← Course outline
Aavistus Training · nis2 · NIS.05

Supply-chain security

What you'll learn

Why supplier risk is a legal obligation, what the supply-chain measure requires of direct-supplier relationships, and the Union-level coordinated risk assessments of critical supply chains.

Regulation — cited to the current EU text

Why supplier risk is a legal obligation

NIS2 does not treat supply-chain security as advisory. Member States are required to ensure that essential and important entities take appropriate and proportionate technical, operational, and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or service provision, and to prevent or minimise the impact of incidents on recipients of their services and on other services 32022L2555 Article 21@2022-12-27. That obligation covers a named, minimum list of measure categories, and supply chain security appears explicitly on that list 32022L2555 Article 21@2022-12-27. An entity that omits it is not applying a narrower interpretation of the law; it is failing a statutory floor.

When assessing whether implemented measures are proportionate, the directive requires that account be taken of the entity's exposure to risks, its size, and the likelihood and severity of incidents — including their societal and economic impact 32022L2555 Article 21@2022-12-27. This means a large operator of critical infrastructure cannot invoke cost alone to evade supply-chain obligations; the scale of potential harm pulls proportionality toward more, not fewer, controls.

What the supply-chain measure requires of direct-supplier relationships

Article 21(2)(d) scopes the obligation to direct relationships: entities must address security-related aspects concerning relationships between themselves and their direct suppliers or service providers 32022L2555 Article 21@2022-12-27. The directive does not impose a blanket obligation to audit the full depth of a supply chain, but it does require structured attention to every direct link.

Article 21(3) specifies the content of that attention. When entities decide which measures under Article 21(2)(d) are appropriate, they must take into account:

  • the vulnerabilities specific to each direct supplier and service provider;
  • the overall quality of products and cybersecurity practices of those suppliers and service providers, including their secure development procedures;
  • the results of the coordinated security risk assessments of critical supply chains carried out in accordance with Article 22(1).

32022L2555 Article 21@2022-12-27

In practice this means the entity cannot assess its supply-chain posture in the abstract. It must conduct per-supplier analysis: a supplier with a documented history of slow patch cycles or weak development hygiene warrants stricter contractual controls or additional compensating measures than one with demonstrably strong secure-development practices. The "overall quality" framing also signals that assessments should be forward-looking and ongoing, not a one-off checkbox at contract signature.

If an entity finds that it is not complying with any of the Article 21(2) measures — including supply-chain security — it must take all necessary, appropriate, and proportionate corrective measures without undue delay 32022L2555 Article 21@2022-12-27.

Union-level coordinated risk assessments of critical supply chains

Beyond entity-level obligations, NIS2 establishes a coordinated mechanism at Union level. The Cooperation Group, in cooperation with the Commission and ENISA, may carry out coordinated security risk assessments of specific critical ICT services, ICT systems, or ICT products supply chains, taking into account both technical and, where relevant, non-technical risk factors 32022L2555 Article 22@2022-12-27. The inclusion of non-technical risk factors is significant: geopolitical dependencies, concentration risk in a single supplier country, or strategic ownership structures can all legitimately inform a coordinated assessment.

The Commission identifies which ICT services, systems, or products may be subject to such assessments, after consulting the Cooperation Group, ENISA, and where necessary relevant stakeholders 32022L2555 Article 22@2022-12-27. This creates a structured pipeline: Union institutions surface the highest-risk categories; those categories then receive collective scrutiny that no single Member State could replicate alone.

The results of these coordinated assessments are not merely informational. Article 21(3) explicitly requires entities to take those results into account when determining what measures under Article 21(2)(d) are appropriate 32022L2555 Article 21@2022-12-27. This closes the loop between Union-level intelligence and entity-level decision-making: a coordinated risk assessment identifying a specific supplier category or product as high-risk becomes a mandatory input into each affected entity's supply-chain security calculus.

Taken together, Articles 21 and 22 build a two-tier architecture: a per-entity obligation to assess and manage direct-supplier risk, and a Union-level coordination mechanism that aggregates intelligence on systemic supply-chain threats and feeds it back down to entities as binding context for their own measures.

Your operations manual

This block connects to your organisation's own information-security policies (ISMS). In the full product it shows, cited to your policy set, how YOUR organisation implements the obligation above — private to your organisation. (Demo placeholder.)

Real-world context — illustrative only

The items below are labeled illustrative context drawn from open sources; they are not regulatory authority and do not modify or interpret the NIS2 obligations described above.

Rising attack volume. Industry analysts have noted a sustained increase in supply-chain attack activity, driving measurable growth in demand for dedicated supply-chain security tooling and services CASE-1. This confirms that the threat model Article 21(2)(d) addresses is active and worsening, not theoretical.

Geopolitical dimension of software supply chains. Commentary in the security community has drawn attention to the geopolitical character of software supply-chain risk — specifically, how the origin and ownership of software components creates non-technical exposure vectors CASE-2. This aligns with Article 22's explicit inclusion of non-technical risk factors in coordinated supply-chain assessments.

Market response in detection tooling. Purpose-built platforms for software supply-chain security have gained industry recognition, reflecting the maturation of a product category aimed at the kind of per-supplier vulnerability and development-practice assessment that Article 21(3) requires of entities CASE-3. The existence of dedicated tooling does not substitute for the legal obligation, but it indicates that the technical means to fulfil it are available.

Check your understanding

1. Under Article 21(2)(d), which supplier relationships must an entity address when implementing supply-chain security measures?

2. When assessing whether supply-chain security measures are proportionate, which factors does NIS2 require to be taken into account?

3. Article 21(3) lists factors an entity must take into account when deciding which supply-chain measures are appropriate. Which of the following appears on that list?

4. Under Article 22, who identifies which ICT services, systems, or products may be subject to a coordinated security risk assessment at Union level?

5. What is the legal status of results produced by a coordinated supply-chain risk assessment carried out under Article 22(1)?