NIS2 Third-Party Risk Management

NIS2 Art. 21 places concrete requirements on the management of supplier and third-party risks.

NIS2 Art. 21 Para. 2 lit. d explicitly requires companies to ensure security in the supply chain — structured register, risk assessments, monitoring and evidence documentation.

What does NIS2 Art. 21 specifically require?

NIS2 Art. 21 stipulates: identification of all relevant third parties, risk assessment, contractual security requirements, continuous monitoring and incident response processes.

NIS2 Art. 21 (2)(d)

Security in the supply chain including security-related aspects of the relationships between entities and their direct providers or service providers.

Continuous Monitoring as NIS2 Requirement

Annual questionnaires are insufficient under NIS2. The directive requires dynamic risk management — continuous monitoring, automatic alerting and regular reassessments.

FAQ

What must companies prove for their suppliers under NIS2?+

NIS2-compliant TPRM with 360TPRM

Sehen Sie in einer 45-minütigen Demo, wie 360TPRM Ihre Anforderungen konkret erfüllt.

Demo →