Supplier cybersecurity assessment criteria:
the yardstick you apply as a buyer

NIS2 MODULEverified.supply

NIS2 requires you to assess suppliers on cybersecurity — but against which criteria? This page lays out the assessment framework: the ten CY areas of Art. 21, how much each one weighs, and how verified.supply condenses them into a single maturity score (0–100) to compare suppliers side by side.

No password needed — we email you a login link.

Your obligation

Your NIS2 obligation as an essential or important entity

NIS2 Art. 21(2)(d) requires you to actively assess the cybersecurity of your suppliers and secure it contractually. Failing to do so is an enforcement risk.

The problem

The problem with your own questionnaires

Your own questionnaire produces inconsistent answers. Suppliers tick yes without evidence. Comparison is impossible. A maturity score based on a standardised assessment does make comparison possible.

The solution

How verified.supply solves this

Through your enterprise dashboard you invite suppliers to the NIS2 module. You see the maturity score (0-100) per supplier and the status per theme. Export an overview for your procurement team or compliance department.

ARTICLE 21(2)(d)

Assess your chain

NIS2 makes cybersecurity in the chain a legal responsibility of the buyer. A standardised maturity score makes that assessment demonstrable and comparable.

Read more

Set your cybersecurity assessment criteria

Invite suppliers to a single standardised assessment framework and compare them on maturity score.

No password needed — we email you a login link.