RegTech

NIS2 Supply Chain Security: What Organisations Must Do

IgeraSolutions Compliance Team
June 17, 2026
9 min read
NIS2 y Seguridad de la Cadena de Suministro: Obligaciones para Empresas EU
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

Article 21(2)(d) of NIS2 requires essential and important entities to implement supply chain security measures covering ICT suppliers, MSPs and sub-contractors. From October 2024, contractual clauses, risk assessments and monitoring are mandatory.

✓ Citing current regulationsSee detailed guide below ↓
RegTech · NIS2 Compliance

NIS2 and Supply Chain Security: What EU Organisations Must Do (Directive 2022/2555)

By IgeraSolutions Compliance Team · Updated June 2026 · 8 min read

Under Article 21(2)(d) of the NIS2 Directive (2022/2555/EU), essential and important entities must implement supply chain security measures addressing risks posed by ICT suppliers, service providers and sub-contractors. This obligation has applied across all EU Member States since October 2024 and carries penalties of up to €10 million or 2% of global annual turnover for essential entities that fail to comply.

Definition

Supply chain security (NIS2): the set of risk management measures an entity must apply to its direct suppliers and service providers, including contractual requirements, security assessments and monitoring of the security posture of ICT vendors and managed service providers. Defined within the broader Article 21 risk management framework, it encompasses both technical and organisational controls applied at the boundary between the entity and its external ICT dependencies.

Key Statistic

62%

of significant cyber incidents in EU critical infrastructure in 2024 originated in or were facilitated by supply chain compromises.

Source: ENISA Threat Landscape 2025

Assess Your NIS2 Supply Chain Posture

IgeraRegTech maps your ICT supplier inventory against Article 21 obligations and generates a gap report in minutes — not weeks of manual analysis.

Explore IgeraRegTech →
In summary
  • Article 21(2)(d) of NIS2 applies to all essential and important entities regardless of sector, requiring active management of ICT supplier risk — not merely contractual tick-boxes.
  • The supply chain obligation extends to non-EU suppliers: geography is irrelevant; what matters is whether the supplier provides ICT services material to your regulated operations.
  • Minimum contractual requirements include incident notification, audit rights, security standards and sub-processor controls — equivalent in spirit to DORA Article 30, but without a statutory clause list.
  • A structured five-step programme — map, risk-rate, contract, assess and monitor — provides the documented evidence trail that supervisory authorities will seek during inspections.

IgeraRegTech NIS2 Supply Chain Module

Ask any NIS2 supply chain question. Receive the exact article, ENISA guidance reference and a concrete contractual action — cited, verifiable and ready to share with your legal team.

Try IgeraRegTech →

Editorial note · Last updated: June 2026 | Sources: NIS2 Directive 2022/2555/EU (Art. 21, 23, 32), ENISA NIS2 Implementation Guidance 2024, ENISA Threat Landscape 2025 | Author: IgeraSolutions Compliance Team. This article is for informational purposes and does not constitute legal advice. Consult qualified legal counsel for advice specific to your organisation.

#NIS2 supply chain security#NIS2 Article 21 suppliers#NIS2 ICT supply chain obligations#supply chain cybersecurity EU#NIS2 Directive 2022 2555 supply chain

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Digital Maturity Test for Property Management

Find out in 60 seconds how many hours you can free up for your team

Pregunta 1 de 3

How do you handle resident queries and incidents?

Was this article helpful?

🛡️IgeraRegTech2026 Diagnostic Matrix
GUÍA DESCARGABLE (TXT)

NIS2 & DORA 2026 Statutory Compliance Gap Assessment Matrix

Diagnostic tool for DPOs and CISOs: essential vs important entity classifier, 10 mandatory risk management measures under NIS2 Art. 21, and DORA ICT third-party rules.

  • Automatic entity classification based on revenue and sector thresholds
  • Real-time compliance scoring with automated remediation action roadmap
  • Mandatory 24h/72h cybersecurity incident alert templates for authorities

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network