NIS2 Supply Chain Declaration Pack
199,00 €
- 6 editable DOCX — the full supplier-security set
- Maps to NIS2 Article 21(2)(d) — supply chain security
- Supplier security policy & clauses, confidentiality statement, self-assessment & compliance checklist
- Instant download after payment
- Secured by Stripe
Licence scope: covers one legal entity. For multiple companies, see the Enterprise Licence (€997) — up to 5 organisations.
30-Day Update-or-Add Pledge: if a template needs adapting to your compliance environment — or your implementation calls for a document outside the standard scope — email info@nis-2-templates.com within 30 days and we’ll update it or add it. You keep everything either way.
Digital download — once you confirm at checkout, the EU 14-day withdrawal right is waived per Directive 2011/83/EU, Art. 16(m).
Description
You assess every supplier’s security, embed the requirements in your contracts, and walk into the audit able to prove it — with 6 editable templates that turn informal vendor management into a documented, Article 21(2)(d) programme.
Instant download · editable DOCX/XLSX · not yet sure? Download the free NIS2 Article 21 compliance checklist first.
CIR 2024/2690 referenced
ISO 27001:2022 cross-referenced
ENISA guidance referenced
UK English
Editable DOCX/XLSX
Your Suppliers Are the Gap You Can’t Evidence
You know your own house is in order. The part that keeps you up is the part you don’t control: your suppliers. Article 21(2)(d) of the NIS2 Directive requires you to address “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers.” CIR 2024/2690 Annex Section 5 spells out what that means in practice: a supply chain security policy, security requirements embedded in your contracts, a process for assessing supplier risk, and ongoing monitoring of supplier compliance.
So you start chasing. You email vendors a blank questionnaire you wrote yourself, you log answers in scattered threads, and you quietly worry that the one unvetted supplier — the third-party risk you never assessed and can’t evidence — is exactly what an auditor will pull on. Because this isn’t a pass/fail checkbox. The auditor wants a documented programme: which suppliers you identified, what you required of them, whether those requirements are contractually binding, and how you assess and track them over time. Manage that informally and you can’t prove any of it — no matter how strong your internal security is.
You shouldn’t have to invent a supplier-assurance programme from a blank page, or carry a personal worry that someone else’s gap becomes your audit finding. The villain here isn’t you. It’s the supplier you never formally assessed — and this pack exists to put that risk on the record.
You Get the Whole Supplier Lifecycle — Already Drafted
We’ve sat where you’re sitting: knowing the directive expects a supplier programme, and having nothing structured to build it on. So you don’t start from scratch. You get 6 editable templates covering the full supplier security lifecycle — policy, contractual clauses, self-assessment, and compliance scoring — each mapped to Article 21(2)(d), CIR 2024/2690 Annex Section 5, and ENISA technical guidance.
Every template follows a consistent 9-section structure — Purpose, Scope, Definitions, RACI matrix, Requirements, Exceptions, Monitoring, References, and Appendix — with pre-filled RACI tables, red-highlighted placeholders for your organisation-specific data, and cross-references to CIR 2024/2690 and ENISA guidance. You fill the red fields; the structure is done.
What one of our customers said
“I’ve just purchased the Complete Toolkit. It provides detailed policy and procedure templates as well as detailed NIS2 compliance implementation guides. Believe this will be a very useful tool for us.”
Enda Macken
Data and Systems Manager · Dromone Engineering Limited · Ireland
Dromone Engineering is an NIS2 “important entity” under Annex II (manufacturing).
What You Receive
| Doc # | Document | What You Do With It |
|---|---|---|
| 42 | Supplier Security Policy | You set your requirements for supplier security: classification criteria, minimum security standards, assessment frequency, and escalation procedures for non-compliance |
| 43 | Supplier Security Clauses | You attach pre-drafted security clauses to procurement agreements — covering data protection, incident notification obligations, audit rights, sub-contractor controls, and termination triggers |
| 44 | Confidentiality Statement | You bind suppliers handling sensitive information — defining their obligations, permitted use, return/destruction requirements, and breach notification duties |
| 45 | Supplier Directory | You record every supplier, their criticality classification, services provided, contract dates, last assessment date, and compliance status — your single source of truth for vendor management |
| 60 | Supplier Self-Assessment Questionnaire | You send this standardised questionnaire straight to your vendors — covering governance, access control, incident management, business continuity, and data protection |
| 61 | Supplier Compliance Checklist | You score the responses — assigning risk ratings, identifying gaps, and generating an overall compliance score for each vendor |
You also get 2 implementation guides (Master Map, Dependency Map) — 8 files total.
How You Go From Purchase to Audit-Ready
- 1. Set the rules. You drop in the Supplier Security Policy and the contractual clauses, fill the red-highlighted fields, and your requirements are now defined and binding.
- 2. Assess your suppliers. You send the Self-Assessment Questionnaire to your vendors, score the answers with the Compliance Checklist, and log them in the Supplier Directory.
- 3. Evidence it. You hand the auditor a documented, scored, tracked supplier programme — every step producing an auditable artefact for Article 21(2)(d).
Define requirements → embed them in contracts → protect confidential information → maintain a vendor register → assess supplier posture → score and track compliance. You close the loop — and you can prove you assessed every supplier in it.
Common Questions About the Supply Chain Pack
Are these templates legal advice?
No. These templates are general samples intended as a starting point for your supply chain security documentation. They do not constitute legal advice. Every document—especially the Supplier Security Clauses (Doc 43)—must be reviewed by a qualified legal professional before you include it in contracts.
Do you offer refunds?
This is a digital download product. You waive the right of withdrawal at checkout in accordance with EU Directive 2011/83/EU, Article 16(m), and you’ll be asked to consent to this before completing payment. 30-day update-or-add pledge: if a template doesn’t fit your environment, email us within 30 days and we’ll update it — or add a document outside the standard scope. You keep everything either way.
Are updates included?
Yes. Your purchase includes one year of updates. As EU guidance evolves—new ENISA publications, member state implementation acts, or CIR amendments—you can download updated templates at no additional cost during your update period.
Can I send the self-assessment to suppliers?
Yes. You send Doc 60 (Supplier Self-Assessment Questionnaire) directly to your suppliers as a standalone document. It covers governance, access control, incident management, business continuity, and data protection. You then use Doc 61 (Supplier Compliance Checklist) to score their responses and assign risk ratings.
Put Your Supplier Risk on the Record
You stop chasing vendors with a blank form you wrote yourself. You assess every supplier against a defined standard, embed the requirements in your contracts, and walk into the audit with a documented programme that proves you did it. That’s the difference between hoping your suppliers aren’t the gap — and being able to show they’re not.
Not ready to buy? Download the free NIS2 Article 21 compliance checklist.
Stripe-secured checkout
VAT handled at checkout
1 year of updates included
Disclaimer: These templates are general samples for internal use. They do not constitute legal advice and must be reviewed by a qualified professional before adoption. No document in this pack guarantees NIS2 compliance. See our full Disclaimer.






Reviews
There are no reviews yet.