Directive NIS2 European Union
Cart 0
Art. 21(2)(d)

Supply chain security


The obligation to address security in relationships with direct suppliers and service providers.

The obligation reaches DIRECT suppliers, not the entire chain, but you must take into account the specific vulnerabilities of each supplier, the overall quality of their products and cyber practices, and their secure development procedures. Article 21(3) adds that you must consider the results of coordinated Union-level risk assessments.

Related terms

Full glossary →

Cart 0