Why suppliers are a board-level NIS2 subject
Critical services increasingly depend on MSPs, hosting, SaaS, ERP, telecom, logistics and operational suppliers. A disruption can affect availability, integrity, confidentiality, safety and reporting obligations even when the organisation's own controls perform as designed.
The board therefore needs visibility of the dependencies that can create material impact and the arrangements used to control them.
Start with a critical-supplier list
Classify direct suppliers by service criticality, access, data, digital interconnectedness, concentration and recovery options. Use a small number of risk classes so that due diligence, contract requirements, review frequency and evidence remain proportionate.
- Which critical process depends on the supplier?
- Which systems, data, identities or locations can the supplier access?
- How quickly can service be restored or transferred?
- Which subcontractors and geographic dependencies matter?
- What is the impact of simultaneous or prolonged failure?
Questions to ask suppliers
Ask how security is governed, which standards and tests apply, how vulnerabilities and changes are handled, which incidents occurred, how continuity is exercised and what evidence is available. The response should relate to the service delivered, not only to the supplier's organisation in general.
For high-risk suppliers, clarify customer responsibilities, limitations and the process for addressing exceptions.
Contracts should cover cooperation and continuity
Include incident notification and update requirements, investigation support, recovery objectives, testing, audit information, subcontractors, data handling, change control and exit. Agreements work best when operational contacts and escalation routes are maintained alongside the legal text.
Assess assurance, incident notification and continuity together
Assurance supports board judgement when the evidence matches the delivered service, relevant period and critical dependency. Certificates, SOC reports and audits form part of the picture alongside incident arrangements, recovery tests, open findings and demonstrated follow-up.
- review scope, validity and exceptions in certificates and assurance reports;
- agree notification deadlines, updates, escalation and investigation support;
- connect RTO, RPO, backup and recovery tests to the critical business process;
- track findings, exceptions and remediation through to evidenced closure;
- report material residual risk and accepted deviations to the board.
The Dutch NCSC also explains how entities within scope may set proportionate requirements for direct suppliers and service providers.
Report the result to the board
Useful reporting shows the number and identity of critical suppliers, concentration and single points of failure, material exceptions, expiring assurance, incidents, continuity-test results, overdue remediation and accepted residual risk.
This supports targeted decisions without bringing every procurement detail into the boardroom.
Frequently asked questions
Which suppliers are critical under NIS2?
Those whose failure, compromise or slow recovery can materially affect critical services, systems, data, safety or continuity.
Must every supplier meet the same requirements?
No. Use risk classes and apply due diligence, contracts, evidence and review frequency proportionately.
What should supplier reporting include?
Critical dependencies, concentration, incidents, evidence, exceptions, continuity, overdue actions and residual risk.
Review your critical-supplier agenda
Training helps directors focus on material dependencies, assurance, incident agreements, continuity and accepted residual risk.
Discuss the appropriate training route