Glossary

Supply Chain Security

One of the 10 Article 21 measures, requiring entities to assess and manage cybersecurity risk from suppliers and service providers.

Explained in depth: The 10 NIS2 security requirements

NIS2 makes an organisation partly responsible for the security practices of its direct suppliers — a significant expansion compared to the original NIS Directive. In practice this means a supplier register, risk-based assessment criteria and security clauses in contracts, all of which have to be documented.

Used in

See also

← All glossary terms