SCRM Supplier Compliance & Risk Management

Home

Directive (EU) 2022/2555 · national transpositions ongoing

NIS2 demands supply chain security – and puts management on the hook for it.

Article 21 names supply chain security explicitly among the minimum measures. What must be assessed is the security of each direct supplier, not only your own infrastructure.

NIS2 covers essential and important entities across 18 sectors – energy, transport, health, waste, food, ICT services and manufacturing among them. Unlike NIS1 it reaches a broad mid-market, generally from 50 employees upwards.

The tone is new: management bodies must approve the measures, oversee their implementation and can be held personally accountable. Supply chain security stops being an IT topic and becomes a board agenda item.

Who is affected

  • Essential and important entities in the covered sectors within the EU.
  • Swiss companies with branches or group entities in the EU.
  • Swiss suppliers and IT providers held to a NIS2 level by EU customers.
  • In Switzerland additionally: the duty to report cyberattacks on critical infrastructure to the BACS.

What is required for the supply chain

Art. 21(2)(d)
Supply chain security, including security aspects of relationships with direct suppliers and service providers.
Art. 21(3)
Assessment must consider each supplier’s specific vulnerabilities and the overall quality of their security practice.
Art. 21(2)
Risk analysis, incident handling, business continuity and cryptography as minimum measures – each with effect on providers.
Art. 20
Approval and oversight by management bodies, training duty included.
Art. 23
Reporting chains for significant incidents – including incidents that occurred at a provider.

How SCRM covers it

Supplier assessment with security profile

Questionnaires, certificates and findings per supplier, comparable across the portfolio.

Criticality and service mapping

Which outage hits which service – the basis for defensible prioritisation.

Incident file per supplier

Incidents recorded with date, impact and action – usable for your internal reporting chain.

Board view

One page with status, open items and due dates for the meeting.

Frequently asked

Does NIS2 apply in Switzerland?

Not directly. It bites through two routes: EU sites inside your own group, and customer contracts in which EU entities pass their requirements on. Switzerland has its own reporting rules for critical infrastructure in parallel.

How deep does the supply chain duty go?

The directive targets direct suppliers and service providers. Their security practice must be assessed – not the entire chain down to raw materials.

What if the incident happens at the provider?

If your service is significantly disrupted, your reporting duty applies. In practice you need contact routes and contractual duties that inform you in time.

As of July 2026. National transposition laws differ; the law at each site governs.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required