← Back to blog
5 August 20267 min read

NIS2 supply chain assessment: how to assess the cybersecurity of your suppliers

What NIS2 requires from you as a buyer

NIS2 (Directive (EU) 2022/2555) requires essential and important entities to actively assess and contractually secure the cybersecurity of their supply chain — Art. 21(2)(d).

In Germany, NIS2 was transposed as the NIS2UmsuCG, in force since 6 December 2025. The supervisory authority is the BSI (Bundesamt für Sicherheit in der Informationstechnik), Germany's Federal Office for Information Security — broadly comparable to the UK's NCSC or the US's CISA. In the UK, the Cyber Security and Resilience Bill is progressing through Parliament as the closest domestic equivalent.

What you need to demonstrate: that you have established which cybersecurity measures your critical suppliers have implemented, and that you have documented that assessment. An email asking "are you secure?" is not documentation.

The ten areas of an NIS2 supply chain assessment

NIS2 Art. 21 defines ten security areas. A structured supply chain assessment questions your suppliers on each of these, rather than asking one generic question.

CY1 — Risk management. Is there a documented cybersecurity risk policy, reviewed at least annually?

CY2 — Incident management. Is there a documented incident-response procedure, and can the supplier notify you of security incidents within 24 hours?

CY3 — Business continuity. Are there a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP), tested at least annually?

CY4 — Supply chain security. Has the supplier in turn built cybersecurity requirements into contracts with its own suppliers, and does it assess their cybersecurity?

CY5 — Secure development, software suppliers only. Are security-by-design principles applied, with regular penetration testing? Non-software companies can mark this as not applicable without losing points.

CY6 — Vulnerability management. Is there a formal patch-management process, with critical patches applied within 14 days?

CY7 — Cyber hygiene and training. Do staff receive cybersecurity training at least annually, and is there an acceptable use policy for IT systems?

CY8 — Cryptography. Is sensitive data encrypted at rest and in transit (HTTPS/TLS)?

CY9 — Access management and HR security. Is multi-factor authentication enabled on critical systems, is least-privilege applied, and is there an offboarding procedure for departing staff?

CY10 — Certifications, optional but valuable. Does the supplier hold ISO/IEC 27001, SOC 2 Type II, Cyber Essentials or TISAX? These add bonus points to the maturity score but are not a prerequisite for a good assessment.

NIS2 supplier assessment vs. NIS2 supply chain assessment: is it the same thing?

In practice the terminology overlaps: NIS2 supply chain assessment, NIS2 supplier assessment, NIS2 supplier risk review, NIS2 vendor questionnaire. These all describe the same underlying obligation from Art. 21(2)(d) — the label changes by organisation, not by process.

"Supply chain assessment" tends to appear in policy documents and formal procurement language; "supplier assessment" and "vendor risk review" are the terms procurement teams use day to day. Whichever term you search for, you mean the same thing: structurally establishing and documenting a supplier's cybersecurity maturity.

As a supplier, the label makes no difference to you: a review against the ten CY areas above answers virtually any variant of the questionnaire a client sends you, regardless of what they call it.

The problem with proprietary questionnaires

Many procurement teams send their own Excel questionnaire to suppliers. In practice, that produces three systematic problems.

Inconsistent answers — suppliers interpret the same question differently. "Do you have a firewall?" means something different to an IT services provider than to a small manufacturer.

No comparability — without a common scoring scale you cannot compare supplier A against supplier B. You get answers, not a score.

No audit-ready documentation — a completed spreadsheet sent by email is not evidence a supervisory authority will readily accept during an audit. You need a structured, dated, archivable assessment — a standardised maturity score, calculated with the same weighted criteria for every supplier, solves all three problems at once.

What measures does a supplier actually need to take?

If you are not yourself an essential or important entity under NIS2, the directive imposes no direct legal obligation on you. But if you supply a client who is in scope, that client passes the requirement down contractually: Art. 21(2)(d) obliges them to assess and secure your cybersecurity, and in practice that becomes a clause in your supplier contract or a tender condition.

The ten CY areas above are, in practice, the baseline a client expects. A documented risk policy (CY1), an incident procedure with a notification deadline (CY2), continuity plans (CY3), multi-factor authentication and access management (CY9), and encryption of sensitive data (CY8) are the five most questionnaires start with.

A practical checklist: (1) map which of the ten CY areas you already have in place; (2) fill the gaps with a basic policy document — for a risk policy or an acceptable use policy, half a page is often enough; (3) record when each was last reviewed, since "reviewed at least annually" is an explicit requirement for nearly every area; (4) when in doubt, ask your client which framework they actually expect — their own questionnaire, or a recognised quality mark such as the one below.

How verified.supply standardises the NIS2 assessment

verified.supply implements the NIS2 assessment as a structured questionnaire across the ten CY areas — completed directly by the supplier, no IT expertise required. The result is a maturity score from 0 to 100, weighted to the risk priorities of NIS2 Art. 21.

Access management (CY9) contributes 16 of the 100 points — the highest weight, because identity is the most common attack surface. Incident management (CY2) and cryptography (CY8) each contribute 14 points. Risk management (CY1) contributes 12 points; business continuity (CY3), vulnerability management (CY6) and cyber hygiene (CY7) each contribute 10 points; supply chain security (CY4) contributes 8 points; secure development (CY5) contributes 6 points. CY5 gets full credit when marked not applicable, so non-software companies are not penalised. CY10 certifications are deliberately excluded from the score — a certificate is evidence of the underlying measures, not an eleventh measure — and appear separately as a bonus on the profile.

As a buyer, you invite your suppliers through the enterprise dashboard. You see each supplier's maturity score and per-area status, and can export a consolidated report — structured, dated and suitable as evidence for a regulatory audit.

Are you the one carrying out the assessment? Our page on the supplier cybersecurity assessment criteria for buyers sets out how much each CY area weighs into the maturity score and how you compare suppliers side by side.

Audits and certification: what do SC10, SC20 and SC30 mean?

Beyond the legal obligation in Art. 21(2)(d) — which prescribes no fixed certification format — a private quality mark for suppliers has emerged in the Netherlands: "NIS2 Supply Chain", with three tiers (SC10, SC20, SC30) offered by several accredited audit providers. This mark is not part of the NIS2 directive itself; it is a market initiative that lets a supplier prove, through an independent audit, that it meets a fixed set of requirements.

SC10 (Basic) targets smaller suppliers with limited risk who supply directly to a NIS2-obligated client. SC20 (Substantial) is for suppliers with an elevated risk profile, for example access to sensitive systems or data. SC30 (High) is for critical links in the chain where disruption has major consequences, and closely mirrors a full ISO/IEC 27001 certification. Certification at any tier requires an independent audit — it is not a self-declaration.

Want to know which tier fits your role in the chain, and how to prepare for both a client questionnaire and a possible SC certification? See our in-depth article on NIS2 SC10 and SC30: what these classifications mean for suppliers.

One distinction matters here: the NIS2 assessment you complete through verified.supply is not a substitute for an SC10/SC20/SC30 certificate, but it covers the same underlying areas and gives you the documented foundation that makes any certification process faster.

Cross-border: what if your supplier or client is German?

If you source from German suppliers, those suppliers may already be registered with the BSI under the NIS2UmsuCG. You can request a standardised cybersecurity assessment from them regardless of your own NIS2 status.

The reverse is just as common: if you supply into large German companies, you should expect a questionnaire based on the NIS2UmsuCG framework. BSI enforcement is already active — this is not a future obligation but a present risk to your German client relationships.

verified.supply's NIS2 assessment produces output that satisfies German NIS2UmsuCG documentation requirements — the same ten themes, the same weighted maturity score, one profile valid whether your auditor sits in Amsterdam, London, Dublin or Munich.

Frequently asked questions

What are NIS2 SC10 and SC30, and what do these classifications mean for suppliers?
SC10, SC20 and SC30 are three tiers of a private Dutch quality mark ("NIS2 Supply Chain") — not an official classification from the NIS2 directive itself. SC10 (Basic) targets smaller suppliers with limited risk, SC20 (Substantial) suppliers with elevated risk or access to sensitive data, and SC30 (High) critical links in the chain. Certification at any tier requires an independent audit.
What measures must a supplier take to be NIS2 compliant?
Formally, NIS2 only obliges essential and important entities, not their suppliers directly. In practice, a NIS2-obligated client will expect the ten CY areas to be in place through its procurement terms: a risk policy, 24-hour incident notification, continuity plans, MFA-based access management, and encryption of sensitive data are the most commonly requested.
How is a supplier assessed or certified under NIS2?
There are two routes: a client assesses your cybersecurity maturity directly, for example through a platform like verified.supply, across the ten CY areas — or you obtain independent certification under a quality mark such as SC10/SC20/SC30. Both routes test largely the same underlying measures.
What is the difference between a "NIS2 supply chain assessment" and a "NIS2 supplier assessment"?
Nothing in substance — both describe the same obligation under Art. 21(2)(d): a client structurally establishing and documenting which cybersecurity measures its suppliers have taken. The terms are used interchangeably across policy documents and procurement teams.

Read also

Build your VS profile (formerly VSME) once

Create an account and get started today.

No password needed — we email you a login link.