Does Your Cloud Supply Chain Comply with NIS2? CIR Annex 5 Creates a One-Level-Down Obligation
Cloud supply chain security is where most NIS2 compliance programmes discover their largest gap — not at the initial audit, but when inspectors ask for the cloud services contract.
Most organisations have completed the obvious steps: verified their cloud provider’s ISO/IEC 27001 certification, reviewed its penetration test summary, and confirmed it appears on their supplier register. What they have not done is check whether their contract with that provider contains the clause that Commission Implementing Regulation (EU) 2024/2690 (CIR 2024/2690) now explicitly requires: a provision flowing defined cybersecurity obligations down to the cloud provider’s own sub-processors.
Section 5 of the Annex to CIR 2024/2690 — hereafter CIR Annex 5 — makes the supply chain security obligation operational. Section 5.1.4(g) of the Annex requires that contracts with direct suppliers include requirements for subcontractors that mirror the obligations imposed on the direct supplier itself. For cloud services, this means: your contract with the cloud provider must require that provider to apply comparable security standards to its managed service vendors, CDN operators, and infrastructure sub-processors. You do not audit those third parties directly; your contract must require your cloud provider to do so.
There is a second structural complexity. Cloud providers are not merely your suppliers. Under Annex I of NIS2 Directive (EU) 2022/2555, cloud computing services are classified as digital infrastructure, making large cloud providers essential entities directly subject to NIS2 — and their own national competent authority (NCA) supervision, audit, and penalty exposure. That dual position creates two parallel sets of obligations that compliance teams need to understand separately.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
This guide covers both: what CIR Annex 5 requires from organisations using cloud services, how the one-level-down subprocessor cascade works in practice, why the physical data centre is a compliance dependency you need to document, and what your supplier register must contain to satisfy an NCA inspection.
This article is for: CISOs and IT security managers building or auditing cloud supply chain controls under Article 21(2)(d); compliance officers preparing documentation for NCA inspection; and legal and procurement teams drafting or reviewing cloud services agreements with NIS2 clauses. If you are a cloud provider seeking to understand your direct obligations as a NIS2-regulated essential entity, Section 4 addresses your dual position.
What Article 21(2)(d) Requires from Organisations Using Cloud Services
Article 21(2)(d) of NIS2 Directive 2022/2555 requires essential and important entities to implement measures that address:
“supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers.”
The phrase “direct suppliers or service providers” defines the scope of your primary obligation: you must assess the cloud provider you contract with, not every company behind it. Article 21(3) adds the substance of that assessment. Entities must evaluate “the vulnerabilities specific to each direct supplier and service provider” and assess “the overall quality of their products and cybersecurity practices and procedures, including their secure development procedures.”
In cloud terms, those three dimensions translate into concrete assessment activities. For CISOs and IT security managers, this means reviewing the cloud provider’s architecture for vulnerabilities specific to shared infrastructure: multi-tenancy isolation weaknesses, API authentication design, credential management architecture, and the provider’s CVE response timeline for components you depend on. For compliance officers, it means creating a documented assessment record for each cloud service in scope — certifications reviewed, gaps identified, and the date of assessment. That documentation is what an NCA inspector will request.
| Assessment dimension (Article 21(3)) | Cloud-specific application |
|---|---|
| Vulnerabilities specific to the supplier | Multi-tenancy isolation risk; shared API surface; identity and access architecture; certificate management weaknesses |
| Overall quality of cybersecurity practices | ISO/IEC 27001 scope and exclusions; SOC 2 Type II — which controls are in scope; penetration test coverage and findings |
| Secure development procedures | SDLC documentation availability; patch management SLA; CVE notification process and response timeline |
A common misunderstanding: NIS2 and CIR 2024/2690 do not legally require ISO 27001 from cloud suppliers. Certification is useful audit evidence of the cybersecurity quality assessment required by Article 21(3), but your obligation is the assessment itself, not any specific certificate. An organisation that has conducted a thorough, documented review of a cloud provider without a formal certification may be more compliant than one that ticked an ISO 27001 checkbox without understanding what scope it covers.
The proportionality principle in Article 21(1) applies throughout: measures must be “appropriate and proportionate” based on entity size, risk exposure, and the likelihood and severity of incidents. A small organisation using one SaaS productivity tool faces a different assessment depth than a critical infrastructure operator running core operational systems on IaaS. The proportionality judgment must itself be documented — NCAs do not accept undocumented proportionality decisions.
CIR Annex 5 and the One-Level-Down Obligation
CIR 2024/2690, which entered into force on 17 October 2024 and applies directly across all 27 EU member states without national transposition, elaborates Article 21(2)(d) into specific supply chain requirements through Section 5 of its Annex.
The CIR Annex has 13 sections, each mapping to one of NIS2’s cybersecurity measure areas. Section 5 — Supply Chain Security — establishes four categories of requirements that directly affect how organisations must manage cloud service relationships.
1. Supply chain security policy (Annex 5.1)
Entities must establish, implement, and apply a supply chain security policy governing relationships with direct suppliers. For cloud services, this policy must include supplier selection criteria — specifically, the cybersecurity practices expected, ability to meet security specifications, and capacity to diversify sources where critical single-provider dependencies exist.
2. Contractual security requirements (Annex 5.1.4)
Contracts with direct cloud suppliers must include defined terms covering: employee background verification and training requirements applicable to staff accessing your systems or data; incident notification obligations (timeline, content, escalation path); audit rights over the provider’s security programme; and vulnerability handling procedures with defined response SLAs.
3. The subcontractor cascade — Annex 5.1.4(g)
Section 5.1.4(g) of the Annex is the one-level-down provision. It requires that contracts include requirements “regarding subcontracting and, where the relevant entities allow subcontracting, cybersecurity requirements for subcontractors” that apply the same obligations as those imposed on the direct supplier.
For cloud services, this means your contract with the cloud provider must contain language requiring that provider to apply comparable security standards to the sub-processors it engages — the managed security operations centre handling its threat monitoring, the third-party CDN distributing your content, the co-location facility providing rack space. You are not required to audit those sub-processors directly. Your contract must create that obligation one level down.
What this clause must accomplish in practical contract terms (your legal team must adapt language to your jurisdiction and circumstances):
- Require the cloud provider to maintain and update its own sub-processor list
- Require that sub-processors meet security standards equivalent to those in your main contract
- Require notification when sub-processors are added, replaced, or substantially changed
- Grant audit rights over the cloud provider’s own sub-processor management process
4. Supplier registry (Annex 5.2)
CIR Annex 5.2 requires entities to maintain and keep current a registry of direct suppliers and service providers, including contact points and a list of ICT products, services, and processes each provides. This registry is the primary evidence document for an NCA Article 21(2)(d) inspection — see Section 6 for required fields.
Cloud Providers as Both NIS2 Entities and Critical Suppliers
The standard NIS2 supply chain discussion positions cloud providers solely as suppliers to regulated customers. The regulatory structure is more complex, and understanding that complexity matters for your compliance posture.
Cloud computing services appear in Annex I of Directive 2022/2555 as part of the “Digital Infrastructure” sector. This means a cloud provider meeting the large enterprise threshold — generally 250 or more employees, or €50 million or more in annual turnover — qualifies as an essential entity under NIS2. Smaller cloud providers may qualify as important entities under Annex II as digital providers. Either way, they are themselves directly regulated under Article 21, subject to their own NCA, and exposed to Article 34 penalty provisions.
This dual position creates two parallel compliance obligations running simultaneously.
The cloud provider as NIS2 entity must:
- Implement all 10 minimum measures under Article 21(2)(a)–(j) as a directly regulated entity
- Report significant incidents to its NCA within 24 hours (early warning), 72 hours (full notification), and one month (final report) — with thresholds defined specifically for cloud computing providers in Article 7 of CIR 2024/2690
- Maintain documented compliance evidence for NCA inspection and respond to unannounced audits
The cloud provider as critical supplier must:
- Meet the security requirements its NIS2-regulated customers impose contractually under Article 21(2)(d)
- Provide audit evidence — certifications, penetration test results, sub-processor lists — to allow customers to satisfy their own CIR Annex 5 obligations
- Flow cybersecurity requirements down to its own sub-processors under CIR Annex 5.1.4(g)
The critical insight for compliance officers: your cloud provider being itself NIS2-regulated does not reduce your Article 21(2)(d) due diligence obligation. Your NCA assesses your supply chain compliance independently of whether your cloud provider is in good standing with its own NCA. As Google Cloud has acknowledged explicitly, cloud providers bear responsibility both “as a covered entity” meeting their own regulatory requirements and “supporting customers along their compliance journeys” — these are distinct obligations, not substitutes for one another.
In practice, using a NIS2-regulated cloud provider creates four parallel compliance evidence trails: your own NIS2 compliance; your cloud provider’s own NIS2 compliance with its NCA; your documented assessment of the cloud provider under Article 21(2)(d); and your cloud provider’s management of its sub-processors under CIR Annex 5.1.4(g). Audit documentation must distinguish between all four.
See also the NIS2 digital infrastructure compliance guide for entity-type-specific implementation requirements applicable to cloud providers and data centre operators fulfilling their own NIS2 obligations.
Data Centre Physical Facility as a NIS2 Supply Chain Dependency
An underappreciated dimension of cloud supply chain risk is the physical infrastructure layer. When your critical workloads run on cloud infrastructure, your organisation’s resilience depends not only on the cloud provider’s cybersecurity but on the physical facilities those services operate from — facilities you typically have no direct relationship with.
Article 21(1) of NIS2 establishes an “all-hazards approach” that encompasses the physical environment of network and information systems. For cloud tenants, this creates a risk that most supply chain assessments fail to capture: failures at the physical layer — power failure, cooling failure, fire, or physical access breach — affect your services directly. In a shared cloud environment, a physical incident at one facility can affect hundreds of NIS2-regulated organisations simultaneously. NIS2’s Annex I classification of cloud computing as critical digital infrastructure reflects precisely this systemic concern.
Physical security standards that NCA-supervised cloud providers and data centre operators must demonstrate include:
- Multi-zone access control with MFA for server hall entry and complete access logging
- VESDA early fire detection with gas-based suppression (not water-based — to protect active equipment)
- Power redundancy from dual substation feeds with UPS and diesel backup carrying a minimum 48-hour fuel reserve
- N+1 or 2N redundant cooling with automated temperature and humidity monitoring
- Full perimeter camera coverage with minimum 30-day retention
These are not aspirational specifications — they are what BSI C5 and ISO/IEC 27001 certification audits verify when physical security is in scope. The gap between marketing claims and audit scope matters: a cloud provider certified against ISO 27001 may have excluded physical security from its certification scope.
For your CIR Annex 5 cloud supply chain assessment, document the physical dependency through three mechanisms:
- Data centre region disclosures — identify the geographic regions in which your cloud provider operates facilities for your workloads. This is relevant to GDPR data residency, NIS2 jurisdictional supervision, and disaster recovery planning.
- Certification scope review — confirm the provider’s third-party certifications include physical security scope. BSI C5 specifically addresses cloud physical infrastructure. ISO/IEC 27001 Annex A.7 (Physical and Environmental Security) must be in scope, not excluded.
- Infrastructure SLA verification — your contract’s availability SLA is the contractual proxy for physical resilience commitments. Understand what incidents the SLA covers and what credits it provides — these define your remediation path if the physical layer fails.
See the NIS2 data centre compliance guide for facility-specific requirements applicable to organisations operating their own infrastructure.
Enforcement, Audit Exposure and Management Liability for Cloud Supply Chain Gaps
Gaps in cloud supply chain documentation are among the most straightforward compliance failures for NCAs to identify during inspection. The evidence trail is simple to test: request the supplier register, the security assessment record for each cloud provider, the relevant contracts, and the sub-processor list review documentation. Gaps in any of these become direct audit findings.
NCAs conducting Article 21(2)(d) inspections typically request four specific evidence categories:
- Supplier register (CIR Annex 5.2) — the current registry of cloud services in scope, with ICT products and services listed per provider
- Security assessment record — the documented vulnerability review, certifications reviewed, and material findings per cloud provider, with assessment date
- Cloud services contracts — specifically the security clause schedule and the section addressing subcontractor and sub-processor requirements under CIR Annex 5.1.4(g)
- Sub-processor list review evidence — documentation that you have reviewed the cloud provider’s published sub-processor list and that your contract requires notification of changes
The absence of the CIR Annex 5.1.4(g) subcontractor clause in a cloud contract is a documented non-compliance finding — not a proportionality judgment. Section 5.1.4(g) is a specific requirement, not qualified by “where appropriate” or “to the extent feasible” language.
Penalty exposure under Article 34 of NIS2 for essential entities reaches up to €10 million or 2% of global annual turnover, whichever is higher. For important entities: up to €7 million or 1.4% of global annual turnover. Beyond financial penalties, NIS2 supervisory powers under Article 32 enable NCAs to hold management personally accountable where entities repeatedly fail to achieve compliance — creating a direct governance obligation for boards and executive teams, not only IT and security departments.
The practical protection is a structured, documented supply chain management programme. NCAs assess whether your organisation has evaluated its cloud supply chain, required appropriate security in contracts, and maintains an ongoing process for reviewing changes — not whether every control is perfect at the time of inspection. For the complete Article 21(2)(d) audit-readiness evidence map, see the NIS2 compliance checklist.
Building a CIR Annex 5-Compliant Cloud Supplier Register
Section 5.2 of CIR Annex 5 requires relevant entities to maintain and keep current a “registry of their direct suppliers and service providers.” For cloud services, the registry needs to capture more than a name and a contract reference. The following fields satisfy the CIR Annex 5.2 requirement and provide the evidence base an NCA audit will examine:
| Registry field | Cloud-specific content |
|---|---|
| Supplier legal entity name | Full legal name, not brand name; country of incorporation; parent entity if relevant |
| NIS2 classification (if known) | Essential entity / important entity / not in scope — relevant to how the provider must manage its own incident reporting |
| ICT services provided | Service model (IaaS / PaaS / SaaS / CDN / managed security); specific platforms; workloads hosted |
| Data classifications processed | Categories of data the service handles: personal data, confidential business data, critical operational data |
| Security assessment date and outcome | Date of most recent assessment; certifications reviewed (and scope confirmed); material gaps identified |
| CIR Annex 5.1.4(g) clause status | Whether current contract contains the subcontractor security flow-down clause — YES / NO / PENDING RENEGOTIATION |
| Sub-processor list | Source and date of most recent sub-processor list received; change notification mechanism in contract |
| Data centre regions | Known regions or facilities; EU / EEA / third-country jurisdiction |
| Next review date | Scheduled based on service criticality — quarterly for highest-risk, annually minimum for all |
Reassessment triggers: CIR Annex 5 requires ongoing monitoring, not point-in-time assessment. Schedule a registry review when your cloud provider updates its sub-processor list, when a security incident at the provider becomes known, when the contract is renewed or material terms change, or at minimum annually.
A practical note on evidence quality: Cloud providers that are themselves NIS2-regulated essential entities tend to publish more structured compliance documentation — sub-processor lists, certification scope summaries, incident notification procedures — making the Article 21(3) assessment more straightforward. Smaller SaaS vendors qualifying as important entities may require more direct engagement to obtain the evidence you need. Document your effort either way: demonstrating that you requested the information, assessed what was provided, and noted any gaps is itself a compliance signal for NCA inspectors.
For the complete supply chain security framework — including Supplier Security Policy, Security Clauses template, Supplier Directory, and Self-Assessment Questionnaire mapped to CIR Annex 5 — see the NIS2 supply chain security guide.
Frequently Asked Questions
Does NIS2 require ISO 27001 certification from cloud providers?
No. NIS2 Directive 2022/2555 and CIR 2024/2690 do not mandate ISO 27001 from cloud suppliers. Certification is useful evidence of the cybersecurity quality assessment required under Article 21(3), but your obligation is the assessment itself — its depth and documentation. SOC 2 Type II, BSI C5, or a well-documented direct technical review can satisfy the same requirement, provided the scope covers the risks relevant to your use of the service.
Must we audit our cloud provider’s sub-processors directly?
Under CIR Annex 5, the primary obligation runs to your direct supplier — the cloud provider. Section 5.1.4(g) requires your contract to flow security requirements through to that provider’s sub-processors, but you are not required to conduct direct audits of those sub-processors yourself. You must have audit rights over the cloud provider’s sub-processor management process and review the sub-processor list regularly, including any notification mechanism for changes.
If our cloud provider is itself NIS2-compliant, does that discharge our supply chain obligation?
No. Your cloud provider’s compliance with its own NCA is a separate regulatory relationship. Your Article 21(2)(d) obligation requires you to assess the provider independently, document that assessment for your own records, and maintain the contractual requirements in your contract. The provider’s NCA registration or certification status is relevant context, but it does not substitute for your due diligence.
Which cloud services are in scope for Article 21(2)(d)?
Scope is risk-based under the proportionality principle in Article 21(1). Apply Article 21(2)(d) assessment to cloud services where failure could materially affect the security, availability, integrity, or confidentiality of your network and information systems — in practice: IaaS/PaaS running critical workloads, SaaS handling sensitive data or integrated with operational systems, and managed security or CDN services with significant access rights. Low-risk ancillary services may warrant lighter assessment depth, documented with reasoning.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS2 Directive (EU) 2022/2555, Article 21 — nis2resources.eu (cited inline)
- Commission Implementing Regulation (EU) 2024/2690 — EUR-Lex (cited inline)
- ISMS Lite — “NIS2 for Data Centers and Cloud Providers” (cited inline)
- Google Cloud — “How Google Cloud Can Help Customers Achieve Compliance with NIS2” (cited inline)
- DLA Piper — “NIS2 Directive Explained, Part 3: Supply Chain Security”
- ENISA — NIS2 Technical Implementation Guidance
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
