Back to News
    NIS2

    NIS2 Value Chain Obligations: What Suppliers Actually Need to Provide.

    The NIS2 Directive (Directive (EU) 2022/2555) raises the cybersecurity bar for essential and important entities across the EU. One of its less visible effects is a wave of supplier requirements landing on companies that are not themselves in direct scope. This article explains what NIS2 actually requires regarding the value chain, what suppliers are typically being asked for, and how to prepare without overcommitting.

    Why this matters.

    Article 21 of NIS2 requires essential and important entities to take appropriate technical, operational and organisational measures to manage cybersecurity risks — explicitly including risks stemming from their value chain and supplier relationships.

    In practice, this means that a hospital, energy company, cloud provider or large manufacturer is now formally accountable for the security posture of the suppliers that support its critical services. That accountability is being passed downstream as contractual clauses, security questionnaires and evidence requests.

    Who is affected.

    Two groups should pay attention:

    • Entities directly in scope of NIS2 (essential and important), which need to demonstrate that they assess and manage value-chain risk.
    • Suppliers to those entities — including SMEs that are not themselves in scope — which are increasingly required to provide security evidence as a condition of doing business.

    What data and evidence companies should prepare.

    Customers in scope of NIS2 typically ask suppliers for evidence aligned to Article 21(2), which lists the minimum risk-management measures. A pragmatic supplier evidence pack covers:

    • Information security policies and an overview of the risk-management framework in use.
    • Incident handling: how incidents are detected, classified, escalated and reported, including notification timelines to customers.
    • Business continuity and backup arrangements, including recovery objectives for services delivered to the customer.
    • Supply chain security: how the supplier in turn assesses its own subcontractors and software providers.
    • Vulnerability handling and patching: SLAs, severity classification and evidence of remediation.
    • Access control, MFA and the use of secured communications, where relevant to the service.
    • Use of cryptography and, where appropriate, encryption of data in transit and at rest.
    • Training and awareness programmes for staff with access to customer systems or data.

    How Regweaver helps.

    Regweaver maps customer requests and the underlying NIS2 measures to a structured set of controls and evidence items. Suppliers can maintain one operational view of what is in place, who owns it and what evidence is current — and reuse it when the next customer questionnaire arrives.

    For entities in direct scope, Regweaver supports the value-chain assessment side: tracking which suppliers have provided which evidence, where gaps exist and where follow-up is needed. The platform does not replace the security tools themselves; it organises the obligations and the evidence around them.

    Key takeaway

    NIS2 turns supplier security from a procurement nice-to-have into a documented obligation. Suppliers that prepare a structured, reusable evidence pack will spend less time on questionnaires and win more business with regulated customers.

    This article is for informational purposes only and does not constitute legal advice.

    Related reading