← Back to blog
5 August 20267 min read

NIS2 supply chain assessment: how to assess the cybersecurity of your suppliers

What NIS2 requires from you as a buyer

NIS2 (Directive (EU) 2022/2555) requires essential and important entities to actively assess and contractually secure the cybersecurity of their supply chain — Art. 21(2)(d).

In Germany, NIS2 was transposed as the NIS2UmsuCG, in force since 6 December 2025. The supervisory authority is the BSI (Bundesamt für Sicherheit in der Informationstechnik), Germany's Federal Office for Information Security — broadly comparable to the UK's NCSC or the US's CISA. In the UK, the Cyber Security and Resilience Bill is progressing through Parliament as the closest domestic equivalent.

What you need to demonstrate: that you have established which cybersecurity measures your critical suppliers have implemented, and that you have documented that assessment. An email asking "are you secure?" is not documentation.

The ten areas of an NIS2 supply chain assessment

NIS2 Art. 21 defines ten security areas. A structured supply chain assessment questions your suppliers on each of these, rather than asking one generic question.

CY1 — Risk management. Is there a documented cybersecurity risk policy, reviewed at least annually?

CY2 — Incident management. Is there a documented incident-response procedure, and can the supplier notify you of security incidents within 24 hours?

CY3 — Business continuity. Are there a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP), tested at least annually?

CY4 — Supply chain security. Has the supplier in turn built cybersecurity requirements into contracts with its own suppliers, and does it assess their cybersecurity?

CY5 — Secure development, software suppliers only. Are security-by-design principles applied, with regular penetration testing? Non-software companies can mark this as not applicable without losing points.

CY6 — Vulnerability management. Is there a formal patch-management process, with critical patches applied within 14 days?

CY7 — Cyber hygiene and training. Do staff receive cybersecurity training at least annually, and is there an acceptable use policy for IT systems?

CY8 — Cryptography. Is sensitive data encrypted at rest and in transit (HTTPS/TLS)?

CY9 — Access management and HR security. Is multi-factor authentication enabled on critical systems, is least-privilege applied, and is there an offboarding procedure for departing staff?

CY10 — Certifications, optional but valuable. Does the supplier hold ISO/IEC 27001, SOC 2 Type II, Cyber Essentials or TISAX? These add bonus points to the maturity score but are not a prerequisite for a good assessment.

The problem with proprietary questionnaires

Many procurement teams send their own Excel questionnaire to suppliers. In practice, that produces three systematic problems.

Inconsistent answers — suppliers interpret the same question differently. "Do you have a firewall?" means something different to an IT services provider than to a small manufacturer.

No comparability — without a common scoring scale you cannot compare supplier A against supplier B. You get answers, not a score.

No audit-ready documentation — a completed spreadsheet sent by email is not evidence a supervisory authority will readily accept during an audit. You need a structured, dated, archivable assessment — a standardised maturity score, calculated with the same weighted criteria for every supplier, solves all three problems at once.

How verified.supply standardises the NIS2 assessment

verified.supply implements the NIS2 assessment as a structured questionnaire across the ten CY areas — completed directly by the supplier, no IT expertise required. The result is a maturity score from 0 to 100, weighted to the risk priorities of NIS2 Art. 21.

Access management (CY9) contributes 16 of the 100 points — the highest weight, because identity is the most common attack surface. Incident management (CY2) and cryptography (CY8) each contribute 14 points. Risk management (CY1) contributes 12 points; business continuity (CY3), vulnerability management (CY6) and cyber hygiene (CY7) each contribute 10 points; supply chain security (CY4) contributes 8 points; secure development (CY5) contributes 6 points. CY5 gets full credit when marked not applicable, so non-software companies are not penalised. CY10 certifications are deliberately excluded from the score — a certificate is evidence of the underlying measures, not an eleventh measure — and appear separately as a bonus on the profile.

As a buyer, you invite your suppliers through the enterprise dashboard. You see each supplier's maturity score and per-area status, and can export a consolidated report — structured, dated and suitable as evidence for a regulatory audit.

Cross-border: what if your supplier or client is German?

If you source from German suppliers, those suppliers may already be registered with the BSI under the NIS2UmsuCG. You can request a standardised cybersecurity assessment from them regardless of your own NIS2 status.

The reverse is just as common: if you supply into large German companies, you should expect a questionnaire based on the NIS2UmsuCG framework. BSI enforcement is already active — this is not a future obligation but a present risk to your German client relationships.

verified.supply's NIS2 assessment produces output that satisfies German NIS2UmsuCG documentation requirements — the same ten themes, the same weighted maturity score, one profile valid whether your auditor sits in Amsterdam, London, Dublin or Munich.

Read also

Build your VS profile (formerly VSME) once

Create an account and get started today.

No password needed — we email you a login link.