Your suppliers' risk is your risk under Article 21.
NIS2 Article 21(2)(d) requires entities to address supply-chain security, including the security-relevant aspects of relationships with direct suppliers and service providers.
In plain terms: your suppliers' risk is your risk, and you are the one who has to show what you did about it. A questionnaire spreadsheet ages the day it is filed — the supplier's estate changes, the contract changes, the threat changes — which is why the obligation reads as a standing register, not an annual audit.
Who these duties bind
Every in-scope entity, through the security-relevant aspects of its direct supplier and service-provider relationships. Article 22 adds the collective view: the EU can assess critical supply chains as a whole, so concentration in one provider becomes visible beyond any single entity's register.
What it asks, in operating terms
| What Article 21(2)(d) asks | Where it is answered |
|---|---|
| Know your direct suppliers and what they touch | Supplier risk register · one record per supplier, services linked to functions |
| Assess the security-relevant aspects of each relationship | Supplier risk register · assessed, owned, dated |
| Keep the record current as relationships change | Evidence automation · continuously refreshed, not annually re-filed |
| See concentration before a supervisor names it | Supplier risk register · concentration flagged by provider |
| Answer the same question under DORA without re-doing it | Supplier risk register · same records populate the DORA register of information |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a supplier register is made of:
- Direct suppliers
- 34 · services mapped to functions
- Assessments current
- 31 · 3 refresh due this quarter
- Concentration flags
- 1 · under review
- Feeds
- NIS2 Art. 21(2)(d) · DORA register of information
- Evidence
- sealed · sha256:e08a…53d7
Where teams usually start
With a demo walked through by TruSecure — the supplier register, an assessment with its evidence chain, and the export an examiner or a DORA ICT examination will ask for. Onboarding then builds the first register from your actual contracts and connections; the subscription keeps it continuous.
Article 21(2)(d) makes your suppliers your problem, and Article 22 lets the EU assess critical supply chains collectively. TruSecure has one sub-processor, in the EEA, with none discontinued in the last 24 months — which makes it the shortest chain you will assess this year.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 Article 21(2)(d) requires entities to address supply-chain security, including the cybersecurity practices of direct suppliers and service providers. TruSecure maintains one continuous supplier risk register that also feeds DORA's register of information where applicable.