Abstract network chain fading into darkness, representing NIS2 fourth-party supply chain risk

NIS2 Fourth-Party Risk: CIR Annex 5 Only Reaches Your Supplier’s Subcontractors Through a Contract Clause

In late 2025, credit unions across the US started sending breach notices to customers who had never done business with the company actually responsible. The intrusion traced back to a vulnerability in a SonicWall firewall — a device the credit unions’ direct marketing vendor, Marquis Software Solutions, used to protect its own network. By the time Marquis finished notifying affected institutions in November 2025, at least 74 banks and credit unions were involved, and individual exposure estimates ran as high as 1.35 million people [6]. The credit unions’ own systems were never touched. Neither was their contract with SonicWall — because they didn’t have one.

That’s fourth-party risk: exposure that originates two links down your supply chain, at a company you’ve never heard of and have no legal relationship with. NIS2 requires you to manage your direct suppliers under Article 21(2)(d). It says almost nothing about the next link down. One clause in the implementing regulation reaches slightly further — a single contract requirement, not a compliance programme. This article maps exactly where that boundary sits, what a stricter EU regime does instead, and what closing the remaining gap actually takes.

Does This Apply to Me?

Fourth-party exposure isn’t sector-limited the way some NIS2 obligations are — it scales with how many links exist between your organisation and the software, infrastructure, or service actually doing the work. A manufacturer running its own ERP on-premises has a shorter chain than a digital infrastructure provider whose helpdesk vendor outsources ticket handling to a subcontractor running on a cloud platform it doesn’t own. Every NIS2 essential or important entity has at least one chain worth mapping; most have dozens.

What changes by role is what you actually need from this article:

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Role What matters here
Compliance Officer / Legal Where the law’s obligation actually stops, and what evidence an auditor can legitimately ask for beyond that point
CISO / IT Security Manager How to get practical visibility into subcontractors you have no contract with, without trying to audit your supplier’s entire vendor list
SME Owner Why a signed supplier contract doesn’t mean the risk stops there — and the lowest-effort fix that closes the one gap the law does address
Board / C-Suite Why “our suppliers are NIS2-compliant” is not the same claim as “our supply chain is safe,” and where the residual liability sits

The Legal Boundary — What Article 21 Actually Requires

Start with what the Directive itself says, because it’s more precise than most compliance guidance implies. Article 21(2)(d) requires entities to address “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers” [1]. Article 21(3) repeats the same scoping language when it defines the assessment duty: entities must take into account “the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures” [1].

Read those two provisions together and the pattern isn’t ambiguous: “direct” appears in both, doing real legal work. This isn’t an oversight legislators will patch in a future amendment — it’s the same proportionality logic that runs through the entire Directive. Article 21(1) already ties every measure to “state of the art,” cost, size, and exposure; extending a direct legal duty down an unbounded chain of subcontractors would make the obligation impossible to scope or audit consistently across 27 member states. The boundary is deliberate. What it means practically is that your legal exposure under Article 21 itself ends at the contract you signed — everything past that is a different kind of risk, not a different kind of obligation.

That distinction matters more than it sounds. A regulator auditing your Article 21(2)(d) compliance has no textual basis to ask why you didn’t assess your supplier’s subcontractor directly — that tiered due-diligence obligation stops at your direct suppliers. But “the law doesn’t require it” and “it can’t hurt you” are two different sentences, and the rest of this article is about the gap between them.

What “Fourth-Party” Actually Means

The term causes more confusion than it should, mostly because of where the counting starts. In standard third-party risk management usage, your own organisation isn’t counted as a “party” in the chain at all — your direct supplier is the “third party” (the third entity in the regulator–you–vendor relationship), and their supplier is the “fourth party”: “the risk to your company posed by suppliers’ suppliers” [8]. NIS2’s own text sidesteps the numbering entirely and just says “direct” — which is the same boundary, described more plainly.

The mechanism that makes fourth-party risk dangerous isn’t exotic. You have no contract with the fourth party, so you have no audit right, no incident-notification clause, and no direct line to their security team. Your only lever runs through your direct supplier: what you required them to require, and whether they actually did. If that chain has a gap anywhere — a missing clause, an unenforced requirement, a subcontractor added after the contract was signed — the fourth party’s failure becomes your incident with none of the contractual tools you’d normally reach for.

Fifth-party risk exists too (your fourth party’s own vendors), but the marginal visibility cost rises fast enough past the fourth-party layer that most frameworks, NIS2 included, don’t try to formalise it. The next section covers the one place NIS2’s implementing rules reach past “direct.”

Where CIR Annex 5 Reaches — and Stops

Commission Implementing Regulation (EU) 2024/2690 (CIR) turns Article 21(2)(d) into a working structure for the digital-infrastructure and ICT-service entity types it directly binds — DNS providers, cloud services, data centres, and similar. Its Annex Section 5 requires a supply chain security policy, documented supplier selection criteria, a set of mandatory contract clauses, and a supplier registry [2]. Every one of those, read on its own, governs the relationship with your direct supplier — with one exception.

Annex point 5.1.4(g) requires your contracts to include “requirements regarding subcontracting and, where the relevant entities allow subcontracting, cybersecurity requirements for subcontractors in accordance with the cybersecurity requirements” [2]. Read that carefully: it’s a clause you put in your contract with your supplier, obliging them to impose equivalent terms on their subcontractor. You never sign anything with the fourth party. You never gain an audit right over them. If your direct supplier fails to flow the clause down — or flows it down on paper but doesn’t enforce it — you have no independent way to know until something breaks.

The supplier registry required by 5.2 makes the same boundary explicit in a different way: it must record contact points and the ICT products, services, and processes provided by “the direct supplier or service provider” [2] — there’s no field for subcontractors at all. An auditor checking your registry against the CIR can confirm it’s complete for direct suppliers and still find nothing wrong, even if none of those suppliers’ own subcontractors have ever been named.

State What it covers Effort to reach
Legal minimum (CIR-compliant) 5.1.4(g) clause present in direct-supplier contracts; registry lists direct suppliers only Low — a contract-language audit
Verified minimum Confirmed the clause is actually enforced, not just present — supplier can name its own critical subcontractors on request Medium — requires supplier cooperation
Practical resilience Direct visibility into which fourth parties support your most critical suppliers, monitored on an ongoing basis High — see the tiered framework below

Most organisations sit at the first row without knowing it — the clause exists in a template somewhere, but nobody has checked whether it made it into every signed contract, or whether “where the relevant entities allow subcontracting” quietly became “always allow it, no questions asked.”

What DORA Requires That NIS2 Doesn’t

The EU has already built a version of NIS2 with the fourth-party gap closed — it’s just scoped to financial entities. The Digital Operational Resilience Act (DORA) directed regulators to write technical standards for exactly the scenario CIR Annex 5 leaves untouched: Article 30(5) required the European Supervisory Authorities to specify what financial entities must assess when subcontracting ICT services that support critical or important functions [3]. The result, Commission Delegated Regulation (EU) 2025/532, published in the Official Journal in July 2025, is explicit in a way NIS2 never is.

It requires financial entities to assess “the length, layering and structure of the subcontractor chain,” not just the first link [4]. Due diligence must cover “both the direct service providers and any foreseeable subcontractors” [4] — a phrase with no NIS2 equivalent. Any material change to the subcontractor chain — adding, removing, or relocating a subcontractor — triggers mandatory pre-notification, with a right to object or terminate [4]. And the entity must be able to demonstrate to its regulator that it retains “full control and oversight over outsourced functions even when services are subcontracted” [4] — a standard that goes well past having a clause in a contract template.

None of this applies to a NIS2 entity outside DORA’s financial-sector scope, and nothing in NIS2’s own text suggests it’s coming — the two regimes remain genuinely different in reach on this specific point, not just in enforcement style. But the RTS is a useful reference for what “closing the gap voluntarily” concretely looks like, because EU regulators have already written down the answer once, for a sector they judged to carry commensurate risk.

Why Fourth-Party Risk Is Not Theoretical

The Marquis Software Solutions case from the introduction isn’t an outlier. SecurityScorecard’s December 2024 analysis of the 100 largest US banks found that 97% had suffered a fourth-party breach — traced back to just 2% of the vendors in their extended supply chains [5]. That concentration is the real story: a small number of shared fourth parties — the payment processors, the cloud regions, the widely-used analytics platforms — create correlated risk across an entire sector at once, which is exactly the profile of concern for an NIS2 sector like digital infrastructure, banking, or health.

The July 2024 CrowdStrike outage illustrates the same mechanism from the availability side rather than the confidentiality side. A single faulty update to CrowdStrike’s Falcon sensor caused an estimated $5.4 billion in direct losses across US Fortune 500 companies in a single day [7]. For organisations with a direct CrowdStrike contract, that’s third-party risk in the ordinary sense. For organisations that received Falcon only because their outsourced cloud or IT provider deployed it on their behalf — with no CrowdStrike relationship of their own — it’s a textbook fourth-party event: a vendor two links away disrupted operations in a single afternoon, and there was no contract to point to afterward.

What both cases share is the actual failure point: neither breach originated at the entity that got hurt, and neither entity had a contractual lever reaching that far down the chain. A supply chain security programme built only to satisfy Article 21(2)(d)’s direct-supplier text would have passed an audit in both cases right up until the incident happened.

Closing the Gap Beyond What the Law Requires

None of this requires building a DORA-grade subcontracting-chain programme for every vendor — that would be disproportionate for most NIS2 entities and isn’t what the law asks for. It requires a short list of actions, tiered by effort, applied only to the suppliers whose failure would actually matter.

Action Effort Closes
Audit every direct-supplier contract for the 5.1.4(g) subcontracting clause; add it where missing Low The legal minimum — confirms you’re actually CIR-compliant, not just assuming you are
Ask critical-tier suppliers to name the subcontractors touching your data or systems, and request their SOC report or equivalent [8] Low–Medium Basic fourth-party visibility, without a formal assessment programme
Restrict fourth-party visibility effort to critical- and important-tier suppliers only — not the full vendor list Medium Keeps the effort proportionate to Article 21(1)’s own risk-based standard
Require pre-notification of subcontractor changes for your highest-criticality suppliers, borrowing DORA’s mechanism voluntarily [4] Medium Catches the scenario that hurt the Marquis-affected credit unions — a chain change nobody was told about
Continuous attack-surface monitoring for concentration risk across your supplier base High The “2% of vendors, 97% of breaches” pattern — shared fourth parties across multiple suppliers

Start at the top of that list, not the bottom. The contract-clause audit is the fastest item on it, closes an actual legal gap rather than a hypothetical one, and needs nothing more than the contracts you already have on file.

Keep the paper trail simple: a copy of the subcontracting clause language actually in force, the supplier’s response when asked to name critical subcontractors (even an incomplete one is evidence you asked), and a note in your supplier registry — required by CIR 5.2 for direct suppliers anyway [2] — flagging which entries have unresolved fourth-party visibility gaps. ENISA’s own supply chain guidance frames continuous monitoring as one of four baseline pillars, alongside mapping, due diligence, and contractual clauses [9] — treat fourth-party visibility as an extension of the monitoring pillar you’re likely already building for direct suppliers, not a separate programme.

The Bottom Line

NIS2’s silence on subcontractors isn’t a drafting gap — it’s the same proportionality principle that shapes the rest of Article 21, applied to a boundary that has to sit somewhere. But a boundary chosen for legal workability isn’t the same as a boundary chosen for safety, and Marquis, CrowdStrike, and SecurityScorecard’s 97% figure all describe the same failure mode: risk that skips the contract entirely and lands on you anyway. Start with the one gap the law actually names — the 5.1.4(g) clause — and treat everything past that as a proportionate, risk-based decision you make deliberately, not one you discover after an incident.

Frequently Asked Questions

Does NIS2 require me to audit my supplier’s subcontractors directly? No. Article 21(2)(d) and 21(3) are scoped to “direct suppliers or service providers” [1], and CIR Annex 5.1.4(g) works through a contract clause your direct supplier must apply — not a right you hold to inspect the subcontractor yourself [2].

Can a fourth party be fined under NIS2? Only if that fourth party is independently an in-scope essential or important entity in its own right. Otherwise, NIS2’s penalty regime applies to regulated entities, not to unregulated subcontractors several links down a chain — the risk lands on you operationally and contractually, even though the legal duty didn’t.

Does my supplier’s ISO 27001 certification cover fourth-party risk? Partially, and only if their certification scope explicitly includes supplier relationship management. ISO 27001:2022 Annex A Control 5.19 addresses information security in supplier relationships, but a supplier’s own certification says nothing about whether they’ve actually flowed equivalent requirements down to their subcontractors — that’s a question you still have to ask directly, not infer from a certificate.

Sources

  1. Directive (EU) 2022/2555 (NIS2), Article 21 — nis-2-directive.com mirror of the consolidated text
  2. Commission Implementing Regulation (EU) 2024/2690, Annex Section 5 — Advisera full-text mirror (eur-lex.europa.eu source regulation)
  3. Digital Operational Resilience Act (Regulation (EU) 2022/2554), Article 30 — digital-operational-resilience-act.com
  4. Commission Delegated Regulation (EU) 2025/532 (DORA subcontracting RTS) — Jones Day legal analysis (jonesday.com); published in the Official Journal of the EU, July 2025
  5. “SecurityScorecard Threat Intel Report: 97% of Leading U.S. Banks Impacted by Third-Party Data Breaches in 2024” — SecurityScorecard (securityscorecard.com), December 2024
  6. “Two more banks notifying thousands of victims about Marquis Software ransomware attack” — The Record, Recorded Future News (therecord.media)
  7. “CrowdStrike’s Impact on the Fortune 500” — Parametrix Insurance (parametrixinsurance.com)
  8. “What is Fourth-Party Risk?” — UpGuard (upguard.com)
  9. “Good Practices for Supply Chain Cybersecurity” (June 2023) — ENISA (enisa.europa.eu)

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: