How does the NIS2 Directive address cybersecurity in supply chains?

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive places significant importance on strengthening cybersecurity within supply chains, recognizing that the vulnerabilities of suppliers and service providers can pose substantial risks to essential and important entities. If you want to better understand what the main objective of the NIS2 Directive is, you can read more in our dedicated article.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

Here is how the directive addresses this issue:

Mandatory Measures for Supply Chain Security

  • Risk Management Requirements: The directive mandates that essential and important entities implement appropriate and proportionate cybersecurity risk management measures, which explicitly include addressing risks in their supply chains and supplier relationships.
  • Supplier Assessment: Entities are required to assess the cybersecurity practices of their suppliers and service providers, analyzing the potential impact of suppliers on the security of their own network and information systems.

Risk-Based Approach to Supply Chain Security

  • Tailored Measures: Entities must adopt a risk-based approach to the security of their supply chains, considering factors such as the sensitivity of data handled by suppliers, the criticality of the services provided, and the suppliers’ access to the entity’s systems.
  • Prioritization: By identifying and prioritizing risks associated with different suppliers, entities can effectively allocate resources to mitigate the most significant threats.

Coordinated Risk Assessments

  • EU-Level Assessments: The directive provides for coordinated assessments of critical supply chain security at the EU level. These assessments, conducted in collaboration with Member States and ENISA, aim to identify systemic risks and dependencies that could affect multiple entities or sectors.
  • Informed Policy Decisions: The results of these assessments help inform policy decisions and the development of guidelines to improve supply chain security across the EU.

Vulnerability Management and Disclosure

  • Coordinated Vulnerability Disclosure: NIS2 introduces a framework for coordinated vulnerability disclosure, encouraging entities to report vulnerabilities in ICT products and services to a designated national CSIRT or to the affected suppliers.
  • Role of CSIRTs: Member States must designate a national CSIRT to act as a trusted intermediary in vulnerability disclosure processes, facilitating communication between entities and suppliers to ensure that vulnerabilities are addressed in a timely manner.
  • European Vulnerability Database: ENISA is tasked with establishing and maintaining a European vulnerability database, which collects and shares information on vulnerabilities, enhancing transparency and awareness among entities and suppliers.

Information Sharing and Cooperation

  • Collaborative Efforts: The directive encourages entities to engage in information-sharing activities, including with their suppliers and service providers. This collaborative approach aims to improve collective awareness of cybersecurity threats and best practices.
  • Trusted Communities: By participating in trusted information-sharing communities, entities can receive timely updates on emerging threats that may affect their supply chains.

Cybersecurity Requirements in Procurement

  • Inclusion of Security in Contracts: Entities are encouraged to incorporate cybersecurity requirements into contractual agreements with suppliers. This may involve setting security standards, requiring compliance with specific certifications, or stipulating incident reporting obligations. For organizations that need to structure this process, starting a structured NIS2 compliance path helps translate these obligations into concrete and documentable actions.
  • Due Diligence: Before engaging suppliers, entities should perform due diligence to assess their cybersecurity posture, ensuring that suppliers meet the necessary security criteria.

Awareness and Training

  • Supply Chain Awareness: Entities must promote cybersecurity awareness not only within their organization but also throughout their supply chains. This includes providing guidelines and training to suppliers on security expectations and practices.

Regulatory Oversight

  • Supervisory Authorities: National competent authorities have the power to oversee entities’ compliance with supply chain security obligations, including conducting audits and inspections related to supply chain practices. In Italy, ACN manages the list of NIS2 entities and compliance deadlines.
  • Enforcement Measures: Failure to adequately manage cybersecurity risks in the supply chain can lead to enforcement actions, including administrative fines.

By incorporating these measures, the NIS2 Directive aims to strengthen the overall cybersecurity posture of essential and important entities by ensuring that supply chain risks are managed effectively. The directive promotes a culture of security that extends beyond individual organizations to encompass the entire supply chain, recognizing that cybersecurity is a shared responsibility in an interconnected digital ecosystem. To consult the full text, the official NIS2 Directive document is available.

Frequently Asked Questions about Supply Chain Security in NIS2

  • Which suppliers fall under the scope of NIS2 supply chain obligations?
  • The directive does not set a size threshold for suppliers but requires essential and important entities to assess all suppliers and service providers that have access to their systems or handle sensitive data. Priority should be given to suppliers critical to operational continuity or information security.
  • How is compliance with supply chain security obligations demonstrated?
  • Entities must document risk assessments of suppliers, security requirements included in contracts, and due diligence activities performed. Competent authorities may request this documentation during audits or inspections.
  • What happens if a supplier does not meet the required security standards?
  • The entity subject to NIS2 remains responsible for its own security posture even in the event of supplier non-compliance. It may be necessary to revise the contract, request corrective measures, or, in more serious cases, terminate the relationship with the supplier to reduce risk exposure.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In