NIS2 knowledge base

NIS2 supply chain: how to organise supplier governance that works

Effective supply-chain governance starts with direct dependencies and material impact. Classify suppliers proportionately, agree requirements, evaluate evidence and maintain recovery and exit options for the relationships that matter most.

Statutory scope and contractual supply-chain requirements

Direct statutory scope depends on sector, entity type, size, exceptions and designation. A supplier relationship by itself does not change that conclusion. Entities within scope must, however, manage supply-chain security and may pass relevant requirements to suppliers.

Keep the legal scope assessment separate from contractual and operational supply-chain obligations.

Make supply-chain risk visible to the board

The board needs a view of suppliers that can materially affect critical services or recovery. Map the dependency, access, concentration, alternatives, subcontractors and recovery time to the organisation's protected interests and risk appetite.

Cascade effects and concentration determine board-level impact

A supply-chain incident can affect several services and organisations at the same time. Disruption at one cloud platform, identity provider, MSP, telecom provider or shared software component may cascade into multiple critical processes and complicate recovery, communications and incident reporting.

Concentration risk arises when several critical processes depend on the same supplier, technology, region or subcontractor. Map shared dependencies, difficult-to-replace providers and material fourth parties alongside direct contracts.

  • identify critical processes that share a supplier or technical component;
  • locate single points of failure and limited alternatives;
  • trace subcontractors that recur across several relationships;
  • test scenarios in which one incident affects several services;
  • record which concentration risk the board accepts and why.

Use risk classes for direct suppliers

A practical three-level model can distinguish critical or high-risk suppliers, medium-risk suppliers and standard suppliers. Each class receives proportionate due diligence, contractual requirements, review frequency, assurance and contingency planning.

  • high risk: material service dependency, privileged access or difficult substitution;
  • medium risk: relevant access or impact with workable alternatives;
  • standard: limited digital connection and manageable impact.

Questions for boards and supervision

Which suppliers can stop critical services? Which evidence supports their control environment? Which incidents and exceptions exist? Are notification, recovery and exit arrangements tested? Where is concentration accepted and why?

These questions help the board focus on material dependency rather than the total number of vendors.

Maintain active supplier governance

Maintain ownership, service reviews, evidence, actions and decision points for critical suppliers. Integrate procurement, security, continuity, legal, risk and process ownership so that issues are addressed once and reported coherently.

Frequently asked questions

Do all suppliers need an audit?

No. Select assurance and review methods proportionately to dependency, access, impact and uncertainty.

What is a cascade effect in the NIS2 supply chain?

A cascade effect occurs when an incident at one supplier, platform or underlying party affects several services or organisations. Boards should therefore assess shared dependencies and concentration risk.

Can we use three supplier risk classes?

Yes. A simple high, medium and standard model can work well when criteria and resulting requirements are clear.

What is the first practical step?

Identify the direct suppliers whose failure or compromise can materially affect a critical service and assign an owner to each relationship.

Build active oversight of supplier risk

Use the boardroom session to classify critical dependencies, agree proportionate requirements and define useful reporting.

Discuss the appropriate training route