NIS2 supply chain security: supplier requirements and contract clauses
Supply chain security is one of the minimum measures of NIS2 Article 21. This page covers what entities must assess in their suppliers, what contracts should contain and what ENISA recommends.
Ask your question
Free account requiredAnswers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.
What the Directive requires
Article 21(2)(d) covers supply chain security, including security aspects of the relationship between each entity and its direct suppliers or service providers. Under Article 21(3), entities must consider the vulnerabilities specific to each direct supplier, the overall quality of their products and cybersecurity practices, including secure development procedures.
At Union level, the Cooperation Group, with the Commission and ENISA, may carry out coordinated security risk assessments of critical ICT services, systems or product supply chains, taking into account technical and, where relevant, non-technical risk factors.
Supply chain policy and contracts under Regulation 2024/2690
For digital infrastructure and ICT service providers covered by the Implementing Regulation, a supply chain security policy must govern relations with direct suppliers. Selection criteria include suppliers' cybersecurity practices, their ability to meet specifications, the quality and resilience of their ICT products and services, and the ability to diversify supply and limit vendor lock-in.
Contracts should specify, where appropriate through service level agreements, cybersecurity requirements, staff training and background checks, prompt incident notification, a right to audit or receive audit reports, and an obligation to handle vulnerabilities.
Frequently asked questions
Which areas do ENISA's supply chain good practices cover?
ENISA groups them into five areas: strategic corporate approach, supply chain risk management, supplier relationship management, vulnerability handling, and quality of products and practices for suppliers and service providers. It recommends a corporate-wide supply chain management system based on third party risk management.
Why does ENISA stress supplier trust?
ENISA's 2021 analysis of supply chain attacks found that around 62% of attacks on customers took advantage of their trust in their supplier. In 66% of the incidents, attackers focused on the suppliers' code to further compromise targeted customers.
Is there practical guidance on evidence of compliance?
Yes. ENISA's Technical Implementation Guidance (June 2025) supports Regulation 2024/2690 with guidance, examples of evidence that a requirement is in place, and mappings to standards and national frameworks.
Embed / API / MCP
Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs β¬0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.
MCP for your agents
This base's MCP server URL (tools ask_base and search_base):
https://kopik.io/api/mcp?base=eu-nis2-cybersecurityClaude Code, Cursor and other clients
claude mcp add --transport http kopik-eu-nis2-cybersecurity "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity" --header "Authorization: Bearer kpk_β¦"{
"mcpServers": {
"kopik-eu-nis2-cybersecurity": {
"url": "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity",
"headers": {
"Authorization": "Bearer kpk_β¦"
}
}
}
}REST API for your apps
mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.
curl -X POST https://kopik.io/api/v1/bases/eu-nis2-cybersecurity/query \
-H "Authorization: Bearer kpk_β¦" \
-H "Content-Type: application/json" \
-d '{"question": "Your question here", "mode": "answer"}'Getting started
- Create a key in your dashboard and top up your credit.
- Replace
kpk_β¦with your key. - Full details (responses, errors, JS and Python examples): developer docs.