The NIS2 Directive (Directive (EU) 2022/2555) replaced the original 2016 NIS Directive and had a national transposition deadline of 17 October 2024. Because it is a directive, the binding rules live in each member state's implementing law, but the obligations they must contain are set by NIS2 itself. Where DORA is a finance-only regulation with highly specific ICT third-party mechanics, NIS2 is broad: it applies to essential and important entities across energy, transport, banking, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, and - as "important" entities - postal services, waste management, chemicals, food, manufacturing, digital providers, and research. Most medium and large organizations in these sectors are in scope, and they push the requirements onto suppliers by contract, so NIS2 reshapes vendor practice well beyond the entities directly named.
The supply-chain obligation (Article 21)
Article 21 requires in-scope entities to take "appropriate and proportionate technical, operational and organisational measures" to manage cybersecurity risk. Two parts speak directly to third-party risk:
- Article 21(2)(d) names "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers" as a required measure. Supply-chain security is not optional or implied - it is one of the enumerated baseline measures every in-scope entity must implement.
- Article 21(3) tells entities how to do it: account for the vulnerabilities specific to each direct supplier and service provider, the overall quality of their products and cybersecurity practices, and their secure-development procedures - and to take into account the results of the EU-level coordinated security risk assessments of critical supply chains carried out under Article 22.
Accountability, reporting, and penalties
Management bodies (Article 20) must approve the risk-management measures, oversee their implementation, and can be held liable for failures; members must also take cybersecurity training. This is what turns supply-chain security from an IT task into a board-level duty.
Incident reporting (Article 23) runs on a tight clock: an early warning to the national CSIRT or competent authority within 24 hours, a fuller incident notification within 72 hours, and a final report within one month. Because a significant incident at a supplier can be the triggering event, your program needs to learn about vendor incidents fast enough to meet these deadlines.
Penalties (Article 34) have real teeth: essential entities face fines up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher; important entities up to EUR 7 million or 1.4%.
Turning NIS2 into TPRM actions
- Inventory and tier direct suppliers and service providers, flagging those supporting essential/important services - Article 21(3) is explicitly per-supplier.
- Assess supplier practices, not just paperwork: product quality, cybersecurity practices, and secure development - which favors evidence-based assessment over a self-reported questionnaire.
- Monitor continuously so posture changes and incidents surface in time to meet the 24/72-hour clock - see continuous vendor monitoring.
- Put it in contracts: security requirements, incident-notification timelines that let you meet Article 23, audit rights, and subcontractor flow-down.
- Keep an auditable trail and report to the board, since management is accountable under Article 20.
An agentic, continuously-monitoring platform maps naturally onto these duties - keeping the supplier inventory current, assessing on observable evidence, and surfacing vendor incidents in time to report. Rescana is built for exactly that continuous, evidence-based model; the point is not the tool but that NIS2 makes per-supplier, ongoing assessment a legal baseline rather than a nice-to-have.
Frequently asked questions
What does NIS2 require for supply-chain and third-party security?
NIS2 (Directive (EU) 2022/2555) makes supply-chain security a mandatory baseline measure. Article 21(2)(d) requires in-scope entities to manage security in the relationships with their direct suppliers and service providers, and Article 21(3) requires them to account for the vulnerabilities of each supplier, the quality of the supplier's products and cybersecurity practices, and its secure-development procedures, while considering the EU-level coordinated risk assessments of critical supply chains under Article 22. In practice this means maintaining a supplier inventory, assessing suppliers on observable evidence rather than self-reported questionnaires alone, monitoring continuously, and putting security and incident-notification terms into contracts.
Who does NIS2 apply to?
NIS2 applies to 'essential' and 'important' entities across a wide set of sectors - including energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, and space (essential), plus postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research (important). It generally captures medium and large organizations in those sectors, with some entities in scope regardless of size. Because it is a directive, the exact scope is set by each member state's implementing law, but suppliers to in-scope entities are typically pulled in through contractual requirements even when not directly named.
How is NIS2 different from DORA for third-party risk?
DORA (Regulation (EU) 2022/2554) is finance-specific and highly prescriptive about ICT third-party risk - it mandates a Register of Information, pre-contract concentration-risk assessment, named contractual clauses, and EU oversight of critical ICT providers. NIS2 is far broader in scope (most sectors of the economy) but less prescriptive on mechanics: it makes supply-chain security a required risk-management measure, adds board accountability and strict incident-reporting timelines, but leaves more of the 'how' to the entity and to national implementing law. A financial entity can be subject to both; where they overlap, DORA is treated as the more specific regime for ICT third-party risk.
What are NIS2's incident-reporting timelines?
Under Article 23, an in-scope entity must submit an early warning to its national CSIRT or competent authority within 24 hours of becoming aware of a significant incident, a more detailed incident notification within 72 hours, and a final report within one month. Because a significant incident can originate at a supplier, a TPRM program needs to detect and triage vendor incidents quickly enough to meet the 24- and 72-hour deadlines, which is a strong argument for continuous monitoring rather than periodic questionnaires.