Compliance

NIS2 and third-party risk: supply-chain security obligations, mapped to TPRM

NIS2 is the EU's broad cybersecurity law for essential and important entities, and unlike DORA it reaches far beyond finance. Its supply-chain clause is short, but it makes third-party security a board-level legal duty across most of the economy. Here is what Article 21 actually asks for and how to operationalize it.

The NIS2 Directive (Directive (EU) 2022/2555) replaced the original 2016 NIS Directive and had a national transposition deadline of 17 October 2024. Because it is a directive, the binding rules live in each member state's implementing law, but the obligations they must contain are set by NIS2 itself. Where DORA is a finance-only regulation with highly specific ICT third-party mechanics, NIS2 is broad: it applies to essential and important entities across energy, transport, banking, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, and - as "important" entities - postal services, waste management, chemicals, food, manufacturing, digital providers, and research. Most medium and large organizations in these sectors are in scope, and they push the requirements onto suppliers by contract, so NIS2 reshapes vendor practice well beyond the entities directly named.

The supply-chain obligation (Article 21)

Article 21 requires in-scope entities to take "appropriate and proportionate technical, operational and organisational measures" to manage cybersecurity risk. Two parts speak directly to third-party risk:

Accountability, reporting, and penalties

Management bodies (Article 20) must approve the risk-management measures, oversee their implementation, and can be held liable for failures; members must also take cybersecurity training. This is what turns supply-chain security from an IT task into a board-level duty.

Incident reporting (Article 23) runs on a tight clock: an early warning to the national CSIRT or competent authority within 24 hours, a fuller incident notification within 72 hours, and a final report within one month. Because a significant incident at a supplier can be the triggering event, your program needs to learn about vendor incidents fast enough to meet these deadlines.

Penalties (Article 34) have real teeth: essential entities face fines up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher; important entities up to EUR 7 million or 1.4%.

Turning NIS2 into TPRM actions

An agentic, continuously-monitoring platform maps naturally onto these duties - keeping the supplier inventory current, assessing on observable evidence, and surfacing vendor incidents in time to report. Rescana is built for exactly that continuous, evidence-based model; the point is not the tool but that NIS2 makes per-supplier, ongoing assessment a legal baseline rather than a nice-to-have.

Frequently asked questions

What does NIS2 require for supply-chain and third-party security?

NIS2 (Directive (EU) 2022/2555) makes supply-chain security a mandatory baseline measure. Article 21(2)(d) requires in-scope entities to manage security in the relationships with their direct suppliers and service providers, and Article 21(3) requires them to account for the vulnerabilities of each supplier, the quality of the supplier's products and cybersecurity practices, and its secure-development procedures, while considering the EU-level coordinated risk assessments of critical supply chains under Article 22. In practice this means maintaining a supplier inventory, assessing suppliers on observable evidence rather than self-reported questionnaires alone, monitoring continuously, and putting security and incident-notification terms into contracts.

Who does NIS2 apply to?

NIS2 applies to 'essential' and 'important' entities across a wide set of sectors - including energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, and space (essential), plus postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research (important). It generally captures medium and large organizations in those sectors, with some entities in scope regardless of size. Because it is a directive, the exact scope is set by each member state's implementing law, but suppliers to in-scope entities are typically pulled in through contractual requirements even when not directly named.

How is NIS2 different from DORA for third-party risk?

DORA (Regulation (EU) 2022/2554) is finance-specific and highly prescriptive about ICT third-party risk - it mandates a Register of Information, pre-contract concentration-risk assessment, named contractual clauses, and EU oversight of critical ICT providers. NIS2 is far broader in scope (most sectors of the economy) but less prescriptive on mechanics: it makes supply-chain security a required risk-management measure, adds board accountability and strict incident-reporting timelines, but leaves more of the 'how' to the entity and to national implementing law. A financial entity can be subject to both; where they overlap, DORA is treated as the more specific regime for ICT third-party risk.

What are NIS2's incident-reporting timelines?

Under Article 23, an in-scope entity must submit an early warning to its national CSIRT or competent authority within 24 hours of becoming aware of a significant incident, a more detailed incident notification within 72 hours, and a final report within one month. Because a significant incident can originate at a supplier, a TPRM program needs to detect and triage vendor incidents quickly enough to meet the 24- and 72-hour deadlines, which is a strong argument for continuous monitoring rather than periodic questionnaires.