Sentrix

Breakdown · NIS2

NIS2: what transposition changes for your suppliers

NIS2 requires essential and important entities to manage their supply chain risk. What a North American supplier must prepare before the questionnaires arrive.

By Sentrix · Published 2026-09-20

A software supplier in Montreal or Boston receives a long security questionnaire from a German customer, with an incident notification clause of twenty-four hours and an audit right. This is not the buyer's whim: it is NIS2 moving down the supply chain, contract by contract.

What the texts say

Directive (EU) 2022/2555, known as NIS2, is published on EUR-Lex. Its Article 21 requires essential and important entities to take cybersecurity risk-management measures, including, in paragraph 2, point (d), supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers. The text specifies that the entity takes into account the vulnerabilities specific to each supplier, the overall quality and resilience of its products and services, and its secure development procedures. Paragraph 3 requires those measures to remain proportionate to the risks, taking into account the state of the art and relevant European and international standards.

Article 22 adds a collective mechanism: the Cooperation Group, the Commission and ENISA may carry out coordinated security risk assessments of critical supply chains, identifying critical ICT services, systems or products, threats and vulnerabilities. Article 23 sets the reporting timeline for significant incidents: early warning within twenty-four hours, notification within seventy-two hours, final report within one month.

According to the European Commission's policy page, the directive came into force in January 2023, covers eighteen critical sectors, targets medium-sized and large entities in those sectors, and Member States had until 17 October 2024 to transpose it. The same page states that on 20 January 2026 the Commission proposed targeted amendments to simplify compliance for 28,700 companies, including 6,200 micro and small enterprises. On the implementation side, ENISA published on 26 June 2025 a technical guidance for Implementing Regulation (EU) 2024/2690, which details the measures expected from digital infrastructure, ICT service management and digital providers, with examples of evidence and mappings to existing standards.

Why it matters

A North American supplier is not, in general, an essential or important entity within the meaning of the directive. It has no European supervisory authority, no registration obligation, no fine to fear directly. But its customer must prove that it manages supplier risk. The only way to do so is to pass the requirements into the contract: security questionnaire, secure development clauses, an incident notification commitment aligned with the Article 23 deadlines, audit rights, exit plan.

National transposition amplifies the effect. The Article 21 base is common, but each Member State has designated its own authority, its own penalty thresholds and its own procedure. A supplier serving customers in France, Germany and the Netherlands receives several versions of the same questionnaire, with different wording. Without a single evidence base, every answer becomes a project.

ENISA's technical guidance is good news here: it names the evidence expected and links it to standards suppliers already know. A program aligned with ISO 27001:2022 covers most of the Article 21 list; what remains is the demonstration.

What we think at Sentrix

A supplier should not answer NIS2 customer by customer. It should build once the evidence its European customers must produce, then reuse it.

  1. Map the exposure: which customers are essential or important entities, in which Member States, for which services. That list determines the national laws to follow.
  2. Align the control base with Article 21: risk management policies, incident handling, continuity, supply chain security, secure development, hygiene and training, cryptography, access control, multi-factor authentication. ISO 27001:2022 (controls 5.19 to 5.22 for suppliers, 8.25 to 8.29 for development) gives the structure.
  3. Prepare a reusable evidence file: certificate or audit report, statement of applicability, vulnerability disclosure policy, penetration test results, incident response plan with the Article 23 deadlines built in.
  4. Standardize the clauses you accept: incident notification, subcontracting, audit, exit. A clause negotiated once, with legal advice, avoids renegotiating it on every contract.
  5. Push the requirement down to your own suppliers: NIS2 speaks of direct suppliers, but your customer will ask what you do about your subcontractors. The third-party risk module of the Sentrix platform is meant to keep that register current.
  6. Follow transposition in your customers' countries, with the regulatory watch and the NIS2 page of the site.

The next step

Take the last supplier questionnaire you received from a European customer and file each question under one of the Article 21 points. The questions without a documented answer are your work plan. If you want to do it with us, write to us.

Sources

Frequently asked questions

Does NIS2 apply directly to a supplier established in Canada or the United States?
No, unless it provides a covered service in the Union itself. The directive targets essential and important entities established in Europe, and it is on them that Article 21 imposes the duty to manage the security of their supply chain. The obligation reaches the supplier through the contract: questionnaires, security clauses, audit rights, incident notification. Refusing those clauses usually means losing the customer.
What does Article 21 actually require on the supply chain?
Article 21, paragraph 2, point (d), requires measures on supply chain security, including security-related aspects of the relationships with direct suppliers. The entity must take into account the vulnerabilities specific to each supplier, the overall quality of its products and services and its secure development practices. Under paragraph 3, the measures must remain proportionate to the risk.
Does national transposition change the requirements from one country to another?
The base is the same, since Article 21 sets a minimum list of measures and Member States had to transpose it by 17 October 2024, according to the European Commission. What varies is the competent authority, the registration procedure, the fine thresholds and the actual timeline. A supplier serving several countries must follow each national law, not only the text of the directive.

Let's talk about your compliance program.

Last updated: 2026-09-20