YarifyStart a conversation

NIS2 supply-chain risk assessment, built for uneven enforcement

Article 21(2)(d) has required supply chain security since October 2024 — but national transposition is still fragmented enough that the Commission is now taking Member States to court over it. Build vendor risk assessment that holds up regardless of where your suppliers, or you, are headquartered.

Classification drives both your obligations and your leverage

Whether you're essential, important, or out of direct scope shapes what you owe regulators — and what you can reasonably demand from suppliers. Get this right before designing a vendor questionnaire.

ClassificationTypical triggerPenalty ceiling
Essential entityLarge organization (250+ employees, or over €50M turnover / €43M balance sheet) in an Annex I high-criticality sector; proactive ex-ante supervisionUp to €10 million or 2% of global annual turnover, whichever is higher
Important entityMedium-sized organization (50+ employees, or over €10M turnover) in an Annex I or II sector; reactive supervisionUp to €7 million or 1.4% of global annual turnover, whichever is higher
Captured regardless of sizeTrust service providers, DNS providers, TLD name registries, and certain other critical entitiesSame tiers as above, based on essential/important status
Out of direct scopeBelow-threshold organizations not in Annex I/II sectors — but often still pulled in as a supplier to an in-scope entityNo direct NIS2 fine, but contractual security obligations flow down from customers

Even a company outside direct NIS2 scope is routinely pulled into this framework as a supplier — an in-scope customer's own Article 21(2)(d) obligation means it has to assess you. Directive (EU) 2022/2555.

Supply chain is one of ten mandatory measures, not a standalone box

Article 21(2) lists ten categories of measures every in-scope entity must address; none can be skipped entirely, though how much you invest in each is proportionate to your risk. Supply chain security sits alongside — and depends on — several of the others.

(a) Risk analysis & policy

Risk analysis and information-security policies underpin every other measure, including how you assess suppliers.

(b) Incident handling

Detection, response and reporting — including incidents that originate at a supplier.

(c) Business continuity

Backup, disaster recovery and crisis management, factoring in supplier dependencies.

(d) Supply chain security

The measure this page is built around — assessing and managing your direct suppliers and service providers.

(e) Secure acquisition & development

Security in acquiring, developing and maintaining systems, including vulnerability handling.

(f) Effectiveness assessment

Policies to test whether your risk-management measures actually work, not just that they exist on paper.

(g) Cyber hygiene & training

Basic practices and staff training — including for people who manage vendor relationships.

(h) Cryptography

Policies on the use of cryptography and encryption.

(i) HR security & access control

Human resources security, access control and asset management — directly relevant to what suppliers can touch.

(j) MFA & secure comms

Multi-factor or continuous authentication, and secured voice/video/text and emergency communications.

Most companies don't get a fixed checklist — and that's the point

Commission Implementing Regulation (EU) 2024/2690 turns Article 21(2) into 150+ specific controls — but only for a named list of digital-infrastructure entity types. Everyone else works from the general obligation and non-binding ENISA guidance.

Who the CIR binds

DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, CDN providers, managed service providers, managed security service providers, online marketplaces, online search engines, social networking platforms, and trust service providers.

What that means for a SaaS or manufacturing vendor

If you don't fall into one of those categories, no EU regulation hands you a numbered control list — 'appropriate and proportionate' is your own documented judgment call, informed by ENISA's guidance.

What that means for the vendors you assess

A vendor that IS a cloud, MSP or marketplace provider can be held to the CIR's specific controls — a vendor questionnaire can reasonably ask about CIR-aligned practices for that category of supplier.

Where ENISA guidance fits

ENISA's Technical Implementation Guidance mirrors the CIR's structure and gives non-binding but practical detail — useful as a design reference even where the CIR itself doesn't legally apply.

Read the CIR's scope carefully before assuming its 150+ controls apply to your organization or your suppliers. Commission Implementing Regulation (EU) 2024/2690 and ENISA Technical Implementation Guidance.

"NIS2 applies" isn't a single EU-wide fact

The directive set an 18 October 2024 transposition deadline. Nearly two years later, enforcement is still uneven enough that the Commission escalated to court action against four Member States — a genuinely current development, not historical background.

Where transposition stands

Roughly two-thirds of Member States had completed transposition as of mid-2026, with several — including some of the largest economies — still finalizing national legislation.

The CJEU referral

On 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for still not having fully transposed NIS2 — with financial sanctions requested. Commission press release.

Build per-jurisdiction tracking, not a single switch

A vendor risk tool that treats "NIS2 in force: yes/no" as one global flag will be wrong for some fraction of your suppliers. Track each supplier's jurisdiction and that jurisdiction's actual transposition status — and don't use "our supplier is in a country that hasn't transposed yet" as a reason to skip the assessment your own obligation still requires.

A real assessment goes past a self-attestation form

"Appropriate and proportionate" means the depth of assessment should match what a supplier can actually touch or break — not a uniform questionnaire sent to every vendor regardless of risk.

Vendor inventory & tiering

Build a complete supplier register first — you can't assess risk you haven't inventoried — then tier by access, criticality and data sensitivity.

Access and blast radius

What systems, data or processes can this supplier actually reach, directly or through the software they provide?

Fourth-party dependency

Does the supplier itself rely on subcontractors or sub-processors whose failure would cascade to you?

Evidence over attestation

For higher-tier vendors, request evidence — audit reports, penetration test summaries, incident history — not just checkbox answers.

Contractual flow-down

Security requirements, incident-notification timelines and audit rights belong in the contract, not just the questionnaire.

Concentration risk

Flag where multiple critical functions depend on the same supplier or the same underlying infrastructure provider.

Automate the workflow, not the judgment

Chasing hundreds of suppliers by email doesn't scale — that part is worth automating. Deciding whether a supplier's answers actually reduce your risk still needs a defined scoring methodology behind the automation, not just faster paperwork.

Tiered questionnaire versions

Different question depth by vendor tier — a payment processor doesn't get the same three questions as an office-supplies vendor.

Mapped to Article 21(2)

Questions trace to specific measures (a)–(j), with CIR-aligned depth for vendors the CIR actually covers.

Automated distribution and reminders

Scheduled sends, escalating reminders, and a clear non-response path instead of manual follow-up.

Defined scoring methodology

A documented, versioned scoring rubric — not an ad hoc judgment call that changes reviewer to reviewer.

Evidence requests for high-risk tiers

Automatically flag high-tier vendors for evidence beyond self-attestation, and track whether it was actually provided.

Escalation workflow

Non-responsive or high-risk vendors route to a defined escalation path — not a spreadsheet cell that just says 'overdue.'

Controls a management body can actually stand behind

NIS2 puts approval and oversight of risk-management measures on the management body. The tool needs to produce something they can review and sign off on, not just a dashboard full of green checkmarks.

Inventory completeness control

Reconcile the supplier register against actual accounts-payable and access-management records — an incomplete inventory undermines everything downstream.

Questionnaire version control

Track which questionnaire version each vendor response corresponds to, so scoring stays comparable over time.

Evidence retention

Retain submitted evidence, not just pass/fail scores, so a finding can be reviewed months later.

Re-assessment cadence control

Enforce tier-based review schedules and trigger-based re-assessment on material change events.

Escalation SLA

Track time-to-resolution for flagged high-risk or non-responsive vendors against a defined SLA.

Management reporting

Produce a periodic summary a management body can actually review and formally approve, with an audit trail of that approval.

Tier your highest-risk suppliers first

Prove the process — inventory, tier, assess, score, escalate, report — on your highest-criticality suppliers before rolling the same workflow out across the full vendor list.

  1. Confirm your own classification

    Determine essential/important status, applicable sectors, and whether the CIR applies to you directly as a digital-infrastructure provider.

  2. Build the supplier inventory

    Reconcile suppliers against accounts-payable and access records; tier by access, criticality and data sensitivity.

  3. Design tiered questionnaires

    Map questions to Article 21(2) measures, with CIR-aligned depth for vendors it covers, and a documented scoring rubric.

  4. Automate distribution and tracking

    Implement scheduled sends, reminders, and a non-response escalation path.

  5. Add evidence collection for top tiers

    Require audit reports or equivalent evidence beyond self-attestation for your highest-risk suppliers.

  6. Report to the management body

    Produce a periodic summary for formal review and approval, with an audit trail of that sign-off.

Acceptance criteria for the assessment system

Risk-tiered

Assessment depth scales with a supplier's access and criticality, not a single questionnaire for everyone.

Traceable to Article 21(2)

Every question maps to a specific measure, with CIR-aligned depth where a vendor is actually covered by it.

Evidence-backed for top tiers

High-risk vendor scores rest on retained evidence, not unverified self-attestation alone.

Jurisdiction-aware

Supplier jurisdiction and its transposition status are tracked, not assumed uniform across the EU.

Escalation-capable

Non-responsive or high-risk vendors route to a defined escalation path with an SLA.

Board-reportable

The system produces a summary a management body can formally review and approve, with an audit trail.

NIS2 vendor risk FAQ

Is NIS2 actually enforceable if my country hasn't finished transposing it?

The directive itself has applied at EU level since 18 October 2024, but a directive generally takes legal effect against private entities through each Member State's own transposing law — and transposition is uneven. As of this page's 2 September 2026 review, roughly two-thirds of Member States had completed transposition, while the Commission had referred Ireland, Spain, France and the Netherlands to the Court of Justice for still not having done so. Practically: check whether your own Member State's NIS2 law is actually in force, and don't assume a supplier headquartered in a non-transposed country is automatically unregulated — its own national timeline may differ from yours.

Does the Commission Implementing Regulation give us a fixed checklist to hand suppliers?

Only if your supplier is one of the specific entity types the regulation covers — DNS providers, TLD registries, cloud, data centre, CDN, managed service and managed security service providers, online marketplaces, search engines, social networking platforms, and trust service providers. For everyone else, Article 21(2)(d)'s supply chain obligation applies without that level of prescribed detail, so 'appropriate and proportionate' measures are a judgment call informed by ENISA's non-binding guidance and your own risk assessment, not a fixed checklist.

Are we 'essential' or 'important' under NIS2, and does it matter for a vendor tool?

Essential entities are generally large organizations (250+ employees, or over €50 million turnover / €43 million balance sheet) in Annex I high-criticality sectors, facing proactive supervision and fines up to €10 million or 2% of global turnover. Important entities are typically medium-sized organizations in Annex I or II sectors, facing reactive supervision and fines up to €7 million or 1.4% of turnover. Some entity types — trust service providers, DNS providers, TLD registries, certain critical infrastructure — are captured regardless of size. Classification affects your own obligations directly and shapes how rigorously you should expect (and can demand) supply-chain assurance from your suppliers.

Can we just require every supplier to hold ISO 27001 and call it compliant?

A certification is useful evidence, not a substitute for an assessment. NIS2's supply chain obligation asks you to assess the security posture of your direct suppliers and service providers in the context of your own risk exposure — a generic ISO 27001 certificate doesn't tell you whether a specific supplier's access to your systems, the criticality of what they provide, or their own sub-supplier dependencies create risk you haven't accounted for. Use certifications as one input to a tiered, risk-based assessment, not as the whole assessment.

Who's personally accountable if our supply-chain risk management fails?

NIS2 puts approval and oversight of cybersecurity risk-management measures on the entity's management body, and Member States' transposing laws generally carry through some form of accountability for that body when measures are neglected. Build the vendor risk process so management-level approval and periodic review are documented events, not something that only exists in a compliance team's inbox.

How often should vendor risk assessments actually be re-run?

Tie the cadence to risk tier and to trigger events, not a fixed annual calendar alone. A vendor with privileged access to critical systems warrants more frequent review than a low-risk supplier; either way, a material change — a breach disclosure, an ownership change, a new subcontractor, or a significant scope change in what they provide you — should trigger an out-of-cycle reassessment rather than waiting for the next scheduled one.

Is questionnaire automation actually useful, or just faster paperwork?

It's only useful if it changes what happens with the answers. Automating distribution, reminders and response tracking solves a real operational problem — chasing hundreds of suppliers by email doesn't scale — but the value is in automated risk scoring against your own criteria, evidence requests beyond self-attestation for higher-risk vendors, and escalation workflows for non-responsive or high-risk suppliers. A faster way to collect unverified self-attestations isn't a risk-management improvement.

Primary sources and status

Reviewed 2 September 2026. NIS2 (Directive (EU) 2022/2555) has applied at EU level since 18 October 2024; national transposition remained incomplete in several Member States on the review date, including four referred to the Court of Justice on 8 July 2026. Commission Implementing Regulation (EU) 2024/2690 binds only the specific digital-infrastructure entity types it names. ENISA guidance is non-binding. Yarify's assessment methodology and delivery sequence are engineering recommendations, not legal advice — confirm your classification and national obligations with qualified counsel.

  1. Directive (EU) 2022/2555 — NIS2 Directive, Article 21Binding cybersecurity risk-management obligation, including supply chain security under Article 21(2)(d), applicable at EU level since 18 October 2024
  2. Commission Implementing Regulation (EU) 2024/2690Binding technical and methodological detail for Article 21(2) measures, but only for DNS, cloud, data centre, CDN, managed (security) service, marketplace, search engine, social platform and trust service providers
  3. ENISA — Technical implementation guidance on cybersecurity risk management measures, v1.0Non-binding ENISA guidance mirroring the CIR annex structure, with practical implementation examples and evidence expectations
  4. European Commission — press release IP/26/1499Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to fully transpose NIS2, 8 July 2026
  5. ENISA Threat Landscape 2025ENISA's annual analysis of the EU cyber-threat environment, including supply chain and third-party compromise trends
  6. European Commission — NIS2 Directive policy pageOfficial Commission overview of NIS2 scope, sectors, supervision tools and national transposition tracking

Send us your supplier list and current process.

Tell us your entity classification, roughly how many suppliers you work with, and how vendor risk gets assessed today — spreadsheet, email, nothing formal. We'll scope the smallest tiered assessment system that gets your highest-risk suppliers covered first.