Skip to main content
NIS2 SUPPLIER RISK

Your suppliers' risk is your risk under Article 21.

NIS2 Article 21(2)(d) requires entities to address supply-chain security, including the security-relevant aspects of relationships with direct suppliers and service providers.

In plain terms: your suppliers' risk is your risk, and you are the one who has to show what you did about it. A questionnaire spreadsheet ages the day it is filed — the supplier's estate changes, the contract changes, the threat changes — which is why the obligation reads as a standing register, not an annual audit.

Who these duties bind

Every in-scope entity, through the security-relevant aspects of its direct supplier and service-provider relationships. Article 22 adds the collective view: the EU can assess critical supply chains as a whole, so concentration in one provider becomes visible beyond any single entity's register.

What it asks, in operating terms

NIS2 supplier risk · how TruSecure answers it
What Article 21(2)(d) asksWhere it is answered
Know your direct suppliers and what they touchSupplier risk register · one record per supplier, services linked to functions
Assess the security-relevant aspects of each relationshipSupplier risk register · assessed, owned, dated
Keep the record current as relationships changeEvidence automation · continuously refreshed, not annually re-filed
See concentration before a supervisor names itSupplier risk register · concentration flagged by provider
Answer the same question under DORA without re-doing itSupplier risk register · same records populate the DORA register of information

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a supplier register is made of:

NIS2 supplier register · excerptSample data
Direct suppliers
34 · services mapped to functions
Assessments current
31 · 3 refresh due this quarter
Concentration flags
1 · under review
Feeds
NIS2 Art. 21(2)(d) · DORA register of information
Evidence
sealed · sha256:e08a…53d7

Where teams usually start

With a demo walked through by TruSecure — the supplier register, an assessment with its evidence chain, and the export an examiner or a DORA ICT examination will ask for. Onboarding then builds the first register from your actual contracts and connections; the subscription keeps it continuous.

Sovereignty

Article 21(2)(d) makes your suppliers your problem, and Article 22 lets the EU assess critical supply chains collectively. TruSecure has one sub-processor, in the EEA, with none discontinued in the last 24 months — which makes it the shortest chain you will assess this year.

See the whole chain

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 Article 21(2)(d) requires entities to address supply-chain security, including the cybersecurity practices of direct suppliers and service providers. TruSecure maintains one continuous supplier risk register that also feeds DORA's register of information where applicable.