and monitored, and that appropriate security requirements have been defined.

Properly assessing cyber risks

In practice, this means that you must thoroughly assess suppliers for cyber risks, include security requirements in contracts and periodically verify that those requirements are being met. Organizations should also establish agreements covering incident reporting, business continuity and recovery after a cyber incident. After all, just one weak link in the supply chain can have serious consequences for your own organization. Examples include a ransomware attack at an IT service provider, a vulnerability in a cloud platform or unauthorized access through an external maintenance provider.

Why is supply chain responsibility under NIS2 so important?

More and more organizations depend on external parties for their IT operations. Software is delivered as a service, data is stored in the cloud and critical business processes rely on systems from multiple suppliers. As a result, organizations often have limited visibility across the entire supply chain. At the same time, existing contracts do not always include clear cybersecurity requirements for suppliers and many suppliers rely on subcontractors over whom you have even less visibility. Unauthorized applications and unsupported (shadow) IT also increase the risk. NIS2 is intended to eliminate these blind spots. Organizations are expected to gain ongoing insight into their digital dependencies and implement appropriate controls to achieve NIS2 compliance.

Supply chain responsibility under NIS2 by sector

Although the principles of NIS2 are the same for every organization, the implementation differs by sector.

  • In healthcare, the focus is on securing electronic health records, medical devices, laboratory systems and external IT service providers. Organizations must be able to demonstrate that suppliers comply with standards such as ISO 27001 and NEN 7510, and that agreements are in place for patch management, monitoring and incident response.
  • In the energy and utilities sector, operational technology, ICS and SCADA systems, and external maintenance providers play a central role. Strict access controls, business continuity agreements and regular supplier audits are essential.
  • In the financial sector, the supply chain requirements of NIS2 complement existing regulations such as DORA. Cloud providers, payment processors and other critical IT suppliers must be continuously monitored, with clear agreements covering incident reporting and risk management.
  • Government organizations often work with a large number of suppliers and complex IT environments. As a result, supply chain transparency, minimum security requirements in procurement processes and regular reviews are becoming increasingly important.
  • Transportation and logistics also rely heavily on digital supply chains, for example for planning, tracking and IoT applications. International collaboration requires clear agreements on data security, availability and incident handling.
  • In manufacturing, production environments and operational technology are the primary focus. External suppliers often have access to machinery or production systems, making access management, documentation of dependencies and business continuity plans indispensable.

NIS2 also places requirements on suppliers

The NIS2 Directive affects more than just organizations that fall directly within its scope. Many suppliers are also facing stricter requirements because their customers need to demonstrate that the entire supply chain is digitally resilient. Organizations are therefore increasingly requesting evidence that suppliers have implemented appropriate cybersecurity measures. Examples include certifications such as ISO 27001 or NEN 7510, security questionnaires, audit reports and clear agreements covering incident reporting and access management. In this way, the requirements of NIS2 extend throughout the entire supply chain.

How can you meet the supply chain responsibility requirements of NIS2?

A good approach starts with gaining insight into your supply chain. Which suppliers support your critical business processes? Which cloud or SaaS solutions are in use? Which external parties have access to your systems or data? The next step is to classify suppliers based on risk. Not every supplier requires the same level of assessment. A cloud provider or managed service provider requires a much more extensive evaluation than an office supplies vendor. Once suppliers have been classified, minimum security requirements can be established and included in contracts. These may cover access management, patch management, incident reporting and business continuity. By periodically reviewing your supplier management processes and continuously monitoring suppliers, you maintain control over cyber risks across your supply chain and can clearly demonstrate your progress toward NIS2 compliance.

Getting started with your NIS2 compliance

Supply chain responsibility is one of the most significant changes introduced by the NIS2 Directive. Cybersecurity does not stop at the boundaries of your organization. It extends across your entire digital supply chain. Organizations that invest in visibility, effective supplier management and continuous monitoring are not only better positioned to meet the supply chain responsibility requirements of NIS2, but also strengthen their overall cyber resilience.

NIS2 support from Kiwa

Would you like to know how well your organization meets the requirements of NIS2? Kiwa supports you with services including a NIS2 gap assessment, training programs and independent audits. These services provide insight into your current level of compliance and help you identify the steps needed to better protect both your organization and your supply chain. Would you like to learn more about Kiwa's NIS2 services? Contact our experts. They will be happy to assist you.  

Contact

Learn more?

Would you like to know more about this topic? Call us at +31 (0)88 998 33 70 or fill out the contact form. Our experts will be happy to help you!

Go to contact form