Auditen
Home / Frameworks / NIS2 / Supply chain security
NIS2 · Art. 21(2)(d)

Supply chain security

Supply chain security requires organizations to manage and mitigate risks stemming from their direct suppliers and service providers. It mandates a proactive approach to ensuring that third-party products, software, and services do not introduce vulnerabilities into the organization's own infrastructure.

What it means

The intent of this requirement is to address "indirect" security threats. Because modern organizations rely heavily on external vendors for cloud hosting, managed services, and specialized software, a vulnerability in a supplier’s environment can become a backdoor into your own.

In practice, the scope extends beyond simple procurement. It covers the entire lifecycle of the relationship: from initial due diligence and selection to ongoing monitoring and secure offboarding. You must treat critical suppliers as an extension of your own attack surface.

This also includes focusing on the quality and integrity of the products themselves. This means ensuring that hardware is authentic and software is free from known vulnerabilities or malicious injections before it is deployed in your environment.

How to meet it

Evidence an auditor asks for

  • A register/inventory of third-party suppliers categorized by their risk level to the organization.
  • Completed security assessment questionnaires or due diligence reports for key vendors.
  • Signed contracts or Service Level Agreements (SLAs) containing specific cybersecurity obligations and liability clauses.
  • Records of periodic vendor reviews, including evidence of follow-ups on identified gaps in a supplier's security.

Common pitfalls

  • "Set and forget" onboarding: Conducting a security check only once at the start of a contract and failing to monitor the vendor over time.
  • Overlooking Shadow IT: Failing to apply supply chain controls to SaaS tools purchased by individual departments outside of central procurement.
  • Lack of enforcement: Having strong security clauses in contracts but lacking a process to verify that the vendor is actually adhering to them.