NIS2 knowledge base

NIS2 suppliers: contracts, risk and board-level control

Supplier risk becomes manageable when the organisation knows which dependencies are critical, agrees proportionate requirements, evaluates meaningful evidence and reports material exceptions and decisions to the board.

Why suppliers are a board-level NIS2 subject

Critical services increasingly depend on MSPs, hosting, SaaS, ERP, telecom, logistics and operational suppliers. A disruption can affect availability, integrity, confidentiality, safety and reporting obligations even when the organisation's own controls perform as designed.

The board therefore needs visibility of the dependencies that can create material impact and the arrangements used to control them.

Start with a critical-supplier list

Classify direct suppliers by service criticality, access, data, digital interconnectedness, concentration and recovery options. Use a small number of risk classes so that due diligence, contract requirements, review frequency and evidence remain proportionate.

  • Which critical process depends on the supplier?
  • Which systems, data, identities or locations can the supplier access?
  • How quickly can service be restored or transferred?
  • Which subcontractors and geographic dependencies matter?
  • What is the impact of simultaneous or prolonged failure?

Questions to ask suppliers

Ask how security is governed, which standards and tests apply, how vulnerabilities and changes are handled, which incidents occurred, how continuity is exercised and what evidence is available. The response should relate to the service delivered, not only to the supplier's organisation in general.

For high-risk suppliers, clarify customer responsibilities, limitations and the process for addressing exceptions.

Contracts should cover cooperation and continuity

Include incident notification and update requirements, investigation support, recovery objectives, testing, audit information, subcontractors, data handling, change control and exit. Agreements work best when operational contacts and escalation routes are maintained alongside the legal text.

Assess assurance, incident notification and continuity together

Assurance supports board judgement when the evidence matches the delivered service, relevant period and critical dependency. Certificates, SOC reports and audits form part of the picture alongside incident arrangements, recovery tests, open findings and demonstrated follow-up.

  • review scope, validity and exceptions in certificates and assurance reports;
  • agree notification deadlines, updates, escalation and investigation support;
  • connect RTO, RPO, backup and recovery tests to the critical business process;
  • track findings, exceptions and remediation through to evidenced closure;
  • report material residual risk and accepted deviations to the board.

The Dutch NCSC also explains how entities within scope may set proportionate requirements for direct suppliers and service providers.

Report the result to the board

Useful reporting shows the number and identity of critical suppliers, concentration and single points of failure, material exceptions, expiring assurance, incidents, continuity-test results, overdue remediation and accepted residual risk.

This supports targeted decisions without bringing every procurement detail into the boardroom.

Frequently asked questions

Which suppliers are critical under NIS2?

Those whose failure, compromise or slow recovery can materially affect critical services, systems, data, safety or continuity.

Must every supplier meet the same requirements?

No. Use risk classes and apply due diligence, contracts, evidence and review frequency proportionately.

What should supplier reporting include?

Critical dependencies, concentration, incidents, evidence, exceptions, continuity, overdue actions and residual risk.

Review your critical-supplier agenda

Training helps directors focus on material dependencies, assurance, incident agreements, continuity and accepted residual risk.

Discuss the appropriate training route