NIS2 requires you to assess suppliers on cybersecurity — but against which criteria? This page lays out the assessment framework: the ten CY areas of Art. 21, how much each one weighs, and how verified.supply condenses them into a single maturity score (0–100) to compare suppliers side by side.
No password needed — we email you a login link.
The assessment criteria at a glance
NIS2 Art. 21(2)(d) requires you to actively assess the cybersecurity of your suppliers and secure it contractually. Failing to do so is an enforcement risk.
Your own questionnaire produces inconsistent answers. Suppliers tick yes without evidence. Comparison is impossible. A maturity score based on a standardised assessment does make comparison possible.
Through your enterprise dashboard you invite suppliers to the NIS2 module. You see the maturity score (0-100) per supplier and the status per theme. Export an overview for your procurement team or compliance department.
NIS2 makes cybersecurity in the chain a legal responsibility of the buyer. A standardised maturity score makes that assessment demonstrable and comparable.
Read more
Invite suppliers to a single standardised assessment framework and compare them on maturity score.
No password needed — we email you a login link.