Directive (EU) 2022/2555 · national transpositions ongoing
NIS2 demands supply chain security – and puts management on the hook for it.
Article 21 names supply chain security explicitly among the minimum measures. What must be assessed is the security of each direct supplier, not only your own infrastructure.
NIS2 covers essential and important entities across 18 sectors – energy, transport, health, waste, food, ICT services and manufacturing among them. Unlike NIS1 it reaches a broad mid-market, generally from 50 employees upwards.
The tone is new: management bodies must approve the measures, oversee their implementation and can be held personally accountable. Supply chain security stops being an IT topic and becomes a board agenda item.
Who is affected
- Essential and important entities in the covered sectors within the EU.
- Swiss companies with branches or group entities in the EU.
- Swiss suppliers and IT providers held to a NIS2 level by EU customers.
- In Switzerland additionally: the duty to report cyberattacks on critical infrastructure to the BACS.
What is required for the supply chain
- Art. 21(2)(d)
- Supply chain security, including security aspects of relationships with direct suppliers and service providers.
- Art. 21(3)
- Assessment must consider each supplier’s specific vulnerabilities and the overall quality of their security practice.
- Art. 21(2)
- Risk analysis, incident handling, business continuity and cryptography as minimum measures – each with effect on providers.
- Art. 20
- Approval and oversight by management bodies, training duty included.
- Art. 23
- Reporting chains for significant incidents – including incidents that occurred at a provider.
How SCRM covers it
Supplier assessment with security profile
Questionnaires, certificates and findings per supplier, comparable across the portfolio.
Criticality and service mapping
Which outage hits which service – the basis for defensible prioritisation.
Incident file per supplier
Incidents recorded with date, impact and action – usable for your internal reporting chain.
Board view
One page with status, open items and due dates for the meeting.
Frequently asked
Does NIS2 apply in Switzerland?
Not directly. It bites through two routes: EU sites inside your own group, and customer contracts in which EU entities pass their requirements on. Switzerland has its own reporting rules for critical infrastructure in parallel.
How deep does the supply chain duty go?
The directive targets direct suppliers and service providers. Their security practice must be assessed – not the entire chain down to raw materials.
What if the incident happens at the provider?
If your service is significantly disrupted, your reporting duty applies. In practice you need contact routes and contractual duties that inform you in time.
As of July 2026. National transposition laws differ; the law at each site governs.