Supply chain guide

Supply chain guide · 9 min

NIS2's binding technical requirements for cloud, MSP and DNS suppliers (Regulation 2024/2690)

Most of NIS2 is a directive, which each country writes into its own law, and that is why so many supplier conversations still end in "we are waiting for the national act". For one group of suppliers that is not true. Commission Implementing Regulation (EU) 2024/2690 has applied directly in all 27 member states since October 2024, and it replaces the general language of Article 21 with thirteen sections of specific technical requirements. If you buy cloud, managed services, DNS, data centre or trust services, your supplier already carries these obligations, and you can ask for evidence today.

Check your domain now

See what's publicly visible about your organisation's security, no sign-up.

This instant preview checks:

  • HTTPS reachable
  • HSTS enabled
  • HTTP → HTTPS redirect
  • SPF configured
  • DMARC enforced
  • Mail (MX) configured

The full report adds ransomware, dark web, certificates, company intel and 100+ more controls.

Key takeaways

  • The regulation applies directly in every member state. There is no national law to wait for.
  • It names eleven kinds of provider, including managed service and managed security service providers.
  • Six of its thirteen requirement areas leave traces you can check from outside. The other seven have to be asked.

Which suppliers it covers

The regulation does not apply to every entity under NIS2. It applies to eleven kinds of provider in three groups, and the list is worth reading closely, because two of the groups describe suppliers that almost every company now depends on.

Digital infrastructure

DNS service providers, top-level domain name registries, cloud computing services, data centre services, content delivery networks, trust service providers

ICT service management

Managed service providers, managed security service providers

Digital service providers

Online marketplaces, online search engines, social networking platforms

Official source: Commission Implementing Regulation (EU) 2024/2690 — adopted 17 October 2024, applicable directly in all member states. Reviewed 13 August 2026.

Why this one is different from the rest of NIS2

NIS2 itself is a directive: it sets objectives, and each member state turns them into national law on its own timetable. That is the honest reason most supplier requirements are still negotiated rather than cited. An implementing regulation works the other way round. It applies as written, in every member state, without any national step in between. So for these eleven kinds of provider there is no transposition to wait for and no national variation to argue about, and the requirements are itemised rather than described in principle.

See how you and your suppliers actually score

Free · no credit card · no expiry

The thirteen requirement areas

The annex sets out thirteen areas. Read as a buyer, they divide into three kinds: the ones that leave traces on the public internet, the ones that leave partial traces, and the ones that exist only inside the supplier's organisation.

  • 1Policy on the security of network and information systemsHas to be asked
  • 2Risk management policyHas to be asked
  • 3Incident handlingHas to be asked
  • 4Business continuity and crisis managementHas to be asked
  • 5Supply chain securityPartly visible
  • 6Security in acquisition, development and maintenanceVisible from outside
  • 7Assessing the effectiveness of the measuresPartly visible
  • 8Basic cyber hygiene and security trainingHas to be asked
  • 9CryptographyVisible from outside
  • 10Human resources securityHas to be asked
  • 11Access controlPartly visible
  • 12Asset managementVisible from outside
  • 13Environmental and physical securityHas to be asked

What you can verify, and what you cannot

This is the part worth being precise about, because a supplier assessment that claims more than it can see is worse than one that admits its limits. Seven of the thirteen areas cannot be observed from outside at all.

Visible from outside

Three areas leave direct traces. Maintenance and patching show up as known vulnerabilities in exposed services. Cryptography shows up as certificate validity and the strength of the TLS configuration. Asset management shows up as internet-facing systems the supplier may have forgotten, including subdomains and services nobody meant to leave open.

Partly visible

Three more are partly visible. Supply chain security can be sampled by seeing which third parties a supplier's own systems depend on. Access control can be sampled from exposed administrative interfaces and leaked credentials, though multi-factor authentication itself cannot be seen. The effectiveness of the measures is partly evidenced by whether external issues get fixed and stay fixed.

Has to be asked

Seven cannot be seen at all: policy, risk management, incident handling, continuity, training, human resources and physical security. No external check will ever evidence them, and a supplier questionnaire is the ordinary way to cover them. This is why the two belong together rather than as alternatives.

When an incident becomes notifiable

The regulation also specifies when an incident counts as significant, which is the point at which the supplier must notify its authority. The general criteria include financial loss above EUR 500 000 or five per cent of annual turnover, exfiltration of trade secrets, or death or considerable damage to health. Some provider types have their own thresholds: for DNS providers and TLD registries, for example, availability falling below 99.9 per cent, incorrect responses, or compromise of registration data. As a buyer this matters for one practical reason: it tells you what your supplier is obliged to report to a regulator, which is a useful floor for what you should expect them to report to you.

What to do with this

If you buy these services

Identify which of your suppliers fall into the eleven types. For most companies it is the cloud platform, the managed service provider and the domain registrar, and often a data centre or a CDN. Then split your assessment the way the regulation splits: check the six observable areas from outside continuously, and ask about the seven internal ones in writing. Cite the regulation rather than a preference, and keep both the answers and the external evidence, because a claim and a measurement disagreeing is itself the finding.

If you are one of these providers

The obligations apply to you directly and have done since 2024. The practical first move is to look at yourself the way a customer will: what is exposed, what has expired, which systems you no longer remember owning. Customers of yours are starting to ask for evidence rather than assurances, and the areas they can verify without asking are the ones where a gap is most embarrassing.

Frequently asked questions

Does this regulation apply to my company?

Only if your company is one of the eleven listed types: DNS, TLD registry, cloud, data centre, CDN, trust services, managed service or managed security service provider, online marketplace, search engine or social platform. If it is not, the regulation still matters to you as a buyer, because it defines what you may expect from suppliers of those services.

How does this relate to NIS2 Article 21?

Article 21 lists risk-management measures in general terms for all entities in scope. This regulation makes those measures specific for the eleven provider types it names, in thirteen itemised areas. Where it applies, it is the more precise instrument, and it applies without national transposition.

Can I verify a supplier's compliance from the outside?

Partly, and it is worth being exact about how much. Three areas leave direct external traces, three more leave partial traces, and seven exist only inside the organisation. So external checks can evidence roughly half and never the rest, which is why a questionnaire covering governance, training and continuity remains necessary alongside them.

See what your suppliers show from the outside

Check the observable half continuously and ask about the rest with a structured questionnaire, with every finding mapped to the article behind it.

Free · no credit card · no expiry

Free plan: the 39-question NIS2 questionnaire for up to 10 suppliers, public checks on your own domain, and DMARC monitoring for one domain.

Related guides

ENISA's hospital procurement cybersecurity guidelines: how to assess your suppliers

ENISA's July 2026 procurement guidelines make supplier cybersecurity part of healthcare buying. Turn them into concrete steps: specify requirements, assess candidates externally, contract, monitor and document, mapped to the NIS2 Article 21(2)(d) supply-chain duty.

How to comply with NIS2: a step-by-step roadmap

The steps to NIS2 compliance in order: confirm scope, register, management accountability (Art. 20), the Article 21(2) measures, supply-chain security, incident reporting (Art. 23) and continuous, evidenced assurance.

Who is in scope for NIS2? Essential vs important entities, sectors and size thresholds

Determine whether NIS2 applies to you: the two tiers, the Annex I/II sectors, the size thresholds, size-independent exceptions, and how the supply chain pulls you in even if you're not designated.

NIS2 for suppliers: you're not designated, but your customers are

Most companies are never designated under NIS2, yet many must comply anyway. How a covered customer's Article 21(2)(d) supply-chain duty flows down to you, what they'll ask for, and how to respond credibly.

NIS2 and the supply chain requirement: what it means in practice

NIS2 requires essential and important entities to assess their supply chain cyber risks. Supplier tiering, 4th-party risk, Art. 23 notification, and what auditors look for.

How a breach happens in 2026: your external surface and your supply chain

The 2026 attack chain step by step — stolen credentials, exploited edge devices, email spoofing — across both your own external surface and your suppliers', and where norppa.io breaks the chain.

Supplier cyber risk assessment: what automated NIS2 monitoring checks

All check categories explained: ransomware, dark web leaks, TLS/DNSSEC, cookie security, CVE/EPSS, sanctions, MX blacklists and SAQ. Finding lifecycle and NIS2 article mapping.

NIS2 Art. 21(2): supplier security checklist

Checklist for procurement and security teams: what to ask, what evidence to collect, and how to respond when a supplier falls short. Includes suggested evidence documents.

NIS2 supplier questionnaire (SAQ): what to ask, how to score it, and a free template

What to ask suppliers under Art. 21(2)(d), how to score answers and respond to gaps, why self-attestation needs verification, and a free copy-paste questionnaire template.

NIS2 incident reporting: the 24- and 72-hour deadlines explained

What counts as a significant incident, the Article 23 timeline (24-hour early warning, 72-hour notification, one-month final report), and when a supplier's incident becomes your obligation.

NIS2 and management responsibility: what boards and leadership must know

What NIS2 expects of the management body: approval and oversight duties, personal liability (Art. 20), training, board reporting KPIs, and the penalties under Art. 34.

ISO 27001 and NIS2: what your ISMS already covers, and the gaps it doesn't

If you hold ISO 27001, what carries over to NIS2 and what does not: statutory incident reporting, management liability, registration, and continuous supply-chain assurance: plus how to close the gap.

NIS2 fines and penalties: how much, who is liable, and how to avoid them

What NIS2 penalties are: the Article 34 caps (€10M / 2% for essential, €7M / 1.4% for important entities), the management body's personal liability (Art. 20, Art. 32), non-monetary enforcement, and how to avoid them with continuous, evidenced diligence.

NIS2 vs DORA: how they differ, where they overlap, and which one applies to you

How the two EU regimes differ and overlap, why DORA is lex specialis for financial entities, which applies to you, and what both mean for third-party and supply-chain risk.

GDPR vs NIS2: how they overlap, where they differ, and when one incident triggers both

How GDPR and NIS2 differ and overlap, when one incident triggers both (GDPR Art. 33 72h to the DPA vs NIS2 Art. 23 24h/72h/1-month to the CSIRT), the Art. 35 cooperation and no-double-fine rule, and what both mean for supplier due diligence.

The EU Cyber Resilience Act (CRA): scope, timeline and what it means for your supply chain

What the CRA requires, its phased dates (in force 2024, reporting Sept 2026, full compliance Dec 2027), who is in scope and why pure SaaS often isn't, how it complements NIS2, and what it means for procurement and supplier due diligence.

The EU AI Act: risk tiers, the timeline, and what deployers must do (Article 26)

What the EU AI Act requires: the risk tiers, the phased dates (in force 2024, prohibited Feb 2025, GPAI Aug 2025, high-risk Aug 2026), the Article 26 deployer obligations, how it stacks with NIS2 and the GDPR, and what it means for AI procurement.

NIS2 transposition status: which EU countries have it in force

Which of the 27 EU Member States have written NIS2 into national law and which are still finalising it, and why the gaps reach your supply chain regardless.

NIS2 supplier contract clauses: what to require from your suppliers

The contract clauses that turn NIS2's supply-chain duty into something enforceable: security baseline, incident-notification window, evidence and audit rights, subcontractor flow-down, and how to verify them continuously.

Your external security posture under NIS2: what suppliers and customers can see

The publicly visible signals customers assess under NIS2 Art. 21(2)(d): email spoofability (SPF/DMARC), certificate hygiene, internet-exposed systems and leaked credentials, why each matters and how to check and fix them.

Do your suppliers use AI? NIS2 supplier risk meets the EU AI Act

Suppliers increasingly embed AI in the services you depend on, and so do their suppliers. Where supplier and nth-party AI creates risk under NIS2 Art. 21(2)(d) and the EU AI Act, what to assess, and how to keep visibility.

Vendor impersonation and CEO-fraud (BEC): email spoofing, DMARC and NIS2

One of the most common supply-chain attacks needs no breach: spoofed email that redirects a payment or steals data. How BEC and vendor impersonation work, the SPF, DKIM and DMARC settings that stop them, and how it fits NIS2 Art. 21(2)(d).

Last reviewed: 19 June 2026

This guide is general information about EU law, not legal advice. NIS2 takes effect through each EU Member State's national transposition law, which can differ in detail. Verify the obligations that apply to you with your competent authority or legal counsel.