INDEPENDENT NIS2 RESOURCEGovernance · Resilience · ImplementationEU framework / national application
HomeRequirementsSupply-chain security
Article 21 / Requirement

Supply-chain security

Consider security-related aspects of relationships with direct suppliers and service providers within the risk-management measures.

What this means in practice

Translate the provision into accountable decisions and documented processes. The exact application depends on the entity, the relevant national law and any applicable sector-specific rules.

Implementation questions

  1. Identify critical direct suppliers
  2. Review contract and assurance evidence
  3. Plan for supplier incidents and continuity

Evidence to organise

RecordWhat to check
Supplier inventoryOwner, currency, approval and follow-up actions
Due diligence recordsOwner, currency, approval and follow-up actions
Contract and remediation registerOwner, currency, approval and follow-up actions
These are planning prompts, not an exhaustive legal checklist or proof of compliance.

Official sources and context

Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.