NIS2 knowledge base

NIS2 supply-chain responsibility: what boards must organise

Supply-chain responsibility means that an entity within scope understands how direct suppliers can affect its network and information systems, services and continuity, and manages that risk through proportionate selection, agreements, evidence and follow-up.

What does NIS2 supply-chain responsibility mean?

The Dutch Cybersecurity Act requires entities within scope to include the security of their supply chain in risk-management measures. The organisation remains responsible for its own service and cannot outsource that responsibility with the technology or process.

This does not make every supplier a NIS2 entity. It does mean that the customer should understand the dependency, agree relevant requirements and maintain enough evidence to govern the risk.

Which suppliers and dependencies are critical?

A supplier becomes board-relevant when failure, compromise or slow recovery can materially affect critical services, safety, data, finance or trust. Digital interconnectedness, privileged access, concentration, substitutability and recovery time are often more informative than annual spend.

  • access to systems, identities, data or operational technology;
  • dependency of a critical process or recovery capability;
  • limited alternatives, long transition time or strong concentration;
  • subcontractors or locations that create hidden dependencies;
  • material incident, continuity or regulatory impact.

Contractual requirements for critical suppliers

Contracts should translate the risk into workable obligations. Security requirements are most useful when they cover scope, ownership, evidence and cooperation rather than repeating a generic promise to be secure.

Address access, vulnerability handling, secure changes, incident notification, investigation support, continuity, recovery, audit information, subcontractors, data return and exit. Align supplier notification timelines with the customer's own statutory reporting timeline.

Assurance: use evidence that fits the dependency

Certifications and assurance reports can provide valuable evidence. Review their scope, period, exclusions, user controls and exceptions. For the most critical dependencies, combine documents with service reviews, technical evidence, exercises or targeted audits where proportionate.

The objective is a supported conclusion about the service that matters, not the collection of the largest possible number of documents.

Incident reporting, continuity and exit

Agree who contacts whom, which information is shared, how quickly early signals are escalated and how updates continue during an incident. Exercise the process so the customer retains time for its own assessment and reporting.

Continuity requires recovery objectives, tested alternatives and a realistic exit or transition route. Management reporting should show the critical supplier population, material exceptions, incidents, test results, overdue actions and accepted residual risk.

Questions for executive and supervisory boards

These questions keep supply-chain risk connected to service continuity, governance and proportionate follow-up.

  • Which suppliers can interrupt our critical services?
  • Which evidence supports management's conclusion about their controls?
  • Are incident timelines and cooperation compatible with our obligations?
  • Which alternatives, recovery arrangements and exit scenarios have been tested?
  • Which exceptions and concentration risks require a decision?

Frequently asked questions

Does NIS2 make every supplier directly subject to the law?

No. Direct scope follows from the Act. Customers within scope can pass proportionate security and continuity requirements through contracts.

Which supplier should receive the most attention?

Prioritise suppliers whose failure or compromise can materially affect critical services, data, safety or recovery.

Is an ISO 27001 certificate sufficient assurance?

It can be valuable evidence. Review the scope, exclusions, period and relevance to the service and supplement it where the risk warrants this.

Which supplier information should reach the board?

A concise view of critical suppliers, concentration, incidents, evidence, exceptions, test results, continuity and decisions.

Put critical dependencies on the board agenda

The Masterclass turns supplier risk into questions about contracts, evidence, incidents, continuity, exit and decision-making.

Discuss the appropriate training route