Supply Chain Risk Management under the NIS2 Directive. Obligations, Supplier Audits and Contractual Clauses

One of the most groundbreaking changes introduced by the NIS2 Directive and the updated Act on the National Cybersecurity System (UKSC) is the move away from treating organizations as independent islands. Experience from recent years clearly shows that the weakest link in an enterprise’s security architecture is rarely its own, central IT infrastructure. Much more often, external companies become the vector for a successful attack: external managed service providers (MSPs), software houses, SaaS software providers, logistics agencies, or entities maintaining cloud infrastructure.

The EU legislator has explicitly imposed a legal obligation on essential and important entities to implement risk management procedures throughout the entire supply chain. This means that failure to properly verify and secure relationships with business partners constitutes a direct violation of NIS2 requirements, subject to severe financial penalties and management liability.

Business Partner as an Attack Vector – Why Is the Supply Chain at the Center of NIS2?

Supply Chain Attacks involve taking control of an external supplier’s systems in order to use them to gain unauthorized access to the supplier’s customers’ resources. With trusted VPN connections, privileged access accounts, or access to software source code, an IT provider can unknowingly and unwillingly become a silent conduit for a threat.

Under NIS2 requirements, every organization covered by the Directive must carry out a detailed identification and classification of its suppliers and subcontractors in terms of their impact on its business continuity. The risk analysis must take into account not only the technical specifics of the products and services provided, but also the maturity level of the partner’s own security measures.

How to Conduct the Supplier Verification and Audit Process (Cyber Due Diligence)?

The implementation of the legal obligation to control the supply chain requires the introduction of formal and repeatable verification procedures at every stage of the B2B relationship lifecycle:

Pre-contractual Assessment (Pre-assessment): conducting detailed security questionnaires and auditing potential suppliers before signing a contract. Verification includes, among other things, certificates held (ISO/IEC 27001, SOC 2), vulnerability management procedures, and backup policies.
Risk Categorization: assigning suppliers to appropriate risk groups (high, medium, low) depending on the extent of their access to sensitive data and critical infrastructure.
Continuous Monitoring and Re-audits: periodically verifying suppliers’ security status throughout the term of the contract, including requiring them to provide up-to-date penetration testing reports.

Essential Cybersecurity Clauses in B2B Contracts

Technical verification alone is insufficient without appropriate legal safeguards. Commercial contracts with providers of IT services, software, and infrastructure must be updated to include dedicated cybersecurity clauses. In contractual relationships, it is essential to precisely regulate the following matters:

Incident Notification Regime (Response SLA): an absolute obligation for the supplier to immediately report any compromise of its systems that could affect the security of the contracting organization.
Right to Audit: granting the contracting organization (or an independent auditor) the right to conduct security inspections and audits at the supplier’s premises or within its technological environment.
Technical and Organizational Measures: imposing specific requirements on the supplier regarding the use of multi-factor authentication (MFA), data encryption, network segmentation, and continuous vulnerability scanning.
Cascading Obligations: requiring the supplier to impose equivalent security standards on its own subcontractors and component suppliers.

Impact of NIS2 on Small and Medium-Sized B2B Companies (SMEs)

Although the NIS2 Directive generally applies directly to medium-sized and large enterprises, its impact on the SME sector is enormous. Small technology companies, consulting agencies, or local software providers that provide services to essential entities (e.g. in the banking, energy, healthcare, or manufacturing sectors) will be forced by their clients to comply with NIS2 standards. Failure to meet these requirements will result in exclusion from tenders and termination of existing contracts.

Secure Your Supply Chain with Rulity Consulting

Effective third-party risk management requires a unique combination of legal expertise and advanced knowledge of IT cybersecurity. The Rulity Consulting team supports organizations in the comprehensive development and implementation of supply chain security policies.

We develop legal and organizational frameworks, prepare secure B2B contract templates and data processing agreements, conduct supplier audits (Cyber Due Diligence), and help smaller entities achieve the compliance necessary to maintain key commercial contracts. Ensure the full security of your business relationships and meet NIS2 requirements before the regulator’s inspection.

Supply Chain Security – Frequently Asked Questions

Do I have to audit absolutely every supplier in my company?

No, NIS2 requirements are based on the principles of proportionality and risk analysis. The detailed audit process (Cyber Due Diligence) should be applied to key suppliers – those that have access to your IT systems, process confidential data, or whose failure would paralyze your operational activities. For other suppliers, basic verification questionnaires are sufficient.

What should I do if an IT supplier refuses to sign a NIS2 amendment?

A key supplier’s refusal to implement security measures or allow verification constitutes a direct regulatory risk for your organization. Under NIS2, the organization should include a contingency plan (exit plan) in its risk management policy, as well as a procedure for gradually replacing entities that do not meet security standards with other partners.

How can I prepare for audit inquiries from NIS2-covered clients?

A key step is to conduct an internal security audit, implement good practices for code and vulnerability management (e.g. OWASP SAMM, ISO 27001), use multi-factor authentication (MFA), and prepare ready-made information packages (so-called security packs) for your contractors, which significantly speeds up tender processes.