What is it?
NIS2 is the EU's revised Network and Information Security Directive. It applies to a much wider set of organisations than the original NIS — most medium and large entities in essential and important sectors — and it makes supply-chain security an explicit obligation.
For in-scope organisations, that means the security of ICT suppliers is no longer a purely internal concern. Regulators expect documented supplier assessments and ongoing oversight.
Why does it matter?
NIS2 introduces personal liability for management bodies and administrative penalties comparable to GDPR. Supplier risk is called out specifically as a required area of cybersecurity risk management. Weak supplier oversight is now a documented compliance failure, not a background operational concern.
Common challenges
- Uncertainty about scope — organisations often discover late that they qualify as an "important entity".
- Treating NIS2 as an IT project rather than a governance obligation.
- No baseline for what "adequate" supplier security actually looks like in practice.
- Existing supplier assessments not designed to produce NIS2-defensible evidence.
Best practice
For each in-scope supplier, an NIS2-aligned assessment should cover, with evidence:
- Governance and accountability for cybersecurity within the supplier organisation.
- Risk management policies proportionate to what the supplier does for you.
- Incident handling, including notification timelines that support your own reporting obligations.
- Business continuity and crisis management.
- Supply-chain security — the supplier's own approach to its suppliers.
- Basic cyber hygiene, encryption, access control and authentication.
- The security of the specific product or service you are procuring.
The assessment must be repeatable and documented. Regulators will ask what you asked, what evidence you saw, and what decision you made.
How Governly supports this area
Governly's assessment workflow produces exactly this record: a versioned assessment with each requirement, the vendor evidence that supports it, and the resulting decision. Organisations aligning to NIS2 typically use the Recommended Enterprise Baseline as a starting point and adapt it to their own scope and risk appetite.