Skip to content

NIS2

How do you meet the NIS2 supply chain security requirements?

What Article 21(2)(d) and 21(3) ask of you, how to assess suppliers in practice, and a runbook for the day a trusted vendor becomes the way in.

Shipping containers at night with one container in the centre ajar and lit from inside, symbolising supply chain risk

The short answer

NIS2 Article 21(2)(d) requires essential and important entities to secure their supply chain, including their relationships with direct suppliers and service providers. Article 21(3) adds that you must weigh each supplier's specific vulnerabilities, product quality and security practices. In practice: keep a supplier register, assess critical vendors, set contract requirements and plan recovery that doesn't depend on them.

Key takeaways

  • NIS2 Article 21(2)(d) makes supply chain security one of the ten mandatory cybersecurity risk-management measures.
  • Article 21(3) requires you to consider each direct supplier's vulnerabilities, product quality and secure development practices.
  • Third-party involvement in breaches doubled to 30% in the Verizon 2025 DBIR, so supplier risk is now a main attack route.
  • Managed service providers are listed in NIS2 Annex I and are also covered by Implementing Regulation (EU) 2024/2690, which includes supply chain requirements.
  • Detection and isolation are not enough: keep a recovery path, such as immutable offsite backups, that no supplier's tooling can reach.

What does NIS2 require for supply chain security?

NIS2 requires you to manage the security risks that come from your suppliers and service providers, and to base your measures on the specific risks of each direct supplier. It is one of the ten Article 21 measures described in our NIS2 compliance guide.

  • Article 21(2)(d) of Directive (EU) 2022/2555: "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers".
  • Article 21(3): entities must take into account "the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures", as well as the results of EU coordinated risk assessments of critical supply chains under Article 22(1).
  • Implementing Regulation (EU) 2024/2690 sets detailed technical requirements for digital providers such as cloud, data centre, managed service and managed security service providers. According to ENISA's technical implementation guidance (June 2025), these include a supply chain security policy and a directory of suppliers and service providers. Read the regulation on EUR-Lex.

Management carries the responsibility. Under Article 20, management bodies approve the risk-management measures, oversee their implementation and can be held liable. Under Article 34, maximum fines for breaching Article 21 are at least €10 million or 2% of worldwide turnover for essential entities and €7 million or 1.4% for important entities. See the ten Article 21 measures and whether you're in scope.

Why are supply chain attacks so hard to stop?

Because the malicious code arrives through a channel you trust: a signed update, a management agent or a software package. Your controls are built to let those through.

Imagine your monitoring agent installs its usual signed overnight update on every server. This time it carries code that opens a remote shell. Nothing looks wrong until files start to change.

  • Kaseya VSA, July 2021. Attackers used zero-day flaws in Kaseya's remote management software to push REvil ransomware. Kaseya reported about 50 direct customers breached and 800 to 1,500 downstream businesses affected (BleepingComputer).
  • npm "Shai-Hulud", September 2025. A self-replicating worm compromised more than 500 npm packages and harvested developer tokens and cloud API keys. CISA advised reviewing dependencies, pinning packages to releases before 16 September 2025 and rotating all developer credentials.

The numbers are rising. According to the Verizon 2025 Data Breach Investigations Report, the share of breaches involving third parties doubled to 30%. The Verizon 2026 DBIR, as summarised by Help Net Security, reports that third-party breaches now feature in 48% of breaches.

How do you assess and manage suppliers under NIS2?

Start with a register of every supplier that touches your network and information systems, rank them by criticality, and put the most effort into the few that could stop or compromise your services.

  1. Build the register. List suppliers, the services and systems they support, the access they have (admin agents, VPN, API keys) and where your data is stored.
  2. Rank by criticality. Ask what happens if this supplier is compromised or unavailable for a week.
  3. Assess critical suppliers. Ask for certifications such as ISO 27001, their vulnerability handling and secure development process, incident history and how they protect their own admin access.
  4. Set contract requirements. Incident notification to you within a fixed time, audit or evidence rights, data location, subcontractor rules and an exit plan.
  5. Monitor and review at planned intervals and after any significant incident, at the supplier or in the wider market.
Supplier tierExamplesMinimum checks
Critical: privileged access or hosts core dataMSP, RMM and EDR tooling, cloud and backup providersCertification and audit report, MFA on admin access, incident notification clause, tested exit and recovery path
Important: business-critical but no admin accessERP SaaS, payroll, payment providerSecurity questionnaire, data location, breach notification clause, data export option
StandardOffice supplies, marketing tools without sensitive dataBasic terms and a data processing agreement where personal data is involved

Watch out for concentration risk: if backups, identity and email sit with one provider, one incident hits everything. See the Microsoft 365 shared responsibility model for where a provider's duties stop.

What belongs in a supply chain incident runbook?

A runbook turns a vendor compromise from improvisation into a procedure. It needs six parts, written and agreed before you need them.

  1. Dependency map. For each critical supplier: which agents, accounts and integrations it has, and on which systems.
  2. Isolation steps per vendor. How to disable the agent, revoke its credentials and block its network paths, and what breaks for the business when you do.
  3. Decision rights. Who may cut off a supplier at 02:00 without waiting for a meeting.
  4. An independent recovery path. Backups and restore tooling that the compromised supplier can't reach, with known recovery objectives per system.
  5. Communication templates. Internal escalation, customer notices and the NIS2 early warning within 24 hours and notification within 72 hours under Article 23.
  6. Test schedule. A tabletop exercise per critical supplier, at least once a year, measuring how long isolation and restore actually take.

Recovery is the part most runbooks skip. If the attacker came in through your management tooling, assume they could see, and possibly delete, anything that tooling could reach.

How do detection, isolation and recovery work together?

Each layer catches what the previous one missed. Detection spots a trusted process behaving badly, isolation limits the spread, and recovery gets you back when the first two were too late.

LayerGoalWhat it looks like
DetectionNotice unexpected behaviour from trusted softwareFile integrity monitoring on agent binaries and system files, vulnerability scanning with CVSS scores, threat hunting mapped to MITRE ATT&CK
IsolationStop the spread quicklyScripted per-vendor cut-off, credential revocation, network blocks, pre-approved decision rights
RecoveryRestore services without the compromised supplierImmutable and air-gapped backups, MFA on backup admin actions, an isolated recovery environment, tested restore times

For MSPs, the Mindtime Security EDR platform provides the detection tooling: vulnerability management, malware detection, CIS configuration compliance, file integrity monitoring, threat hunting, MITRE ATT&CK mapping and automated response based on rules the MSP configures. Mindtime provides the platform; the MSP runs the service and responds.

Related: when MFA fails, backup is the last line.

What does NIS2 supply chain security mean for MSPs?

MSPs sit on both sides. They are entities in their own right, listed in NIS2 Annex I under ICT service management, and they are the critical supplier their clients must assess.

  • As an entity: an MSP in scope must meet Article 21, including supply chain security for its own vendors such as RMM, PSA, EDR and backup platforms, and the detailed requirements of Implementing Regulation (EU) 2024/2690.
  • As a supplier: clients will ask for certifications, incident notification terms, evidence of MFA on admin access and proof that their data can be restored independently.
  • As a target: one compromised management platform can reach every client at once, as Kaseya showed.

In the Netherlands, the Cyberbeveiligingswet applies from 15 August 2026, and the NCSC says about 8,000 organisations in 18 sectors fall under it. Many will put these questions to their IT providers. See also immutable backup for MSPs.

What to do next

Supply chain security under NIS2 comes down to three things: know your suppliers and their access, set and check requirements for the critical ones, and keep a recovery path that doesn't depend on any of them. Write the runbook now and test it once a year per critical supplier.

As a supplier, Mindtime is ISO 27001 and NEN 7510 audited and signs a GDPR Data Processing Agreement with every contract. Backups are stored only in our own Tier III data centres in the Netherlands and Germany, independent of US hyperscalers, as immutable copies (Object Lock) plus an air-gapped copy. Admin actions require MFA, and data is AES-256 encrypted in transit. Mindtime covers the backup and disaster recovery layer; see our NIS2 compliance guide for how that fits Article 21.

Want to check your supply chain recovery path? Get a free assessment. MSPs can also visit our partner programme.

This article is information, not legal advice.

Frequently asked questions

What is a supply chain attack in IT?

A supply chain attack compromises you through a supplier you trust instead of attacking you directly. Typical routes are a poisoned software update, a compromised remote management tool, a malicious open-source package or stolen credentials of a service provider. Because the code is signed or the access is legitimate, normal security controls often let it through, which is why recovery planning matters.

What does NIS2 Article 21(2)(d) require?

It requires essential and important entities to include supply chain security in their cybersecurity risk-management measures, covering the security aspects of their relationships with direct suppliers and service providers. Article 21(3) adds that you must consider each supplier's specific vulnerabilities, product quality and security practices, including secure development, and the results of EU coordinated supply chain risk assessments.

Are managed service providers covered by NIS2?

Yes. Managed service providers and managed security service providers are listed in NIS2 Annex I under ICT service management (business-to-business). Most MSPs that are medium-sized or larger fall in scope, and Implementing Regulation (EU) 2024/2690 sets detailed technical requirements for them, including supply chain security. Check your national law, such as the Dutch Cyberbeveiligingswet or the German NIS2UmsuCG.

What should a supplier contract include for NIS2?

For critical suppliers, include incident notification to you within a fixed time, your right to evidence or audits, security requirements such as MFA on admin access, data location, rules for subcontractors and a clear exit and data return process. For digital providers in scope of Implementing Regulation (EU) 2024/2690, contractual security requirements are part of the supply chain policy ENISA describes.

Sources

  1. Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, Publications Office of the European Union, 2022
  2. Commission Implementing Regulation (EU) 2024/2690EUR-Lex, Publications Office of the European Union, 2024
  3. Technical implementation guidance on cybersecurity risk-management measures, version 1.0ENISA, 2025
  4. Verizon's 2025 Data Breach Investigations Report: alarming surge in cyberattacks through third partiesVerizon, 2025
  5. Lessons for organizations from the Verizon 2026 Data Breach Investigations ReportHelp Net Security, 2026
  6. Kaseya: roughly 1,500 businesses hit by REvil ransomware attackBleepingComputer, 2021
  7. Widespread supply chain compromise impacting npm ecosystemCISA, 2025
  8. Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van krachtNationaal Cyber Security Centrum (NCSC), 2026
Part ofNIS2 Compliance