Healthcare guide · 8 min
ENISA's hospital procurement cybersecurity guidelines: how to assess your suppliers
On 22 July 2026 ENISA published updated procurement guidelines for the cybersecurity of hospitals and healthcare providers, one of the first deliverables under the EU Action Plan for hospital cybersecurity. They make supplier cybersecurity a formal part of the buying process: requirements for suppliers, a practical checklist, and controls across the whole procurement lifecycle. Healthcare is a NIS2 essential sector, so this sits on top of the Article 21(2)(d) duty to manage supply-chain risk. This guide turns the guidelines into concrete steps for assessing a supplier before and after you sign.
Key takeaways
- • ENISA expects cybersecurity to be built into every phase of healthcare procurement, not bolted on afterwards.
- • The core is assessing supplier security before you sign and monitoring it for the life of the contract.
- • Most of the assessment can be done from public signals, with a documented decision and evidence trail.
What ENISA published, and why it matters
The procurement guidelines are among the first deliverables under the EU Action Plan for hospital cybersecurity, launched in 2025, and arrive alongside a new European Cybersecurity Support Centre for healthcare providers. They set out cybersecurity requirements for suppliers, highlight the products and services where security matters most, and provide a practical checklist across the procurement lifecycle. Because hospitals and healthcare providers are essential entities under NIS2, this complements the Article 21(2)(d) duty to identify and manage the risk carried by your suppliers: the guidelines describe how to do that at the point of purchase, and continuously afterwards.
Official source: ENISA — procurement guidelines for hospitals and healthcare providers — published 22 July 2026, one of the first deliverables under the EU Action Plan for hospital cybersecurity. Reviewed 22 July 2026.
Cybersecurity across the procurement lifecycle
The guidelines cover every phase, from specifying requirements to running the contract. These five steps translate that into what to actually assess about a supplier, and most of it uses information you can obtain without any access to the supplier's systems.
Specify supplier cybersecurity requirements before the tender
Decide the baseline a supplier must meet before you invite bids: email authentication, encryption, vulnerability management, incident notification and evidence expectations. Writing this down turns 'trust us' into measurable criteria you can score every bidder against.
Assess candidates from the outside before you sign
Before a contract, check the supplier's public security posture: email spoofability (SPF/DMARC), certificate hygiene, internet-exposed systems and any leaked-credential exposure. This pre-contract due diligence flags high-risk suppliers while you can still choose a different one, without needing access to their systems.
Put security into the contract
Turn the requirements into clauses: the measures the supplier must maintain, the right to evidence, breach-notification timelines and sub-supplier obligations. This is where ENISA's requirements for suppliers become enforceable rather than aspirational.
Monitor continuously, not once
A supplier that looked fine at signing drifts: a certificate expires, a new system is exposed, credentials leak. The guidelines cover the whole lifecycle for a reason. Continuous external monitoring keeps the posture honest for the life of the contract, instead of a snapshot that ages.
Record the decision and keep the evidence
Document the go/no-go decision, the requirements checked and the evidence behind it. For an essential entity this is both good procurement and the accountability trail NIS2 expects: you can show what you assessed, when, and why you accepted or rejected a supplier.
See how you and your suppliers actually score
7-day free trial · no credit card · cancel anytime
How norppa operationalises this
norppa was built for exactly this supply-chain duty. It assesses a candidate supplier's external security posture before you sign (a pre-contract verdict without consuming a monitoring slot), records the procurement go/no-go decision with a justification, sends a structured questionnaire for the requirements suppliers must attest to, and then monitors each supplier continuously across 100+ automated checks, mapping every finding to the relevant NIS2 article. The result is the documented, lifecycle-long evidence trail the ENISA guidelines describe, without an IT project or access to the supplier's systems.
Common mistakes
- ✕Treating security as a one-off box at onboarding, when the guidelines cover the whole contract lifecycle.
- ✕Writing 'must be secure' into a tender with no measurable, checkable criteria.
- ✕Assessing only the supplier's questionnaire answers, never the external reality behind them.
- ✕Keeping no record of why a supplier was accepted, leaving no accountability trail for auditors or regulators.
Assess a healthcare supplier before you sign
See a sample supplier report (findings, NIS2 mapping and evidence) in two minutes.
7-day free trial · no credit card · cancel anytime
Related guides
How to comply with NIS2: a step-by-step roadmap
The steps to NIS2 compliance in order: confirm scope, register, management accountability (Art. 20), the Article 21(2) measures, supply-chain security, incident reporting (Art. 23) and continuous, evidenced assurance.
Who is in scope for NIS2? Essential vs important entities, sectors and size thresholds
Determine whether NIS2 applies to you: the two tiers, the Annex I/II sectors, the size thresholds, size-independent exceptions, and how the supply chain pulls you in even if you're not designated.
NIS2 for suppliers: you're not designated, but your customers are
Most companies are never designated under NIS2, yet many must comply anyway. How a covered customer's Article 21(2)(d) supply-chain duty flows down to you, what they'll ask for, and how to respond credibly.
NIS2 and the supply chain requirement: what it means in practice
NIS2 requires essential and important entities to assess their supply chain cyber risks. Supplier tiering, 4th-party risk, Art. 23 notification, and what auditors look for.
How a breach happens in 2026: your external surface and your supply chain
The 2026 attack chain step by step — stolen credentials, exploited edge devices, email spoofing — across both your own external surface and your suppliers', and where norppa.io breaks the chain.
Supplier cyber risk assessment: what automated NIS2 monitoring checks
All check categories explained: ransomware, dark web leaks, TLS/DNSSEC, cookie security, CVE/EPSS, sanctions, MX blacklists and SAQ. Finding lifecycle and NIS2 article mapping.
NIS2 Art. 21(2): supplier security checklist
Checklist for procurement and security teams: what to ask, what evidence to collect, and how to respond when a supplier falls short. Includes suggested evidence documents.
NIS2 supplier questionnaire (SAQ): what to ask, how to score it, and a free template
What to ask suppliers under Art. 21(2)(d), how to score answers and respond to gaps, why self-attestation needs verification, and a free copy-paste questionnaire template.
NIS2 incident reporting: the 24- and 72-hour deadlines explained
What counts as a significant incident, the Article 23 timeline (24-hour early warning, 72-hour notification, one-month final report), and when a supplier's incident becomes your obligation.
NIS2 and management responsibility: what boards and leadership must know
What NIS2 expects of the management body: approval and oversight duties, personal liability (Art. 20), training, board reporting KPIs, and the penalties under Art. 34.
ISO 27001 and NIS2: what your ISMS already covers, and the gaps it doesn't
If you hold ISO 27001, what carries over to NIS2 and what does not: statutory incident reporting, management liability, registration, and continuous supply-chain assurance: plus how to close the gap.
NIS2 fines and penalties: how much, who is liable, and how to avoid them
What NIS2 penalties are: the Article 34 caps (€10M / 2% for essential, €7M / 1.4% for important entities), the management body's personal liability (Art. 20, Art. 32), non-monetary enforcement, and how to avoid them with continuous, evidenced diligence.
NIS2 vs DORA: how they differ, where they overlap, and which one applies to you
How the two EU regimes differ and overlap, why DORA is lex specialis for financial entities, which applies to you, and what both mean for third-party and supply-chain risk.
GDPR vs NIS2: how they overlap, where they differ, and when one incident triggers both
How GDPR and NIS2 differ and overlap, when one incident triggers both (GDPR Art. 33 72h to the DPA vs NIS2 Art. 23 24h/72h/1-month to the CSIRT), the Art. 35 cooperation and no-double-fine rule, and what both mean for supplier due diligence.
The EU Cyber Resilience Act (CRA): scope, timeline and what it means for your supply chain
What the CRA requires, its phased dates (in force 2024, reporting Sept 2026, full compliance Dec 2027), who is in scope and why pure SaaS often isn't, how it complements NIS2, and what it means for procurement and supplier due diligence.
The EU AI Act: risk tiers, the timeline, and what deployers must do (Article 26)
What the EU AI Act requires: the risk tiers, the phased dates (in force 2024, prohibited Feb 2025, GPAI Aug 2025, high-risk Aug 2026), the Article 26 deployer obligations, how it stacks with NIS2 and the GDPR, and what it means for AI procurement.
NIS2 transposition status: which EU countries have it in force
Which of the 27 EU Member States have written NIS2 into national law and which are still finalising it, and why the gaps reach your supply chain regardless.
NIS2 supplier contract clauses: what to require from your suppliers
The contract clauses that turn NIS2's supply-chain duty into something enforceable: security baseline, incident-notification window, evidence and audit rights, subcontractor flow-down, and how to verify them continuously.
Your external security posture under NIS2: what suppliers and customers can see
The publicly visible signals customers assess under NIS2 Art. 21(2)(d): email spoofability (SPF/DMARC), certificate hygiene, internet-exposed systems and leaked credentials, why each matters and how to check and fix them.
Do your suppliers use AI? NIS2 supplier risk meets the EU AI Act
Suppliers increasingly embed AI in the services you depend on, and so do their suppliers. Where supplier and nth-party AI creates risk under NIS2 Art. 21(2)(d) and the EU AI Act, what to assess, and how to keep visibility.
Vendor impersonation and CEO-fraud (BEC): email spoofing, DMARC and NIS2
One of the most common supply-chain attacks needs no breach: spoofed email that redirects a payment or steals data. How BEC and vendor impersonation work, the SPF, DKIM and DMARC settings that stop them, and how it fits NIS2 Art. 21(2)(d).
Last reviewed: 19 June 2026
This guide is general information about EU law, not legal advice. NIS2 takes effect through each EU Member State's national transposition law, which can differ in detail. Verify the obligations that apply to you with your competent authority or legal counsel.