01
Supply chain security
Risk management must extend to relationships with direct suppliers and service providers — which for software means knowing your dependencies, assessing the components you consume, and being able to answer for them.
Directive (EU) 2022/2555
NIS2 requires essential and important entities to manage cybersecurity risk with appropriate technical and organisational measures. Two of those measure areas land directly on software teams: supply chain security, and security in the acquisition, development and maintenance of systems — including vulnerability handling and disclosure.
16 January 2023
Directive entered into force
17 October 2024
Member State transposition deadline
18 October 2024
National laws apply — obligations now live
Primary source: Directive (EU) 2022/2555 on EUR-Lex · Last reviewed 14 August 2026
Scope depends on your entity, sector and — for directives — national transposition. This page is informational, not legal advice.
We produce technical evidence and control narratives. We do not certify your compliance — that remains with you and your auditors.
01
Risk management must extend to relationships with direct suppliers and service providers — which for software means knowing your dependencies, assessing the components you consume, and being able to answer for them.
02
Security has to be embedded across the lifecycle of network and information systems, not applied as a final gate before release.
03
You need a defined process for receiving, triaging, remediating and — where relevant — disclosing vulnerabilities, with evidence that it operates.
04
Management bodies are expected to approve and oversee risk-management measures, which is why these programmes now require reporting that an executive committee can read.
Map your software estate against the measure areas that apply to your entity
Establish dependency inventory and supply chain governance with continuous SBOM
Integrate secure development controls into the lifecycle rather than beside it
Build the vulnerability handling workflow with owners, SLAs and an auditable trail
No. NIS2 is a directive, so it takes legal effect through each Member State's national transposition. The core measure areas converge, but thresholds, registration duties, supervisory regimes and penalties are defined nationally. Scope must be assessed against the law of the Member States where you operate.
Often, in two ways. ICT service management is itself a listed sector, so you may be in direct scope. And independently of that, your regulated customers must manage supply chain risk — so their obligations reach you contractually, through security requirements and due-diligence questionnaires.
The directive sets measure areas, not a document template. In practice supervisors look for demonstrable process: what you assessed, how you prioritized, who owned remediation, and evidence that it happened. That is the artifact set we build.
We link legal texts and standards directly. This page is informational and is not legal advice; obligations depend on your entity, sector and national transposition.
A scoped assessment maps your estate to the obligations that actually apply to your entity — and produces the evidence trail.