How the NIS2 Directive defines and addresses “supply chain security”

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive recognizes the importance of supply chain security in ensuring a high level of cybersecurity. This article analyzes how the Directive defines and addresses this aspect, with reference to the specific articles that regulate the obligations for essential and important entities. For a complete overview of the general purpose of the NIS2 Directive, it is useful to start from the objective that the regulation aims to achieve.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

The sources provide information on how the Directive defines and addresses this crucial aspect:

Definition of Supply Chain Security:

Although the NIS2 Directive does not provide an autonomous definition of “supply chain security,” its requirements regarding cybersecurity risk management clearly include the security of supply chains.

  • Article 21, Paragraph 2(d) establishes that entities designated as “essential” or “important” must implement cybersecurity risk management measures, which also include “supply chain security.”
  • This paragraph further specifies that such measures should take into account “security-related aspects concerning the relationships between each entity and its direct suppliers or service providers.”
  • This language highlights how the Directive recognizes the interconnection of cybersecurity risks within a supply chain and emphasizes the need for entities to proactively manage risks arising from their suppliers and service providers.

How to Manage Supply Chain Security:

The NIS2 Directive employs a multi-factorial approach to improve supply chain security:

  1. Risk Management at the Entity Level:
  • Supplier Due Diligence: Article 21, Paragraph 3, emphasizes the importance of due diligence when entities assess the adequacy of security measures adopted in the supply chain. Entities must consider the specific vulnerabilities of each direct supplier and service provider, taking into account:
    * Vulnerabilities Specific to the Individual Supplier.
    * General Cybersecurity Practices of Suppliers: Including their secure development procedures.
    * Results of Coordinated Risk Assessments: Entities must consider the results of any coordinated risk assessments conducted at the EU level, as indicated in Article 22, Paragraph 1.
  • Management of Non-Compliance: If an entity detects non-compliance with the required security measures, including aspects related to supply chain security, Article 21, Paragraph 4, imposes the obligation to implement appropriate corrective actions in a timely manner. This highlights the continuous nature of supply chain risk management and the need for constant monitoring and improvement.
  1. Coordinated Risk Assessments:
  • EU-Level Assessments: Article 22, Paragraph 1, allows the NIS Cooperation Group, in collaboration with the Commission and ENISA, to undertake “coordinated risk assessments of specific critical supply chains of ICT services, ICT systems, or ICT products.”
  • Focus on Critical Supply Chains: This provision gives the EU the ability to proactively identify and assess vulnerabilities in supply chains that are crucial to the Union’s cybersecurity.
  • Consideration of Technical and Non-Technical Factors: These coordinated risk assessments must take into account both technical and non-technical factors, emphasizing the importance of a holistic approach to supply chain security.
  • Identification of Critical ICT Products and Services: Article 22, Paragraph 2, clarifies that the Commission, in consultation with relevant stakeholders, will determine which ICT services, systems, or products are considered critical to the extent that they justify a coordinated risk assessment for their security.
  1. Promotion of Secure Development Practices:
  • Secure by Design and Default: Although not explicitly mentioned in the context of supply chain security, Article 21, Paragraph 2(e) refers to security in the “acquisition, development, and maintenance” of ICT systems. This indirectly promotes the adoption of “security by design and by default” principles throughout the entire supply chain.
  • Encouragement of the Use of Certifications: Article 24 promotes the use of cybersecurity certification schemes established by the Cybersecurity Act (Regulation (EU) 2019/881). By promoting the use of certified cybersecurity products, services, and processes, the Directive indirectly incentivizes the adoption of more robust security practices among suppliers within the supply chain.

In conclusion, the NIS2 Directive integrates supply chain security as a fundamental element of its cybersecurity risk management framework. It emphasizes a proactive and continuous approach, requiring entities to assess and address risks arising from their suppliers and service providers. The Directive also grants the EU the ability to carry out coordinated risk assessments of critical supply chains. For organizations that need to structure or verify their path to NIS2 Directive compliance, it is useful to start with an analysis of the measures already implemented and the gaps still open. You can also consult the official text of the NIS2 Directive to verify the cited provisions directly.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In