NIS2 asks you to notice. it doesn't say how.
Directive (EU) 2022/2555 puts your direct suppliers inside your own security obligations, and requires you to take their vulnerabilities and cybersecurity practices into account when you decide what measures are appropriate. For eleven kinds of digital provider, Implementing Regulation (EU) 2024/2690 goes further and requires them to act on changes in a supplier's practices. Neither builds a way to find out that doesn't depend on the supplier telling you.
the two sentences that put your suppliers in scope.
The whole supply-chain obligation is Article 21(2)(d), one of ten minimum measures:
“supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”
Article 21(3) says what to weigh: the vulnerabilities specific to each direct supplier and service provider, the overall quality of their products and cybersecurity practices, and their secure development procedures. It also requires you to take into account the results of any coordinated security risk assessment carried out under Article 22.
The word doing most of the work is direct: NIS2 stops at the companies you contract with. Recital 85 says entities “could consider” risks from further down the chain, which is an encouragement and nothing more. If you also fall under DORA, though, its subcontracting reach is wider. How DORA and NIS2 differ.
are you in scope of NIS2? essential and important entities.
NIS2 covers entities of a type listed in Annex I or Annex II that reach the size of a medium-sized enterprise under Commission Recommendation 2003/361/EC, or exceed it. Broadly, that means fifty or more staff, or turnover or a balance sheet total above ten million euro. Broadly, because the underlying test uses an “and/or” construction and NIS2 disapplies part of the Recommendation's own arithmetic.
The split that follows decides how hard supervision bites. Article 3(1) makes an entity essential on any of seven grounds: an Annex I type above the medium-sized ceilings; a qualified trust service provider, TLD name registry or DNS provider at any size; a provider of public electronic communications networks or services at medium size; a central-government public administration body; an entity a Member State designates under Article 2(2), points (b) to (e); an entity identified as critical under the CER Directive (EU) 2022/2557; and, where a Member State so provides, an entity identified before 16 January 2023 as an operator of essential services under the old NIS regime. Important entities are everyone else in scope. Essential entities face supervision before anything goes wrong; important entities are supervised after.
Size isn't the whole test. Article 2(2) pulls in certain entities regardless of size, including anyone who is the sole provider in a Member State of a service essential to critical societal or economic activity, and Member States may add categories of their own. If you're near a threshold, check your national act.
your obligations come from your own country's law.
A directive binds Member States, not companies. What reaches you is the national transposing act, and Article 5 lets any Member State go further than the Directive. Belgium did, by requiring essential entities to undergo a third-party conformity assessment the Directive never asks for.
Transposition was due by 17 October 2024, to apply from 18 October 2024, and it didn't go to plan. The Commission sent letters of formal notice to twenty-three Member States on 28 November 2024, reasoned opinions to nineteen on 7 May 2025, and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice. So “NIS2 requires you…” is shorthand. Read your own act.
when does NIS2 require an unscheduled supplier review?
The operational detail lives in Implementing Regulation (EU) 2024/2690. Before quoting it at yourself, check whether it binds you: it applies to eleven kinds of digital provider: DNS providers, TLD registries, cloud, data centres, content delivery networks, managed service providers, managed security providers, online marketplaces, search engines, social platforms, and trust service providers. If you make things, treat what follows as well-argued best practice rather than as your legal obligation.
Point 5.1.6 of its Annex sets the review duty, and it has two legs:
“The relevant entities shall review the supply chain security policy, and monitor, evaluate and, where necessary, act upon changes in the cybersecurity practices of suppliers and service providers, at planned intervals and when significant changes to operations or risks or significant incidents related to the provision of ICT services or having impact on the security of the ICT products from suppliers and service providers occur.”
The first leg is a date in the calendar. The second has no cadence and no threshold, and never says how you'd find out.
That qualifier at the end narrows things. The incidents that trigger the second leg are ones touching the ICT services or products themselves, so an insolvency filing doesn't automatically count as one. It is still a significant change to that supplier's operations, and to your risk. That's the other half of the same clause.
The discovery mechanisms it does build are contractual, and both run through the supplier. Point 5.1.4 has supplier contracts specify, where appropriate, an obligation on the supplier to notify you without undue delay of incidents affecting your systems, and a right to audit or to receive audit reports. Both work while the supplier is functioning and willing. A company that has entered administration doesn't send the notice, and doesn't host your audit. Neither does one whose ownership changed last week, or one added to a sanctions list this morning.
Then there's point 5.1.7(c), which requires entities to “assess the need for unscheduled reviews and document the findings in a comprehensible manner”. So the documentation duty attaches to the assessment itself, and it doesn't switch off in the months when nothing happened. ENISA's June 2025 implementation guidance is non-binding, and written for those same eleven provider types. It lists what should trigger an unscheduled review: material changes in a supplier's operations, changes in its risk exposure, failure to meet contractual obligations, and new threats affecting what it supplies.
Two of those four surface in the public record before anyone writes to you: a material change in a supplier's operations, and a change in its risk exposure. The other two mostly don't. A missed contractual obligation is private between you and the supplier, and a new vulnerability in what it supplies is a job for a different kind of tool.
what the management body carries.
Article 20(1) puts approval and oversight of the Article 21 measures on the management body, and provides that management bodies can be held liable for the entity's infringements of that article. Article 20(2) requires their members to undergo training. That combination is why NIS2 tends to arrive on a risk manager's desk as a board question.
On penalties, two things get misreported. Take the figures: ten million euro or 2% of total worldwide annual turnover for essential entities, seven million or 1.4% for important ones, whichever is higher. The text says “a maximum of at least”, which makes them floors on what national law must allow, not ceilings, and they attach to infringements of Article 21 or 23 specifically. And the power to ask a court to temporarily bar a chief executive from managerial functions, at Article 32(5)(b), applies to essential entities only. Most mid-market firms in scope are important entities, and that particular sanction isn't aimed at them.
what we can't evidence for you.
what we do.
We watch the companies you name in public records: company registries, court and insolvency filings, sanctions and watchlists, regulatory notices and enforcement, breach and outage reports, and the trade press in the market where each one operates. When something crosses the line you set in writing, you get one email with the document behind it.
Set against point 5.1.6, that's a trigger detector for the second leg, the one with no stated method. And the dated weekly log is what your 5.1.7(c) documentation can rest on, because it records what we checked and what crossed your line, including in the weeks when nothing did. Those weeks are the hardest to evidence after the fact.
A quiet log is a record of what we read and what we found. It isn't a finding that no unscheduled review was needed, and it couldn't be. If something was never published we won't see it, and no alert doesn't mean nothing happened. Assessing whether a review is needed, and writing that assessment down, is the duty point 5.1.7(c) puts on you. Nothing you buy moves that.
No questionnaire goes out. Your suppliers are never contacted, so nothing waits on a vendor's security team returning a spreadsheet to a customer smaller than they are.
every public source we read →
see a full weekly watch log, anonymized →
common NIS2 questions.
what does NIS2 require for supply chain security?
Article 21(2)(d) requires measures covering "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers". Article 21(3) then requires you to take into account the vulnerabilities specific to each direct supplier, the overall quality of their products and cybersecurity practices, and their secure development procedures. The Directive prescribes no method, demands no questionnaire and sets no monitoring frequency.
does NIS2 apply to my suppliers?
Not through you. NIS2 binds entities that are themselves in scope by sector and size. Your obligation under Article 21(2)(d) is about how you manage the relationship. Making your supplier compliant isn't your job. A supplier may of course be in scope in its own right, and many contracts now push obligations down the chain, but that's contract law rather than the Directive reaching them through you.
does NIS2 reach my suppliers’ suppliers?
The obligation stops at your direct suppliers and service providers. Both Article 21(2)(d) and Article 21(3) say "direct". Recital 85 says entities "could consider" risks from other levels of the chain, which encourages rather than obliges. It's one of the clearer differences from DORA, which does reach into subcontracting chains.
do I have to send my suppliers a security questionnaire?
No. Nothing in NIS2 or in Implementing Regulation (EU) 2024/2690 requires a questionnaire. They require supplier risk to be taken into account, reviewed and acted on when something changes. How you learn what changed is left entirely to you, which is why the questionnaire became the default rather than the requirement.
what’s the difference between an essential entity and an important entity?
Supervision, mainly. Essential entities are supervised before anything goes wrong; important entities are supervised after, once something suggests they breached the Directive. Article 3(1) makes an entity essential on any of seven grounds, and size is only the first: an Annex I type above the medium-sized ceilings, a qualified trust service provider, TLD name registry or DNS provider at any size, a provider of public electronic communications networks or services at medium size, a central-government public administration body, an entity a Member State designates under Article 2(2), points (b) to (e), an entity identified as critical under the CER Directive (EU) 2022/2557, and in some Member States an operator of essential services identified before 16 January 2023. Everyone else in scope is important, and most mid-market firms land there.
what are the penalties for breaching NIS2?
Ten million euro or 2% of total worldwide annual turnover for essential entities, seven million or 1.4% for important ones, whichever is higher. Two things about those figures get misreported. The text says “a maximum of at least”, which makes them floors on what national law has to allow rather than ceilings, so your own act can go further. And they attach to infringements of Article 21 or Article 23 specifically, rather than to the Directive at large. The power to ask a court to temporarily bar a chief executive from managerial functions, at Article 32(5)(b), reaches essential entities only. Most mid-market firms in scope are important entities, so that sanction isn’t aimed at them.
can managers be held personally liable under NIS2?
Article 20(1) puts approval and oversight of the Article 21 measures on the management body, and provides that management bodies can be held liable for the entity’s infringements of that article. Article 20(2) requires their members to undergo training. That combination is why NIS2 tends to arrive on a risk manager’s desk as a board question. The sanction people usually have in mind is narrower than the fear: Article 32(5)(b) lets a competent authority ask a court to temporarily bar a chief executive from managerial functions, and it applies to essential entities only. What binds you either way is your own country’s transposing act, and Article 5 lets any Member State go further than the Directive.
if a supplier is breached, does that start my NIS2 reporting clock?
It might. The Article 23 early warning runs within twenty-four hours of your becoming aware of a significant incident affecting your service, not from the supplier’s incident. So an alert about a supplier breach can start your awareness clock rather than help you beat it. We read public sources on an interval matched to how often each one changes, which isn’t an incident detector however fast it runs: if nothing was published, we won’t see it. Whether an event at a supplier is a significant incident for you is your call, and your national act’s.
is NIS2 in force in my country yet?
Check your national act, not the Directive. Member States had to transpose by 17 October 2024 and apply their measures from 18 October 2024, and several missed it. The Commission sent letters of formal notice to 23 Member States on 28 November 2024 and reasoned opinions to 19 on 7 May 2025, and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice. Article 5 also permits Member States to go further than the Directive, so the text that binds you is the national one. Checked 2 August 2026.
Version 1.2, 26 August 2026. Every article and point cited here was checked against its text on 2 August 2026, and the transposition figures were current then. The questions added since were written from that same checked material and cite nothing new. National transposition keeps moving, so read the act that binds you: the Directive itself is on EUR-Lex. This page describes what we read and how we deliver it. It isn't legal advice, and it can't tell you whether you're in scope.