Tech & productVerified by Kopik: Official sources reviewed and answers tested by Kopik

NIS2 supply chain security: supplier requirements and contract clauses

Supply chain security is one of the minimum measures of NIS2 Article 21. This page covers what entities must assess in their suppliers, what contracts should contain and what ENISA recommends.

Ask your question

Free account required

Each question stands alone Β· 1 free a month, then with a subscription.

Answers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.

What the Directive requires

Article 21(2)(d) covers supply chain security, including security aspects of the relationship between each entity and its direct suppliers or service providers. Under Article 21(3), entities must consider the vulnerabilities specific to each direct supplier, the overall quality of their products and cybersecurity practices, including secure development procedures.

At Union level, the Cooperation Group, with the Commission and ENISA, may carry out coordinated security risk assessments of critical ICT services, systems or product supply chains, taking into account technical and, where relevant, non-technical risk factors.

Supply chain policy and contracts under Regulation 2024/2690

For digital infrastructure and ICT service providers covered by the Implementing Regulation, a supply chain security policy must govern relations with direct suppliers. Selection criteria include suppliers' cybersecurity practices, their ability to meet specifications, the quality and resilience of their ICT products and services, and the ability to diversify supply and limit vendor lock-in.

Contracts should specify, where appropriate through service level agreements, cybersecurity requirements, staff training and background checks, prompt incident notification, a right to audit or receive audit reports, and an obligation to handle vulnerabilities.

Frequently asked questions

Which areas do ENISA's supply chain good practices cover?

ENISA groups them into five areas: strategic corporate approach, supply chain risk management, supplier relationship management, vulnerability handling, and quality of products and practices for suppliers and service providers. It recommends a corporate-wide supply chain management system based on third party risk management.

Why does ENISA stress supplier trust?

ENISA's 2021 analysis of supply chain attacks found that around 62% of attacks on customers took advantage of their trust in their supplier. In 66% of the incidents, attackers focused on the suppliers' code to further compromise targeted customers.

Is there practical guidance on evidence of compliance?

Yes. ENISA's Technical Implementation Guidance (June 2025) supports Regulation 2024/2690 with guidance, examples of evidence that a requirement is in place, and mappings to standards and national frameworks.

For developers and agents

Embed / API / MCP

Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.

MCP for your agents

This base's MCP server URL (tools ask_base and search_base):

MCP URL
https://kopik.io/api/mcp?base=eu-nis2-cybersecurity
Claude Code, Cursor and other clients
Claude Code
claude mcp add --transport http kopik-eu-nis2-cybersecurity "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity" --header "Authorization: Bearer kpk_…"
JSON config (mcpServers)
{
  "mcpServers": {
    "kopik-eu-nis2-cybersecurity": {
      "url": "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

REST API for your apps

mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-nis2-cybersecurity/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Your question here", "mode": "answer"}'

Getting started

  1. Create a key in your dashboard and top up your credit.
  2. Replace kpk_… with your key.
  3. Full details (responses, errors, JS and Python examples): developer docs.