Supply chain security under NIS2 Art. 21(d) is one of the central requirements of the directive: organisations must systematically manage the security not only of their own systems but also of their suppliers and service providers.
What does NIS2 Art. 21(d) concretely require?
NIS2 Art. 21(d) requires 'supply chain security including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers'. Concretely: complete supplier inventory, risk classification of all suppliers, due diligence before contract, continuous monitoring of critical suppliers, security requirements in supplier contracts and documented evidence for supervisory authorities.
62% aller Cyberangriffe erfolgen über die Lieferkette (IBM 2023). NIS2 reagiert darauf mit verbindlichen Anforderungen — nicht mit Empfehlungen.
360TPRM as NIS2 supply chain security platform
360TPRM is the technical solution for NIS2 Art. 21(d): automatic supplier inventory and classification, continuous cyber intelligence monitoring of all suppliers, automated risk assessments and compliance evidence, NIS2-compliant documentation and audit reports, and immediate alerts on risk escalations.
360TPRM wurde entwickelt um NIS2-Lieferkettensicherheitsanforderungen vollständig zu erfüllen — von der Erstbewertung bis zum kontinuierlichen Monitoring.
FAQ
Implement NIS2 supply chain security
See in a 45-minute demo how 360TPRM specifically meets your requirements.
Request free demo →