BLOG · GUIDE ·

NIS2 supply chain security: what customers ask their IT suppliers and the evidence that answers it

Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software

IN BRIEF
  • NIS2’s risk-management measures apply to essential and important entities, and Article 21(2)(d) makes supply chain security one of them, so a supplier outside the directive’s scope meets NIS2 as questionnaires, contract clauses and requests for evidence from in-scope customers
  • Article 21(3) has customers take into account the vulnerabilities specific to each direct supplier, the overall quality of their suppliers’ products and cybersecurity practices, including secure development procedures, and the results of coordinated risk assessments of critical supply chains under Article 22(1)
  • Point 5.1.4 of the Annex to Implementing Regulation (EU) 2024/2690 lists, where appropriate, contract clauses on security requirements, staff skills and background checks, incident notification without undue delay, audit rights, vulnerability handling, subcontracting and exit; it binds the digital infrastructure, ICT service and digital providers listed in its Article 1
  • Supplier questionnaires ask about MFA, privileged accounts, access to the customer’s systems, backups and restore tests, incident notification time, patching, subcontractors and certificates, and each answer should point to a dated document such as a configuration export or a test report
  • The directive covers entity types listed in its Annexes I and II from medium-sized enterprises upwards under Recommendation 2003/361/EC, plus some types and cases regardless of size; managed service providers, defined in Article 6(39), are among the listed types

Eurokommerz × Vixen.UNO: Cyber Resilience  Talk to an expert →

How NIS2 supply chain security reaches IT suppliers outside its scope

Article 21 of NIS2 requires Member States to ensure that essential and important entities take security measures. Point (d) of the article’s paragraph 2 lists among the minimum measures “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”. A supplier outside the directive’s scope therefore meets NIS2 through its customers’ third-party risk management. That risk management reaches the supplier as a security questionnaire, a security annex to the contract or a request for evidence such as a restore test report. Under Article 21(3), those customers take into account “the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures”. Our guide to NIS2 Article 21 security measures covers all ten measures.

Commission Implementing Regulation (EU) 2024/2690 details this in point 5 of its Annex: a supply chain security policy with selection criteria and contract clauses (point 5.1) and a directory of suppliers (point 5.2). The regulation binds the entities listed in its Article 1, among them cloud computing, data centre and managed service providers. ENISA wrote its technical implementation guidance of June 2025 for those entities. ENISA adds that, beyond them, its indications “may be considered useful by other public or private bodies for improving their cybersecurity”.

Which companies NIS2 covers: sectors and the medium-sized threshold

Article 2(1) applies the directive to entities of a type listed in its Annex I or II. Such an entity must qualify as a medium-sized enterprise under Commission Recommendation 2003/361/EC or exceed the ceilings for medium-sized enterprises. It must also provide services or carry out activities in the Union. The recommendation defines a small enterprise as one that “employs fewer than 50 persons and whose annual turnover and/or annual balance sheet total does not exceed EUR 10 million”. Staff are counted in annual work units. A listed entity that is not small therefore meets the size test. The recommendation’s ceilings for medium-sized enterprises are fewer than 250 persons and an annual turnover not exceeding EUR 50 million and/or an annual balance sheet total not exceeding EUR 43 million. Under Article 6 of the recommendation’s Annex, the data of partner and linked enterprises are added, so a subsidiary is not measured on its own figures alone. Recital 16 of the directive lets Member States take into account an entity’s independence from its partner or linked enterprises, for example in its network and information systems. Article 2(2) to (4) of the directive cover some types and cases regardless of size, among them trust service providers and DNS service providers.

Annex I point 9 lists managed service providers and managed security service providers. Article 6(39) defines a managed service provider as an entity providing services by assistance or active administration on customers’ premises or remotely. The services relate to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications or other network and information systems. Both types of provider are also relevant entities under Article 1 of the implementing regulation. An IT service company in scope as one of them therefore applies point 5 of the Annex as binding law. Annex II point 5(b) covers manufacturers of computer, electronic and optical products. Whether a given company is in scope, and as which type of entity, is a legal assessment for its legal department.

Subcontractors and Article 22 coordinated risk assessments

Recital 85 of the directive says entities “should in particular be encouraged to incorporate cybersecurity risk-management measures into contractual arrangements with their direct suppliers and service providers”. It adds that entities “could consider risks stemming from other levels of suppliers and service providers”. Questions about subcontractors follow from the second point: a reseller or service company is the direct supplier, and its manufacturers, data centres and engineering partners sit one level down.

Under Article 22, the NIS Cooperation Group, with the Commission and ENISA, may carry out coordinated security risk assessments of critical supply chains. The Group does so “taking into account technical and, where relevant, non-technical risk factors”. Article 21(3) requires entities to take the results into account. Recital 90 refers to the assessment carried out for 5G networks and names non-technical factors such as “undue influence by a third country on suppliers and service providers”. On 13 February 2026 the Commission announced the Cooperation Group’s EU ICT Supply Chain Security Toolbox, with risk assessments of connected and automated vehicles and detection equipment. The Commission did not say whether these assessments fall under Article 22(1). Questions about a supplier’s ownership, where its staff work and its data is stored, and its dependence on one vendor address this non-technical side.

Contract clauses in Implementing Regulation 2024/2690, point 5.1

Point 5.1.1 requires a supply chain security policy in which the customer shall “identify their role in the supply chain and communicate it to their direct suppliers and service providers”. The selection criteria of point 5.1.2 cover the supplier’s cybersecurity practices including secure development and its ability to meet the customer’s cybersecurity specifications. They also cover the quality and resilience of the supplier’s products and services and the customer’s ability to diversify sources and limit vendor lock-in. Point 5.1.4 lists what contracts should specify, “where appropriate through service level agreements”, and qualifies the list with “where appropriate”.

POINT 5.1.4WHAT IT ASKS FORCHECK BEFORE SIGNING
(a) Security requirementscybersecurity requirements for the supplier, including those of point 6.1 on acquiring ICT products and serviceswhether it lists requirements or cites a whole standard, and which you meet today
(b) Skills and trainingawareness, skills, training and, where appropriate, certifications of the supplier’s employeeswhich roles it covers, how training is recorded
(c) Background checksverification of the background of the supplier’s employeeswhich staff it covers, what proof is expected
(d) Incident notificationnotice “without undue delay” of incidents that present a risk to the customer’s systemsthe time in hours, the channel, what counts as notifiable
(e) Audita right to audit or to receive audit reportsnotice, scope, frequency, whether a third-party report is accepted
(f) Vulnerability handlinghandling vulnerabilities that present a risk to the customer’s systemstarget times per severity, how advisories reach the customer
(g) Subcontractingrules on subcontracting and security requirements for subcontractorsnamed subcontractors, clauses passed on, notice before changes
(h) Exitobligations at termination, such as retrieval and disposal of informationreturn format, deletion confirmed in writing, access removed

Implementing Regulation (EU) 2024/2690, Annex, point 5.1.4. The right-hand column is our reading.

Point 5.1.6 has customers monitor changes in suppliers’ cybersecurity practices “at planned intervals” and after significant changes or incidents, so the questionnaire is repeated. Point 5.2 requires a registry with “contact points for each direct supplier and service provider” and what each provides. Name a security contact and list what you deliver. For components critical to the customer’s security, point 6.1.2 adds “requirements regarding security updates throughout the entire lifetime of the ICT services or ICT products, or replacement after the end of the support period”. It also adds “information describing the hardware and software components used”. A reseller answers these points from the manufacturer’s support policy and documentation.

NIS2 supplier questionnaire: the questions and the evidence for each

The questions below map to points of the Annex, and the evidence column names the dated documents that support each answer.

TOPICEXAMPLE QUESTIONANNEX POINTEVIDENCE
MFAIs MFA enforced for remote access, email and admin consoles?11.6, 11.7the policy, a configuration export showing enforcement, exceptions with reasons
Privileged accessAre admin accounts personal, separate and reviewed?11.3, 11.4admin accounts per person, separate admin identities, the last access review
Access to our systemsHow do your staff connect to our network?6.7.2(d), (h), 11.2.2(d)named accounts, access approved by the customer for a set period, MFA, logs
Backups and restore testsWhen did you last restore from backup?4.2.2, 4.2.6the backup plan, job logs, the last restore test report with date and time taken
Incident notificationWithin how many hours will you notify us?5.1.4(d), 3.3the incident procedure with its customer notification step, named contacts
Vulnerabilities, patchesHow fast do you fix critical vulnerabilities?5.1.4(f), 6.6, 6.10target times per severity, the last scan summary, the advisory channel
SubcontractorsWho else handles our data or reaches our systems?5.1.4(g)subcontractors with role and country, clauses passed on, the data processing agreement
CertificationsWhich certificates do you hold?5.1.2, 5.1.4(b)each certificate with holder, scope and expiry; staff certifications for named roles

Implementing Regulation (EU) 2024/2690, Annex points named; ENISA Technical Implementation Guidance, version 1.0 (June 2025), examples of evidence for point 4.2.2. The questions and the other evidence are our reading.

An export from the identity system shows what is enforced today, which a policy alone does not; our guides to phishing-resistant MFA and privileged access management cover those controls. For backups, ENISA’s examples of evidence under point 4.2.2 include “Backup plans” and “Logs from backup software that show regular backups are being performed”. Point 4.2.6 asks for regular recovery tests with documented results, as our NIS2 backup guide explains.

Under Article 23(4), an in-scope customer’s early warning to its CSIRT or competent authority is due within 24 hours of becoming aware of a significant incident. A supplier’s notice may be how the customer becomes aware, so a contract may set the notice in hours instead of “without undue delay”. Point 3.3.2 has customers communicate their event reporting mechanism to suppliers, and that channel belongs in your incident procedure; our article on NIS2 incident reporting covers the customer’s deadlines.

Our security and compliance assessment audits infrastructure, access, backups and compliance with NIS2 requirements, and ends with a risk map and a prioritised action plan. Send us the questionnaire you received and the answers you cannot yet support with evidence.

How a mid-size supplier prepares one evidence pack

A supplier with several in-scope customers gets the same questions in different templates, and one evidence pack, kept current, answers them all.

  1. Map each question in the questionnaires and security annexes received so far to an Annex point.
  2. Write a company sheet with the legal entity, a security contact, the incident notification channel and an exact list of what you supply.
  3. Describe how your staff reach customer systems: named accounts, MFA, approval by the customer for a set period, logging, removal of access when the work ends.
  4. File the evidence for each topic in the table above with its date: policy excerpt, configuration export, last test report, last review record.
  5. List subcontractors with role and country, and certificates with the entity that holds each, its scope and its expiry date.
  6. Mark each gap as planned, with a date, instead of answering yes for a control that is not in place.
  7. Update the pack after significant changes and before each planned re-assessment under point 5.1.6.

Network diagrams and penetration test reports can be shown under an NDA or in a review meeting rather than uploaded to a supplier portal. Answers attached to a contract can become commitments, so describe your systems as they are on the day you answer.

Certificates in a supplier assessment: holder and scope

Neither Article 21 nor point 5 of the implementing regulation’s Annex requires a supplier to hold an ISO/IEC 27001 certificate. Under point 5.1.2, each customer sets its own selection criteria. ENISA’s June 2023 report on supply chain cybersecurity draws on a 2022 survey of 1,081 organisations across the EU. In it, 61 % of the organisations said they “require security certification from suppliers”.

A certificate covers the legal entity and the scope written on it. A data centre operator’s ISO/IEC 27001 certificate therefore does not extend to a reseller or service company hosting systems there. An answer should name the entity that holds each certificate. Point 5.1.4(b) concerns certifications of the supplier’s employees, “where appropriate”, such as the vendor certifications of the engineers on a contract.

When Eurokommerz is the supplier on your list, we fill in your form and state precisely which entity holds which certificate. We hold no ISO certificate of our own and do not borrow our partner’s. Send us your supplier questionnaire through the form below.

General information on EU law as of October 2026, not legal advice for an individual case.

What we do

Under Cyber Resilience, our engineering partner Vixen.UNO audits infrastructure, access, backups and compliance with NIS2 requirements. You receive a NIS2 compliance map with the gaps listed and a plan to close them. The compliance map is a technical assessment. Implementation covers network segmentation, zero-trust access with multi-factor authentication and privileged access management, regular test restores and an incident response plan. The implementation is rolled out step by step in agreed maintenance windows with a rollback plan. The price of the technical assessment is fixed before work begins, and we do not issue compliance certificates. As a supplier, we sign an NDA before technical detail, provide a data processing agreement on request and name subprocessors in the contract, as our security and compliance page sets out.

FAQ

Does NIS2 apply to suppliers?
NIS2 applies to a supplier directly only under one of two conditions. Either the supplier is itself an entity of a type listed in Annex I or II and at least a medium-sized enterprise, or it falls under a case covered regardless of size. For IT companies the entries to check are managed service providers and managed security service providers. Article 6(39) defines managed service providers as entities providing services related to the installation, management, operation or maintenance of ICT products, networks, infrastructure or applications, on customers’ premises or remotely. Companies that host systems should also check the cloud computing and data centre service provider entries. Otherwise the requirements reach the supplier as questionnaires, contract clauses and requests for evidence from in-scope customers. This is because Article 21(2)(d) and 21(3) cover the security of the customers’ relationships with direct suppliers and service providers.
What does NIS2 require for supply chain security and third-party risk?
Article 21(2)(d) lists supply chain security among the minimum measures, including the security-related aspects of each entity’s relationships with its direct suppliers and service providers. Article 21(3) requires entities to take into account the vulnerabilities specific to each direct supplier and service provider. Entities must also take into account the overall quality of products and cybersecurity practices of their suppliers and service providers, including secure development procedures. The same applies to the results of coordinated risk assessments of critical supply chains under Article 22(1). For the digital infrastructure, ICT service and digital providers it covers, Implementing Regulation (EU) 2024/2690 adds a supply chain security policy, contract clauses and a directory of suppliers.
What is in a NIS2 supplier questionnaire?
Questionnaires ask about topics such as multi-factor authentication, privileged accounts and how the supplier’s staff reach the customer’s systems. They also ask about backups and restore tests, incident notification time, vulnerability and patch management, subcontractors and certificates. These topics map to points of the Annex to Implementing Regulation (EU) 2024/2690, chiefly the contract clauses of point 5.1.4 and the access control rules of point 11. Each topic is answered with dated evidence. Examples are a configuration export, an access review record, a restore test report, the incident procedure, a subcontractor list and certificates showing holder and scope.
Which contract clauses does NIS2 require with suppliers?
The directive’s articles name no specific clauses. Recital 85 of the directive says entities should be encouraged to put cybersecurity risk-management measures into contracts with their direct suppliers and service providers. For the entities it covers, Implementing Regulation (EU) 2024/2690 point 5.1.4 lists, where appropriate, cybersecurity requirements, staff skills, training and certifications, background checks and incident notification without undue delay. The list also includes a right to audit or to receive audit reports, vulnerability handling, subcontracting rules and obligations at termination. ENISA’s June 2025 guidance on that regulation notes that its indications may be useful to other public or private bodies as well.
How quickly must a supplier notify a customer of an incident under NIS2?
The directive sets no deadline for suppliers. For the entities it covers, Implementing Regulation (EU) 2024/2690 point 5.1.4(d) asks contracts to oblige suppliers to notify incidents that present a risk to the customer’s systems without undue delay. A customer may turn this into a fixed number of hours. This is because the customer’s own early warning to the CSIRT or competent authority is due within 24 hours of becoming aware of a significant incident under Article 23(4). The agreed time, the channel and what counts as a notifiable incident belong in the contract.
Does a supplier need ISO 27001 certification for NIS2?
Neither Article 21 of the directive nor point 5 of the implementing regulation’s Annex requires a supplier to hold an ISO/IEC 27001 certificate. Each customer sets its own selection criteria. Customers may still ask for one: in the survey behind ENISA’s June 2023 report on supply chain cybersecurity, 61 % of organisations said they require security certification from suppliers. That figure names no particular standard. Where a certificate is held by a partner, such as a data centre operator, the answer should name the entity that holds it and the scope it covers.

Send us the questionnaire or security annex your customer sent, with a short note on how your company handles MFA, admin accounts, backups and incidents today. We reply within one business day with a date for a first call, on which we work through your situation and infrastructure, and you leave with two or three possible solution scenarios. The first call is free of charge.

Talk to an expert
Talk to an expert

We reply within one business day

By sending this form you agree that we process your details to answer your enquiry – see our privacy policy.

request@eurokommerz.at
Jordangasse 7, 1010 Vienna