Art. 21(2)(d)
Supply chain security
The obligation to address security in relationships with direct suppliers and service providers.
The obligation reaches DIRECT suppliers, not the entire chain, but you must take into account the specific vulnerabilities of each supplier, the overall quality of their products and cyber practices, and their secure development procedures. Article 21(3) adds that you must consider the results of coordinated Union-level risk assessments.
Related terms
- Essential entity · Art. 3(1)
- Important entity · Art. 3(2)
- Significant incident · Art. 23(3)
- Early warning · Art. 23(4)(a)
- Size-cap rule · Art. 2(1)
- CSIRT · Art. 10