Abstract network diagram representing NIS2 vendor risk assessment and supplier security evaluation

How to Vet NIS2 Suppliers Without an Audit Team: A Tiered Due-Diligence Method for Article 21(2)(d)

Article 21(2)(d) of the NIS2 Directive does not tell you how to assess a supplier. It tells you that you have to, and then leaves the method to you. That gap is where most vendor risk programs go wrong: either every supplier gets the same 40-page audit regardless of what they actually touch, or nobody gets vetted beyond a signature on a contract. Neither survives a regulator’s first question, which is usually “how did you decide this supplier needed less scrutiny than that one?”

This article gives you the decision method: which suppliers get a questionnaire, which get a document review, and which justify an audit — plus a due-diligence questionnaire built directly from the CIR 2024/2690 Annex’s actual requirements, not a generic security checklist with NIS2 branding.

Why This Isn’t Optional Anymore

Third-party involvement in confirmed data breaches jumped from 15% to 30% in a single year — the largest single-year shift the Verizon Data Breach Investigations Report series has recorded, driven by mass exploitation of file-transfer software and credential reuse across vendor ecosystems [6]. IBM’s parallel research puts the average cost of a supply-chain compromise at $4.91 million, with a 267-day average lifecycle from breach to containment, longer than any other attack vector IBM tracks [6]. Those figures describe exactly the failure mode Article 21(2)(d) targets: an entity with a mature internal security program, undone by a supplier nobody assessed. ENISA’s own June 2023 study of EU essential and important entities frames the same four components used in this article — mapping, due diligence, contractual clauses, and continuous monitoring — as the baseline structure for supply chain cybersecurity across the bloc [3], which is the sequence this article follows.

What Article 21(2)(d) and the CIR Actually Require of You

In plain terms: you must know which of your suppliers could hurt you, and prove you checked. Article 21(2)(d) requires “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers” [1]. Article 21(3) sharpens this into an assessment duty: entities must take into account “the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures” [1].

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The Commission Implementing Regulation 2024/2690 (CIR) turns that duty into a working structure — though only DNS providers, TLD registries, cloud providers, data centres, CDNs, MSPs/MSSPs, marketplaces, search engines, social platforms, and trust service providers are formally bound by it. Everyone else answers to Article 21(2)(d) directly, but the CIR Annex is the closest thing to an official methodology, and using it as an interpretive reference is defensible even outside its binding scope. Annex Section 5.1 requires: a documented supply chain security policy (5.1.1); supplier selection criteria covering cybersecurity practices, secure development, product quality/resilience, and supply-source diversification (5.1.2); contract clauses across eight categories (5.1.4); integration of those criteria into procurement (5.1.5); periodic policy review (5.1.6); and ongoing monitoring of SLA reports, incidents, and unscheduled review triggers (5.1.7) [2]. Section 5.2 adds a mandatory supplier directory — contact points plus the ICT products, services, and processes each direct supplier provides [2].

Article 21(1)’s proportionality clause is what makes tiering legitimate rather than optional: measures must match “state of the art,” implementation cost, entity size, and the degree of risk exposure [1]. A five-person accounting-software vendor and your core cloud infrastructure provider do not get the same treatment — and the CIR doesn’t ask you to pretend otherwise.

One more piece of the legal picture is worth knowing, mostly so you don’t overstate it: Article 22 lets the Cooperation Group, working with the Commission and ENISA, carry out its own coordinated EU-level risk assessments of specific critical ICT supply chains [1]. That process runs at Union level — it doesn’t replace your own entity-level assessment duty under Article 21(3), and CIR 5.1.3 only asks you to factor its results in where they exist, not to wait for one before assessing your own suppliers [2].

Classifying Suppliers: Three Models, One Practical Answer

If you haven’t built a supplier classification matrix yet, our supply chain security implementation guide covers the full three-tier (critical / important / standard) method with the four classification criteria in detail — this section is a recap, not a rebuild.

What’s worth knowing before you commit to one model: regulators and standards bodies don’t agree on how to cut this. BSI, Germany’s national competent authority, deliberately avoids publishing a fixed “critical supplier” threshold test — it leaves the vulnerability analysis to the entity itself, consistent with Article 21(3)’s own wording [5]. ISO 27001:2022’s Annex A 5.19 instead recommends four supplier categories by value and risk, from business-critical down to no material impact, explicitly rejecting a single blanket policy [4]. The three-tier critical/important/standard split used on this site sits between the two: fewer bands than ISO’s four, but more structure than BSI’s leave-it-to-you approach.

Model Bands Best fit
BSI (no fixed bands) Entity-defined, vulnerability-led Mature risk functions with an existing methodology
Three-tier (critical/important/standard) 3 Most SMEs and mid-market entities — enough resolution without excess admin
ISO 27001 Annex A 5.19 4 Entities already running an ISMS who want NIS2 and ISO tiering to reconcile

Pick one, document why, and move on — the model matters less than being able to show an auditor you applied it consistently.

Choosing a Due-Diligence Method: Questionnaire, Document Review, or Audit

Match the method to what the tier is actually protecting, not to what feels thorough. Three methods cover nearly every supplier relationship, and each has a real cost and a real ceiling on what it proves.

A self-assessment questionnaire is cheap and fast — it takes a supplier an afternoon and you a day to review — but it only proves what the supplier is willing to write down. Use it as the entry gate for every supplier regardless of tier, and as the only method for standard-tier suppliers with no system access and no sensitive data.

A document review — ISO 27001 or SOC 2 Type II certificates, penetration test summaries, sub-processor lists — costs more time (checking scope and validity, not just presence of a logo) but proves a third party already looked. The catch: a certificate proves what was true on its audit date, for the scope stated, which is narrower than most buyers assume — a SOC 2 report scoped to “cloud infrastructure” says nothing about the application layer your data actually touches. Use document review as the standard method for important-tier suppliers, and as a supplement (not a replacement) for critical-tier ones.

An on-site or remote audit is the only method that verifies practice rather than paperwork — walking through an access-control implementation, watching a patch-management ticket close, sampling actual logs. It is also the most expensive method per supplier, in both your time and the supplier’s cooperation. Reserve it for critical-tier suppliers: those with direct access to your systems or data, or whose failure would disrupt an essential service. For most mid-market entities, that’s a handful of suppliers a year, not the whole vendor list — which is exactly the proportionality Article 21(1) is asking for [1].

A Due-Diligence Questionnaire Built From the CIR’s Real Requirements

Here’s a fact worth stating plainly: the CIR Annex does not define a supplier questionnaire, numbered or otherwise — Section 5 sets outcome requirements (a policy, selection criteria, contract clauses, monitoring), not a form to hand a vendor [2]. Any list you see online claiming to be “the official CIR questionnaire” is someone’s interpretation, not the regulation’s text. What follows is exactly that: an interpretation, built to operationalize CIR 5.1.2’s selection criteria, 5.1.4’s contract-clause categories, and Article 21(3)’s vulnerability assessment — 37 questions across seven categories, sized so a supplier can complete it in under an hour and you can score it in less.

Category What it operationalizes Questions
Cybersecurity practices & secure development CIR 5.1.2 6
Product/service quality & resilience CIR 5.1.2 4
Contractual readiness CIR 5.1.4 (8 clause categories) 8
Access, data & vulnerability exposure Art.21(3) 6
Sub-processor / fourth-party visibility CIR 5.1.4(g) cascade 4
Business continuity & substitutability Art.21(1), CIR 5.1.2 5
Certifications & independent assurance ISO 27001, DIN SPEC 27076 4

The contractual-readiness section is the one worth building out first, because it maps one-to-one onto CIR 5.1.4’s eight mandatory clause categories: cybersecurity requirements, staff awareness/training/certification, background verification, incident notification timelines, audit rights, vulnerability-handling obligations, sub-contracting cascade, and termination/data-return terms [2]. If a supplier can’t answer whether their own contract mirrors those eight, you’ve found your gap before you’ve spent a euro on an audit.

For the certifications section, don’t accept a certificate as a pass by default — a supplier possessing an ISO 27001 certificate demonstrates a management system exists, not that a specific control you care about is implemented at the maturity you need. Germany’s BSI names DIN SPEC 27076 (“CyberRisikoCheck”) as a recognised baseline self-assessment instrument for smaller suppliers who don’t yet hold a full ISMS certification [5] — a useful middle ground between “no evidence” and “full ISO audit” for important-tier suppliers who can’t afford certification yet.

Document Review and On-Site Audits: What “Verifiable” Actually Means

BSI’s guidance uses one word that should anchor your entire document-review process: supplier compliance must be überprüfbar — verifiable, not just claimed [5]. That has a concrete implication: a supplier statement that they “follow industry best practices” is not evidence; a dated penetration-test report with a remediation log attached is.

For an on-site or remote audit of a critical-tier supplier, three things separate a useful audit from a box-ticking exercise. First, sample actual artifacts — a specific access-review log from the last quarter, not a policy document describing how access reviews should work. Second, walk the incident-notification path end to end: does the supplier’s internal escalation actually reach a point of contact who can hit your contract’s notification deadline, or does the clause exist on paper only? Third, check the sub-processor cascade named in CIR 5.1.4(g) — ask the supplier to name their own critical sub-processors, because your Article 21(3) exposure doesn’t stop at your direct supplier’s front door [2].

Remote audits (screen-shared log review, video walkthroughs of physical controls) satisfy the same verification standard as on-site visits for most software and cloud suppliers, and cost a fraction of travel time — reserve genuine on-site visits for suppliers with physical infrastructure dependencies (data centres, manufacturing subcontractors, colocation providers).

Continuous Monitoring: The Triggers That Replace the Annual Checkbox

CIR 5.1.7 doesn’t ask for an annual review calendar — it asks for monitoring against four specific triggers: regular review of SLA implementation reports, review of incidents as they occur, an assessment of whether an unscheduled review is warranted, and analysis of risk from changes to the supplier’s product or service [2]. That’s a materially different obligation than “reassess every 12 months,” and it’s the gap most vendor risk programs miss: a critical supplier that changes cloud region, acquires a company, or has a public breach mid-cycle triggers a review regardless of where they sit on your calendar.

Build monitoring around triggers, not dates: an SLA-report review cadence tied to contract renewal, a standing rule that any supplier-side security incident (even one that didn’t touch you) triggers a re-assessment, and a change log that flags sub-processor additions or infrastructure moves for the same treatment. Standard-tier suppliers can stay on an annual questionnaire refresh; critical-tier suppliers need the trigger-based model, because CIR 5.1.6 requires periodic policy review specifically to catch changes in supplier cybersecurity practice, not just the passage of time [2].

What to Document, and Who Owns It

An auditor reviewing your Article 21(2)(d) compliance will ask for four things: the classification decision and its rationale per supplier, the due-diligence evidence gathered per tier (questionnaire responses, certificates, audit reports), the contract clauses in place against the CIR’s eight categories, and the supplier directory required by Section 5.2 [2]. Missing any one of the four is a documentation gap, not necessarily a security gap — but it’s the one regulators can verify in an afternoon, so it’s usually where a first review starts.

Task Owner Effort
Supplier classification (tier assignment) CISO / Risk function Medium — one-time per supplier, low ongoing
Questionnaire distribution & scoring Procurement, with CISO sign-off Low per supplier
Contract clause negotiation Legal, briefed on the 8 CIR categories Medium — higher for legacy contracts
Audit execution (critical tier) CISO or contracted assessor High — budget accordingly
Supplier directory maintenance Procurement Low, ongoing
Trigger monitoring (incidents, changes) CISO / Risk function Low ongoing, spikes on trigger events

Frequently Asked Questions

Does Article 21(2)(d) require me to assess my suppliers’ suppliers? No — the Directive’s own language is scoped to “direct suppliers or service providers” [1]. The CIR’s cascade requirement (5.1.4(g)) works through your direct supplier’s contract: you require them to flow equivalent cybersecurity terms down to their own critical sub-processors, rather than assessing those fourth parties yourself [2].

How often should a standard-tier supplier be reassessed? An annual questionnaire refresh is a reasonable, proportionate baseline for standard-tier suppliers under Article 21(1) — there’s no CIR-mandated interval, so document your own cadence and the reasoning behind it rather than citing a specific number as a legal requirement.

What if a critical supplier refuses an audit? Treat refusal as a data point in itself: a supplier unwilling to demonstrate verifiability, in BSI’s terms, has effectively told you their controls can’t survive scrutiny [5]. Escalate to contract renegotiation (adding the audit-rights clause explicitly if it’s missing) or begin evaluating substitutability — which is exactly why CIR 5.1.2 lists “capacity to diversify supply sources” as a selection criterion in the first place [2].

Sources

  1. Directive (EU) 2022/2555 (NIS2), Article 21 — nis-2-directive.com mirror of the consolidated text
  2. Commission Implementing Regulation (EU) 2024/2690, Annex Section 5 — Advisera full-text mirror (eur-lex.europa.eu source regulation)
  3. “Good Practices for Supply Chain Cybersecurity” (June 2023) — ENISA (enisa.europa.eu)
  4. ISO/IEC 27001:2022, Annex A Control 5.19 — ISMS.online explainer
  5. “NIS-2: Sichere Lieferkette” — BSI (Bundesamt für Sicherheit in der Informationstechnik), Germany’s national competent authority (bsi.bund.de)
  6. “Supply Chain Attack Statistics for 2026” (secondary aggregation of Verizon 2025 Data Breach Investigations Report and IBM 2025 Cost of a Data Breach Report) — Swif (swif.ai)

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: