NIS2 Vendor Risk Scoring: The Four Criteria the Regulation Names — and the Threshold It Leaves to You
Search the NIS2 Directive for the word “score”. You will not find it. Search Commission Implementing Regulation (EU) 2024/2690 — the act that converts Article 21(2) into technical requirements — and it is absent there too. Search ENISA’s 170-page implementation guidance and “scoring” appears exactly twice, both times about rating vulnerability severity with CVSS, neither time in the supply chain section.
Yet 90% of the EU entities ENISA surveyed run specific third-party controls, and 54% conduct supplier risk assessments or audits [5]. Most of those assessments end in a number. That number is not prescribed by law, which means nobody will tell you it is wrong — until a supervisor asks what it is made of, what happened when a supplier fell below it, and who signed that off.
The criteria, unlike the score, are named. There are four of them, and building the model around anything else is where most vendor scorecards quietly stop being NIS2 evidence.
Does a scoring model apply to you?
In short: every essential and important entity owes a reasoned supplier selection process. Only some of them are bound by a Union-level list of criteria — and that difference decides how formal your model needs to be.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Commission Implementing Regulation (EU) 2024/2690 binds eleven named categories: DNS service providers, TLD name registries, cloud computing providers, data centre providers, CDN providers, managed service providers, managed security service providers, online marketplaces, online search engines, social networking platforms, and trust service providers. For those entities, Annex point 5.1.2 is directly applicable law. For every other in-scope entity — energy, health, transport, water, manufacturing, public administration and the rest — the binding text is Article 21(2)(d) and Article 21(3) of Directive (EU) 2022/2555 as transposed nationally, and the Annex is the closest available Union benchmark rather than a rule you are held to [1][2]. The wider set of obligations sits in our overview of NIS2 supply chain security requirements.
Ireland’s NCSC, drafting guidance for exactly the entities the Implementing Regulation does not cover, is the clearest public answer to “how much model is enough”. Its draft measure RMM012 puts the supplier registry and SLA-or-audit assurance in Foundational actions — the baseline every entity is expected to meet — and places “define criteria to select suppliers or service providers” in Supporting actions, which scale with your risk assessment [4]. Read plainly: the register is non-negotiable, the formal rubric is the part that scales. This is Irish draft guidance for Irish entities, not an EU-wide position.
| Your situation | What binds you | Is a documented scoring model expected? |
|---|---|---|
| One of the 11 categories in CIR 2024/2690 Article 1 | Annex point 5.1.2 directly | Yes — the four criteria are an unqualified “shall include” |
| Any other essential or important entity | Article 21(2)(d) and 21(3) as transposed; CIR Annex as benchmark | Reasoned selection is expected; a numeric model is one way to evidence it |
| Irish entity outside the digital sectors | NCSC draft RMM012 (Foundational vs Supporting split) | Registry and SLA/audit assurance are baseline; selection criteria are risk-scaled |
| You supply an in-scope entity but are out of scope yourself | Nothing directly — but your customer’s Article 21(3) duty reaches you | You will be scored regardless, and Article 21(3) has no small-supplier carve-out |
The seven dimensions, and where each one comes from
Most published NIS2 vendor scorecards are generic third-party-risk templates with a directive number stapled on the front. Geographic risk, financial stability, insurance coverage — defensible commercial criteria, none of them named anywhere in the NIS2 stack. The regulation does name criteria. Annex point 5.1.2 states that the criteria to select and contract suppliers “shall include the following”: (a) the cybersecurity practices of the suppliers, including their secure development procedures; (b) their ability to meet cybersecurity specifications set by you; (c) the overall quality and resilience of the ICT products and services and the risk-management measures embedded in them, including their risks and classification level; and (d) your own ability to diversify sources of supply and limit vendor lock-in, where applicable [2].
Article 21(3) adds a fifth input — the vulnerabilities specific to each direct supplier — and Annex 5.1.3 adds a sixth, the results of Article 22(1) coordinated Union risk assessments [1][2]. Split secure development out of (a), where the legislator names it separately in both instruments, and you have a rubric of seven dimensions with a citation behind every row.
| # | Dimension | Legal source | Evidence that answers it | Can it be N/A? |
|---|---|---|---|---|
| 1 | Cybersecurity practices | Annex 5.1.2(a); Art 21(3) | ISMS scope, certifications, control evidence | No — unqualified |
| 2 | Secure development procedures | Annex 5.1.2(a); Art 21(3) | SDLC documentation, SBOM, vulnerability disclosure policy | No — unqualified |
| 3 | Ability to meet your specifications | Annex 5.1.2(b) | Clause-by-clause written response to your own requirements | No — unqualified |
| 4 | Product quality, resilience and classification level | Annex 5.1.2(c) | Architecture and resilience evidence, plus your classification of the service | No — unqualified |
| 5 | Supplier-specific vulnerabilities | Art 21(3), first limb | Known CVEs in the product you buy, breach history, exposure | No — directive-level duty |
| 6 | Diversification and lock-in exposure | Annex 5.1.2(d) | Substitutability analysis, data portability, exit terms | Yes — “where applicable”, with written reasoning |
| 7 | Coordinated Union assessment findings | Annex 5.1.3; Art 21(3) 2nd subpara | Applicable NIS Cooperation Group assessments | Yes — “where applicable”, with written reasoning |
That last column is not a stylistic distinction. Section 5 of the Annex carries ten instances of “shall”, four of “where appropriate” and three of “where applicable” — and none of the qualifiers attach to 5.1.2(a), (b) or (c) [2]. Where a qualifier does apply and you judge the requirement inapplicable, Article 2(2) of the Implementing Regulation requires you to “in a comprehensible manner document its reasoning to that effect”. A qualifier is permission to skip with a written reason, not permission to skip.
ENISA’s guidance under 5.1.2 adds nine further criteria worth considering: the supplier’s legal jurisdiction and whether it is itself regulated under NIS2 or the Cyber Resilience Act, its corporate ownership, its own dependence on sub-suppliers, its breach history, national authority advisories on supplier selection, and lock-in parameters such as open data formats and proprietary features [3]. Those are extensions. They sit alongside the four, not instead of them — and ENISA’s own “examples of evidence” for the whole of 5.1.2 is a single line: a policy containing those elements. The agency that wrote 170 pages of implementation guidance never asks for a number.
Dimension 6 is the one almost every commercial scorecard omits, and it is the one the Union has just reinforced. The Commission’s ICT Supply Chain Security Toolbox, published on 13 February 2026, recommends “the assessment of critical suppliers, the importance of multi-vendor strategies and approaches to overcome dependencies on high-risk suppliers” [6]. Note what dimension 6 actually measures: not the supplier’s security, but your architecture’s tolerance for losing them.
Why a weighted average is the wrong shape
Use gates first, then weight inside the gates. A single weighted total is the default model on the market and it has a structural flaw against this particular legal text: 5.1.2 says the criteria “shall include” all four, and an average lets a strong result on one compensate for a failure on another. A supplier with privileged access to production that scores 9 out of 10 on certifications and 2 out of 10 on its ability to meet your specifications averages to a pass. The average is precisely the artefact that conceals the failure a supervisor would look for.
A defensible model has three layers:
- Gates (pass or fail, before any scoring). Derive them from the contract terms Annex 5.1.4 requires: will the supplier accept the obligation to notify you of incidents without undue delay (5.1.4(d)); a right to audit or to receive audit reports (5.1.4(e)); and disclosure plus security requirements for subcontracting (5.1.4(g))? Add one technical gate: no unresolved critical vulnerability in the specific product you are buying. A supplier that fails a gate does not get a score, it gets a decision.
- A weighted score across the seven dimensions, inside the gates. Weight by how the service actually touches you — access, data, and dependency — which is the output of criticality tiering rather than an input to it. Our guide to classifying suppliers under NIS2 covers that step.
- A written result. The score, the gate outcomes, the date, the evidence reviewed, and what changed because of it.
There is a second failure mode, and it is the most common control in Europe. ENISA found that requiring suppliers to comply with security standards and maintain certifications is the single most cited third-party measure, at 63%, and has been the most cited since 2022 [5]. A certificate is real evidence for dimension 1. It says nothing about dimension 3, because a general-purpose certification is not scoped to the specifications you wrote; nothing about dimension 4’s classification of the specific service you buy; and nothing whatever about dimension 6. Treating a certificate as the score is how three of the four named criteria disappear from a model that still looks compliant.
Where your pass mark legally comes from
In short: nothing in the NIS2 stack tells you what number is good enough. One provision tells you who must decide, and it is not in the supply chain section.
“Risk tolerance”, “risk appetite” and “risk criteria” appear in the Implementing Regulation once, once and twice respectively — and every one of those occurrences sits in a single place, Annex point 2.1.2 [2]. That point requires entities to “establish the risk tolerance level in accordance with the risk appetite”, to “establish and maintain relevant risk criteria”, and to “evaluate the identified risks based on the risk criteria”. Your supplier pass mark is not a supply chain artefact at all. It is an application of risk criteria your risk-management policy is already obliged to hold — which is also why a scoring model invented inside procurement, with no line back to that policy, is hard to defend.
Three consequences follow that most vendor scorecards miss:
- The threshold is board-visible. Annex 2.1.1 requires risk assessment results and residual risks to be accepted by management bodies, or by named accountable persons with adequate reporting to the board. A pass mark set quietly by a security team is a pass mark nobody has accepted.
- Onboarding below your own threshold is not, in itself, an infringement. The threshold is yours, and Annex 2.1.2(j) expressly contemplates accepting residual risk — provided you document “the reasons justifying the acceptance of residual risks in a comprehensible manner”. A supplier that scored 41 against a pass mark of 60 and was approved anyway is defensible with that record, and very hard to defend without it.
- The score has to change something. Annex 5.1.4 requires contract terms to be set on the basis of the policy “and taking into account the results of the risk assessment carried out in accordance with point 2.1”. A score that produces the same contract as a supplier thirty points higher is evidence that the model is decorative.
Annex 2.1.2(d) is worth reading in the same sitting: it requires risks to be identified and documented “in particular in relation to third parties”, explicitly including “the identification of single point of failures”. Concentration risk is already inside your risk process. Dimension 6 is where it surfaces in the supplier model.
Give the score an expiry date
Annual review is a habit, not a requirement. Annex 5.1.6 sets a cadence and a trigger set: entities shall monitor, evaluate and where necessary act upon changes in suppliers’ cybersecurity practices “at planned intervals and when significant changes to operations or risks or significant incidents” affecting supplier products or services occur [2]. Annex 5.1.7 breaks that into four standing duties: monitor SLA implementation reports where applicable; review incidents involving supplier products and services; assess the need for unscheduled reviews and document the findings in a comprehensible manner; and analyse the risks presented by changes to those products and services, taking mitigating measures in a timely manner.
The practical translation is that every supplier score carries a valid-until date and a named trigger list, and that 5.1.7(c) obliges you to record the assessment even when the answer is that no unscheduled review was needed. “We considered it and concluded nothing had changed” is a documented finding. Silence is not.
Dimension 7 works the same way. Two coordinated Article 22(1) assessments now exist, published with the Commission’s toolbox on 13 February 2026 — one on connected and automated vehicles, one on detection equipment used at borders and customs [6]. If neither touches your supply chain, the defensible action is to record that conclusion in your policy review, not to leave the clause unanswered. Choosing an assessment method for the underlying evidence is a separate decision, covered in our guide to vetting suppliers without an audit team.
Who owns which part of the model
| Role | Owns | Effort |
|---|---|---|
| Management body / board | Approving the risk tolerance level behind the pass mark; accepting residual risk on below-threshold suppliers (Annex 2.1.1) | Low — two decisions a year, both minuted |
| Compliance / legal | Keeping every dimension traceable to 5.1.2(a)–(d) or Article 21(3); holding the written reasoning for each “where applicable” exclusion | Medium — the traceability map is built once, maintained per change |
| CISO / security | Gate definitions, dimension weights, evidence review, supplier vulnerability monitoring, unscheduled-review triggers | High — this is the working half of the model |
| Procurement | Running the gates before signature, carrying the score into the 5.1.4 clause set, maintaining the 5.2 supplier registry | Medium — process change rather than new documentation |
What a supervisor can actually test
No authority can mark your model, because there is no correct score. Five things about it are testable from documents you either hold or do not: whether the four named criteria are present; whether every “not applicable” carries written reasoning under Article 2(2); whether the threshold traces to an approved risk tolerance rather than a spreadsheet default; whether the score demonstrably changed a contract term; and whether the review happened when a trigger fired. Build the rubric so those five have paper answers, and the number itself stops mattering — which is, on the evidence of the legal text, exactly the point. For the underlying legal standard the model has to satisfy, see what NIS2 due diligence actually requires.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Frequently Asked Questions
Do I actually need a numeric supplier score?
No instrument in the NIS2 stack requires one. The directive, the Implementing Regulation and ENISA’s guidance all use the words “criteria” and “risk criteria”, never “score” [1][2][3]. A number is one way — often the most auditable way — to show that criteria were applied consistently across a supplier population. A structured qualitative assessment against the same seven dimensions, documented per supplier, meets the same evidentiary purpose.
Can a third-party security rating service be my score?
ENISA names vendor risk-management software reports and standardised questionnaires among the evidence to consider under 5.1.2 [3]. Consider is the operative word. An external rating can supply evidence for dimensions 1 and 5, since both concern the supplier’s own posture and known exposure. It cannot answer dimension 3, which measures the supplier against specifications only you have written, or dimension 6, which measures your architecture rather than theirs.
What should the pass mark be?
No Tier 1 source gives a number, and anyone publishing one is describing their own risk criteria rather than a legal requirement. What matters is that the threshold derives from your approved risk tolerance under Annex 2.1.2(b), is applied consistently, and that every exception is documented under 2.1.2(j).
Does the score cover my suppliers’ suppliers?
Article 21(2)(d), Article 21(3) and Annex points 5.1.2 and 5.2 are all framed around direct suppliers and service providers. Reach beyond that tier is exercised contractually, through the subcontracting requirements in Annex 5.1.4(g), rather than by scoring parties you have no relationship with — a distinction we cover in detail in NIS2 fourth-party risk.
Sources
- European Union. Directive (EU) 2022/2555 (NIS2) — Articles 21(1), 21(2)(d), 21(3) and 22(1). EUR-Lex, Official Journal.
- European Commission. Commission Implementing Regulation (EU) 2024/2690 — Article 1, Article 2(2) and Annex points 2.1.1, 2.1.2, 5.1.2–5.1.7 and 5.2. EUR-Lex, Official Journal.
- ENISA. Technical Implementation Guidance on Cybersecurity Risk Management Measures, version 1.0, June 2025.
- National Cyber Security Centre Ireland. NIS 2 Risk Management Measures Guidance (draft), 4 June 2025 — measure RMM012.
- ENISA. NIS Investments 2025 — Main report, Insight #6.
- European Commission. EU launches new toolbox to strengthen ICT supply chain security, 13 February 2026.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
