- Meaning
- Security along the whole supply chain
- Aim
- Controlling risks from suppliers and service providers
- Relation to NIS2
- Express duty (Article 21)
- Tools
- Risk assessment, contracts (DPA), monitoring
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is supply chain security?
Supply chain security is the disciplinethat keeps security in view not only inside your own organisation but along the Supply chain end to end. Where the supply chain describes the structure of dependencies, supply chain security is the managed programme behind it: it defines how suppliers, service providers and partners are selected, vetted and kept secure across the whole business relationship. The logic behind it is simple: an attack or an outage at a partner – a hacked software supplier, say – can strike straight through to your own operations.
Why NIS2 stresses the supply chain
Many of the severe attacks of recent years ran through the supply chain. That is why NIS2 names supply chain security expressly as one of the minimum risk management measures in Article 21(2)(d). Entities in scope have to assess and steer the risks arising from their supply chain systematically – including the security of the products and services that their suppliers themselves use. The directive has applied since 18 October 2024, and each Member State makes it binding through its own transposing law, so this stopped being a nice-to-have and became a duty a supervisor can check.
How do you put it into practice?
- Assess suppliers: identify the critical partners and check their level of security.
- Contracts: fix the security requirements in writing – and where personal data is processed, in a Data processing agreement (DPA).
- Monitoring: Third-party risk has to be tracked continuously, not checked once.
An example from a machinery manufacturer: The IT manager first sorts the roughly 40 IT suppliers into critical, medium and non-critical. For the five critical ones – among them the ERP host and the remote maintenance provider who sits deep inside the production control system through a remote connection, and whose outage or compromise would halt manufacturing within hours – he asks for a security concept, an ISO 27001 certificate or a completed questionnaire, writes incident reporting duties into the contract and reviews the status every year. A one-off selection turns into a running programme. That takes discipline.
Checklist: assessing a supplier for security
Where do you start? The checklist below walks step by step through a vendor assessment – from rating criticality to continuous monitoring. Tick a point off only once it is evidenced and not merely claimed.
- 1. Rate criticality: Which data, systems or processes does the supplier touch? Would an outage affect essential services? Set the category: critical, medium or non-critical.
- 2. Clarify access and dependency: Does the partner have remote access, administrator rights or physical entry? Is there an alternative supplier if this one fails?
- 3. Obtain evidence of security: ISO 27001, IT-Grundschutz (the German baseline standard), SOC 2 or a completed security questionnaire. Important: check the scope and the validity date of a certificate, not merely that one exists.
- 4. Anchor the contract clauses: Security requirements, a duty to report incidents (matched to the NIS2 reporting chain of 24 hours, 72 hours and one month), a right to audit, a rule on sub-processors and – where personal data is processed – a Data processing agreement (DPA).
- 5. Define the monitoring: Who checks, and when? An annual reassessment of critical partners, tracking of expiring certificates and a defined route of response if a supplier reports a vulnerability.
- 6. Document it: Record the result, the date and the person responsible. Without evidence the assessment will not hold up in an inspection.
Supply chain security and risk management
Supply chain security is a fixed component of risk management: third-party risks feed into the risk analysis and are then treated with the matching Controls in the same way as any other risk. That closes the circle between the strategy (risk management), the programme (supply chain security) and the individual case, which is the concrete risk of one particular service provider.
Next steps
- Draw up a complete list of every supplier and service provider with an IT or data connection.
- Rate them by criticality and deal with the critical partners first.
- Apply the assessment checklist above to every critical supplier.
- Write reporting duties and security requirements into the contract at the next renewal.
- Fix a firm date for the reassessment – otherwise the review goes stale.
Further reading: Directive (EU) 2022/2555, Article 21 (EUR-Lex)
Frequently asked questions
What is supply chain security?
Supply chain security is the discipline that defines and monitors the security requirements placed on suppliers, service providers and partners along the whole value chain, so that risks coming from third parties are controlled systematically instead of looking only at your own organisation. The logic behind it is simple: an attack or an outage at a partner, a hacked software supplier for example, can strike straight through to your own operations and disrupt them badly.
Is supply chain security mandatory under NIS2?
Yes. Article 21(2)(d) of the directive names supply chain security expressly as one of the minimum risk management measures, and the wording covers the security of the products and services that suppliers themselves use. The directive has applied since 18 October 2024 and is made binding on you by the transposing law of the Member State in which you are established, so assessing and steering supply chain risks is a duty a supervisor can check, not an optional extra.
How do you steer supply chain risks?
You start by identifying the critical suppliers and checking their level of security, through an ISO 27001 certificate or a security questionnaire for example. You then fix security requirements and incident reporting duties in the contract, and where personal data is processed you add a data processing agreement under Article 28 GDPR. What decides the outcome is keeping the level of security under continuous review and reassessing critical suppliers every year, rather than checking once when the contract is signed.