Abstract network of glowing blue nodes with one outer cluster highlighted in amber, representing supplier risk reaching into an organisation under NIS2

NIS2 Due Diligence: The 3 Factors That Set Your Bar — and the 8 a Regulator Weighs Instead

Search for “NIS2 due diligence” and you will find a hundred pages telling you your effort should match the risk. None of them mention that the NIS2 Directive uses the phrase due diligence exactly once — in Article 28(1), about the accuracy of domain name registration data. It never appears in connection with suppliers. Commission Implementing Regulation (EU) 2024/2690, which carries the binding technical requirements, does not contain the phrase at all. Neither does ENISA’s 170-page implementation guidance [1][2][3].

There is no legal standard called “NIS2 supplier due diligence” to comply with. There are three separate tests, in three separate places, each with its own named factor list. And the factors that let you justify doing less at design time are absent from the list a regulator must weigh when it decides what to do about you.

This article sets out all three from the primary text, and marks the line where proportionality stops working.

Does This Apply to You?

Article 21 binds every essential and important entity. What differs is the level of detail you are measured against, and whether a second instrument sits on top of the Directive.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Your position What binds you What sets the depth
Essential or important entity, not in the 11 categories below Article 21(1)–(4), as transposed into your national law The Article 21(1) three-factor test, plus your national competent authority’s guidance
DNS service provider, TLD name registry, cloud provider, data centre provider, CDN provider, managed service provider, managed security service provider, online marketplace, online search engine, social networking platform, or trust service provider Article 21 and the Annex to CIR 2024/2690, directly applicable in every Member State CIR Article 2(2), plus a documented-reasoning duty every time you rely on a qualifier
Below the size thresholds and not caught by a special case in Article 2 NIS2 does not apply to you directly Nothing — but expect these requirements to reach you contractually, from customers who are in scope
A supplier to an in-scope entity NIS2 does not bind you through your customer Article 21(2)(d) makes your security your customer’s problem, so it will arrive as contract language

If you are unsure which tier you fall into, the boundary between essential and important status is decided by sector and size, not by how critical you feel: see our breakdown of the six routes into important-entity status. The 11 categories in the second row matter more than most entities realise, because the CIR’s Annex only binds them — for everyone else it is a well-informed benchmark, not law, a point we set out in the Article 21(2)(a) analysis. For the measure-by-measure view of all ten obligations and how the CIR Annex maps onto each of them, see our complete Article 21 breakdown.

“Due Diligence” Appears Once in NIS2, and Not About Suppliers

The phrase everyone uses is not in the law. That matters, because it means no auditor can ask whether you met “the NIS2 due diligence standard” — there isn’t one to meet. They can only ask whether you did what Articles 21(1), 21(2)(d) and 21(3) actually say.

We searched the full text of all three instruments. The counts:

Instrument “due diligence” Where, and about what
Directive (EU) 2022/2555 (NIS2), Recitals 1–144 and Articles 1–46 1 Article 28(1) — TLD name registries and domain name registration services must maintain registration data “with due diligence”. Nothing to do with suppliers.
CIR (EU) 2024/2690 — the binding technical requirements 0
ENISA Technical Implementation Guidance v1.0, 170 pages 0

The word diligence on its own appears twice in the Directive. The second instance is the one people are reaching for, and it is narrower than they think. Recital 86 says essential and important entities “should therefore exercise increased diligence in selecting a managed security service provider” [1]. Two things about that sentence: it is a recital, so it explains intent rather than creating an obligation, and it is scoped to one supplier type. It is not a general supplier-vetting mandate — it is a signal that your penetration testers and incident responders deserve a harder look than your stationery vendor, which is a point worth taking seriously when you are outsourcing security operations to an MSSP.

ENISA’s Technical Implementation Guidance is the more revealing absence. Across 170 pages written specifically to tell entities how to implement the security measures, the word “proportionality” appears zero times and “proportionate” twice — once about patching, once about effectiveness assessments, neither in the supply chain section [3]. The document that is supposed to operationalise Article 21 simply does not discuss how much is enough. It lists requirements and gives examples of evidence. Proportionality lives somewhere else entirely.

The Three Factors That Set Your Bar

Article 21(1) of the NIS2 Directive has a second subparagraph that does two different jobs in two sentences, and almost every summary merges them into one. Separating them is the single most useful thing you can do with this provision.

The first sentence: “Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed.” The second: “When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact” [1].

Only the second sentence is the proportionality test. The first is a set of inputs into deciding what “appropriate to the risks posed” means. Cost of implementation sits in the first sentence, not the second — it shapes how you reach an adequate level of security, and it is not one of the three factors against which the proportionality of your measures is assessed.

Factor (Article 21(1)) Pushes your bar up when Pushes it down when
Degree of your exposure to risks You are internet-facing, heavily integrated with third parties, or a known target for your sector Your attack surface is genuinely narrow and your supplier dependencies are few and shallow
Your size You are large enough that complexity, headcount and system sprawl create risk of their own You are small enough that a control is physically unachievable — see the compensating-measures route below
Likelihood and severity of incidents, including societal and economic impact An outage of your service disrupts other services, a region, or a public function An incident would be contained inside your own organisation

Two factors people cite confidently are not in that list. Recital 82 adds “the criticality of the entity”, and CIR Recital 4 adds “size and structure” [1][2]. Both are recitals. They explain what the legislature had in mind; they do not create a fourth or fifth statutory factor. In practice criticality resurfaces anyway, because national authorities import it — Ireland’s draft guidance builds it into the board’s expectations at RMM002.SA05 [4] — but you should know which of your arguments rests on binding text and which rests on interpretation, because only one of them survives a determined lawyer.

There is a quieter drafting decision in the Implementing Regulation worth noticing. CIR Article 2(2) restates the proportionality test for the 11 categories it binds — exposure to risks, size, likelihood and severity — but it does not restate “state-of-the-art” or “cost of implementation” [2]. Article 21(1) has not gone anywhere, so those inputs still exist in the Directive. But when the Commission wrote down how to apply the Annex, cost is not the lever it reached for. The lever it wrote instead is the one in the next section.

What Article 21(3) Actually Obliges You to Do About Suppliers

Article 21(3) is the only place NIS2 tells you how to think about a specific supplier, and its verb decides everything. Entities must “take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures” [1].

Take into account. Not audit, not verify, not obtain evidence of. Article 21(3) creates a consideration duty. That is a lower bar than the questionnaire industry implies — and a more dangerous one, because a consideration leaves no artefact unless you deliberately create one. A supplier assessment you performed in someone’s head is legally indistinguishable from one you never performed, the moment an authority exercises its power under Article 32(2)(g) to request “evidence of implementation of cybersecurity policies” [1].

The word direct is doing equally heavy lifting: the duty reaches your suppliers, not theirs. Recital 85 says entities “could consider” risks from deeper tiers — permissive, not mandatory — which is why fourth-party risk only reaches you through a contract clause rather than through the Directive itself.

Article 21(3) has a second subparagraph that was, until recently, a pointer to nothing. It requires entities to take into account “the results of the coordinated security risk assessments of critical supply chains carried out in accordance with Article 22(1)” [1]. For three years there were no such results to take into account. That changed on 30 January 2026, when the NIS Cooperation Group published its risk assessment on connected and automated vehicles — in its own words, a “coordinated Union level security risk assessment of connected and automated vehicles (CAVs) and their supply chains carried out under Article 22 of the NIS2 Directive” — in which “Member States, the Commission and ENISA identified and assessed 107 risks associated with CAVs, of which 14 are identified as top risks” [5]. A second assessment covers detection equipment used at borders and customs, and on 13 February 2026 the Commission published both alongside the EU ICT Supply Chain Security Toolbox [6].

If your supply chain touches either domain, a dormant clause just became operational. You now have named documents that Article 21(3) requires you to factor into your supplier measures, and their absence from your risk file is a visible, dated gap. If your supply chain touches neither, the second subparagraph still does nothing for you — and saying so in your risk assessment is itself a defensible act of consideration.

Where Proportionality Stops: The Floor and the Dial

Proportionality changes how deep you go. It does not change whether you go. The practical question is which parts of a supplier programme are floor and which are dial — and for the 11 CIR-bound categories, the Annex answers it by where it uses a qualifier.

Every requirement in the CIR Annex is drafted with “shall”. Some carry a softener: “where appropriate”, “where applicable”, or “to the extent feasible”. Counting across the Annex proper, we found 218 instances of “shall” against 48 “where appropriate”, 10 “where applicable” and 4 “to the extent feasible”. Scoped to Section 5, the supply chain section, the ratio is 10 “shall” against 7 qualifiers — 4 “where appropriate”, 3 “where applicable”, none “to the extent feasible” [2].

Those seven are your dial. Section 5.1.4 is the clearest example: contracts must “specify, where appropriate through service level agreements, the following, where appropriate” — two qualifiers in a single introductory clause, governing all eight contract elements. But a qualifier is not permission to skip. CIR Article 2(2) attaches a price: where an entity considers a qualified requirement not appropriate, not applicable or not feasible, “the relevant entity shall in a comprehensible manner document its reasoning to that effect” [2]. Turning the dial down is free. Turning it down silently is the infringement.

The Regulation’s recitals add one more route for the genuinely small. Recital 5 says entities that cannot implement a requirement “due to their size” should be able to take “compensating measures”, and works the example: a micro-entity that cannot segregate conflicting duties can substitute targeted management oversight or increased monitoring and logging [2]. Note what that is and is not — a substitution, evidenced, not an exemption.

The most useful public answer to “which half is the floor” comes from a national authority. Ireland’s NCSC, in its draft Risk Management Measures Guidance, splits every measure into Foundation Actions — “the minimum required to meet the legislative obligations of the Directive… a baseline of security practices that all entities are expected to uphold” — and Supporting Actions, which “supplement the foundation actions to provide enhanced security”. Its instruction is unambiguous: “All entities are expected to implement the foundation actions as a baseline. To determine whether supporting actions are also required, organisations should conduct a thorough risk assessment” [4].

Where the split falls for supply chain is not where the market assumes.

NCSC Ireland RMM012 (supply chain) Tier What that means for you
A supply chain policy covering relationships with direct suppliers, incorporating the Article 21(3) considerations and the Article 22(1) results Foundation Non-negotiable regardless of your size or budget
Identifying which relationships are ICT, ICS or OT supply relationships Foundation Non-negotiable
An up-to-date registry of direct suppliers with contact points and supplied systems Foundation Non-negotiable — this is the CIR Annex 5.2 directory
Assurance via SLAs and/or auditing mechanisms that suppliers “establish and continue to operate adequate security measures” Foundation Non-negotiable — but the mechanism is your choice
Defined criteria for selecting suppliers Supporting Scalable to your risk assessment
The full set of contract clauses (audit rights, incident notification, training, subcontracting) Supporting Scalable to your risk assessment

Read that table twice. The two artefacts most vendors sell as “the NIS2 due diligence requirement” — the supplier selection criteria and the contract clause set — sit in the scalable half. The supplier register nobody wants to maintain sits in the non-negotiable half, alongside an assurance mechanism you must have in some form. If your programme consists of a thorough questionnaire and no maintained directory, you have optimised the dial and skipped the floor.

One important limit: this is Ireland’s draft guidance, dated 4 June 2025, addressed to Irish entities. Other Member States draw the line differently, and the split is not itself EU law. Use it as the best-published worked example of regulatory thinking, verify it against your own authority’s guidance, and do not port it across a border unchecked.

A workable gap analysis, then, looks like this:

Typical current state Required state Effort to close
A procurement spreadsheet listing vendors and spend A directory of direct suppliers with contact points and the ICT products, services and processes each supplies Low — the data mostly exists, it is the structure and ownership that are missing
Security questionnaires sent at onboarding, filed and never revisited Documented criteria applied at selection, plus monitoring that reacts to supplier incidents and significant changes Medium — needs a named owner and a review trigger, not a bigger questionnaire
Standard commercial contracts with a confidentiality clause Contracts specifying the CIR 5.1.4 elements, or documented reasoning for each one you judged inapplicable Medium to High — legal review and, for existing suppliers, renegotiation at renewal
Supplier risk discussed informally at management meetings Board-approved measures under Article 20(1), with a record of the approval Low — but it must pre-date the incident to be worth anything

If you want the operational layer rather than the legal one, we cover how to tier suppliers and how to run the assessments without an audit team in separate guides. This one is about the standard those methods are measured against.

The Eight Factors a Regulator Weighs Instead

Here is the asymmetry that should change how you write things down. When something goes wrong, the assessment switches to a different list — and your design-time proportionality arguments are not on it.

Article 32(7) tells competent authorities what they must take “due account of” when taking enforcement measures against an essential entity. There are eight items, and Article 34(3) applies the same eight to the decision to fine and the amount [1].

Article 32(7) factor Can you influence it in advance?
(a) Seriousness of the infringement and importance of the provisions breached Partly — Article 32(7)(a) lists five things that are a serious infringement “in any event”, including failure to remedy deficiencies after binding instructions
(b) Duration of the infringement Yes — detection and remediation speed is the whole variable
(c) Relevant previous infringements Historical
(d) Material or non-material damage caused, including financial loss and users affected Partly — containment and blast-radius design
(e) Intent or negligence on the part of the perpetrator of the infringement Yes — and note that the infringement is yours, not the attacker’s: “the perpetrator of the infringement” is the regulated entity
(f) Measures taken by the entity to prevent or mitigate the damage Yes — bankable in advance
(g) Adherence to approved codes of conduct or approved certification mechanisms Yes — bankable in advance
(h) Level of cooperation with the competent authorities Yes — decided in the first 48 hours

Read the list again and note what is missing. Not one of Article 21(1)’s three proportionality factors appears — not your exposure, not your size, not the likelihood or severity of incidents. Nor does cost of implementation, nor state-of-the-art. The arguments that legitimately let you build a smaller supplier programme are not arguments an authority is directed to weigh once it is deciding what to do about a breach of that programme.

This is not the same as saying proportionality vanishes. Article 32(1) requires supervisory and enforcement measures to be “effective, proportionate and dissuasive, taking into account the circumstances of each individual case” [1] — but that governs the proportionality of the authority’s response, not the adequacy of your budget. “We are small and it was expensive” is a design-time justification. Its enforcement-time equivalent is factor (f): the measures you actually took. Those are different sentences, and only one of them is written down in your files before the incident.

Factor (g) is the most underused. Adherence to approved certification mechanisms is a statutory mitigating factor, which puts a concrete regulatory value on certification beyond the sales pitch — worth weighing when you next price an ISO 27001 certification against doing nothing.

The exposure the eight factors modulate:

Entity type Maximum administrative fine for infringing Article 21 or 23 Supervision style
Essential entities At least €10,000,000 or 2% of total worldwide annual turnover of the undertaking, whichever is higher (Article 34(4)) Proactive — on-site inspections, regular and targeted security audits, security scans, random checks (Article 32(2))
Important entities At least €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher (Article 34(5)) Ex post — triggered by evidence, indication or information of non-compliance (Article 33(1))

Those are minimum ceilings Member States must provide for, not tariffs; national transpositions may go higher, and the split between proactive and reactive supervision is set out in more detail in our guide to NIS2 supervisory and enforcement measures.

What This Changes, by Role

The same three tests land differently depending on what you are accountable for.

Role What to do differently on Monday
Compliance officer Stop calling it due diligence in your documentation and start citing Article 21(2)(d), 21(3) and, if you are CIR-bound, Annex 5.1.2 and 5.1.4 by number. Then open a reasoning log: every qualified requirement you decided not to apply needs a written, comprehensible reason under CIR Article 2(2), and that log is the single artefact most programmes lack.
CISO or IT security manager Audit which half of your programme is floor and which is dial. If you have deep questionnaires but no maintained supplier directory, and no SLA or audit mechanism giving you ongoing assurance, you have built the scalable half and skipped the baseline. Check whether your supply chain touches connected vehicles or border detection equipment; if it does, the Article 22(1) assessments are now inputs you are required to consider.
SME owner or non-technical decision-maker Your size is a real factor under Article 21(1), and CIR Recital 5 contemplates substituting compensating measures where a control is genuinely unachievable at your scale. Neither is self-executing. Both work only if the substitution and the reasoning are written down before anyone asks, and neither reduces the baseline — the directory and the policy are not optional at any size.
Board member or executive Article 20(1) makes you approve the measures, oversee implementation, and liable for infringements. The two enforcement factors you can influence — 32(7)(f) and (g) — are both evidenced by things with dates on them: a resolution approving the measures, a certification, a remediation programme. Approve them early or they are worth nothing later.

Frequently Asked Questions

Is there an official NIS2 supplier due diligence questionnaire?
No. Neither the Directive nor CIR 2024/2690 prescribes a questionnaire, and neither uses the phrase “due diligence” in a supplier context. What the CIR requires of the 11 categories it binds is a supply chain security policy containing four named selection criteria (Annex 5.1.2) and a directory of direct suppliers (Annex 5.2). A questionnaire is one way to gather the inputs; it is not itself the requirement.

How deep does NIS2 due diligence have to go into the supply chain?
Article 21(2)(d) and 21(3) reach your direct suppliers and service providers. Recital 85 says entities “could consider” risks from deeper tiers — permissive language, not an obligation. Reaching a supplier’s subcontractor is done contractually, via the subcontracting requirements in CIR Annex 5.1.4(g), not by direct operation of the Directive.

Can we do less because we are a small company?
Size is one of the three factors in Article 21(1), so yes, it legitimately affects the depth of your measures — and CIR Recital 5 contemplates compensating measures where a requirement cannot be met due to size. But it does not remove requirements, and it does not appear anywhere in the Article 32(7) list an authority weighs at enforcement. Document the reasoning at the time you make the decision.

Does the CIR apply to us if we are not one of the 11 categories?
Not as binding law. CIR 2024/2690 Article 1 names DNS providers, TLD registries, cloud, data centre, CDN, managed service and managed security service providers, online marketplaces, search engines, social networking platforms and trust service providers. For every other essential or important entity the Annex is the most detailed public statement of what the Commission considers adequate, which makes it a strong benchmark and a reasonable basis for your own reasoning — but your binding obligation is Article 21 as transposed nationally.

What are the Article 22 coordinated risk assessments, and do they apply to us?
They are Union-level assessments of specific critical ICT supply chains carried out by the NIS Cooperation Group with the Commission and ENISA. Article 21(3) requires entities to take their results into account when deciding which supply chain measures are appropriate. The first two — connected and automated vehicles, and border and customs detection equipment — were published in early 2026. If your supply chain does not touch those domains, record that conclusion rather than ignoring the clause.

Will a supplier certification satisfy our Article 21(2)(d) obligation?
It can support it, and adherence to approved certification mechanisms is an express mitigating factor under Article 32(7)(g), but no certificate discharges the duty by itself. Article 21(3) asks you to take into account vulnerabilities specific to each direct supplier and the overall quality of their practices — an assessment about that supplier in your context. A certificate is evidence feeding that assessment, not a substitute for it.

The Standard You Are Actually Held To

The phrase “NIS2 due diligence” is a market convenience, not a legal test, and treating it as one leads programmes to over-invest in the scalable half and under-invest in the baseline. Three provisions do the real work: Article 21(1) sets the depth by three named factors, Article 21(3) tells you what to consider about each direct supplier, and CIR Article 2(2) prices every qualifier you rely on at one documented reason.

The practical consequence is narrower than it sounds. Proportionality is a design-time argument that must be written down at design time, because the eight factors in Article 32(7) do not include a single one of the reasons you had for building smaller. What they do include — measures actually taken, certifications actually held, cooperation actually given — are all things with dates on them. Build the file before you need it, and “proportionate” stops being an adjective you hope someone accepts and becomes a decision you can show.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Directive (EU) 2022/2555 (NIS2 Directive) — EUR-Lex, Official Journal (linked above). Articles 20, 21, 22, 28, 32, 33 and 34, and Recitals 81, 82, 85 and 86. Article-level text for Article 21 and Article 32.
  2. Commission Implementing Regulation (EU) 2024/2690 — EUR-Lex, Official Journal (linked above). Articles 1 and 2, Recitals 4–6, and Annex Section 5 (supply chain security).
  3. Technical Implementation Guidance on cybersecurity risk-management measures, version 1.0 (June 2025) — ENISA (linked above).
  4. NIS 2 Risk Management Measures Guidance, draft of 4 June 2025 — National Cyber Security Centre, Ireland (linked above). Foundation and Supporting Actions, and RMM012 (supply chain policy).
  5. Connected and Automated Vehicles: EU Coordinated Risk Assessment, 30 January 2026 — NIS Cooperation Group, with the European Commission and ENISA (linked above).
  6. Toolbox to improve ICT supply chain security, 13 February 2026 — European Commission, Shaping Europe’s Digital Future.
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: