secria.eu

why am I responsible for the security of my suppliers

The chain is only as strong as its weakest supplier

Responsibility for supplier security rests with essential and important entities because their own digital security largely depends on the systems, software and services of others. An organisation can secure its own network well, but if a supplier with access to those systems is poorly secured, this creates an entry point that bypasses the organisation's own measures. The duty of care therefore looks not only at the walls of the organisation itself, but at the entire supply chain behind it.

In practice, this affects far more businesses than just the regulated organisations themselves. An essential or important entity that must assess its supply chain often passes that assessment on in the form of a questionnaire or contractual requirement to its suppliers — even if those suppliers are not subject to the law themselves. Anyone receiving such a security questionnaire from a customer thereby experiences the consequences of NIS2 without being subject to it themselves. Which measures are relevant in this regard is described under the ten measures distinguished by the Directive.

Where this follows from the duty of care

Article 21(2) of the NIS2 Directive explicitly names the security of the supply chain as part of the ten measures falling under the duty of care, including the security aspects of relationships with direct suppliers and service providers. The Cybersecurity Act incorporates this obligation into Dutch law. The NCSC explains that this duty of care is risk-based: an entity must identify where risks exist in the supply chain and put appropriate measures in place to address them, which in practice often means suppliers are asked to provide evidence of their security. ISO/IEC 27001 offers in Annex A a set of control measures that address supplier relationships and thus frequently serve as a reference framework in such assessments.

What you concretely need to do

The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.

View the subscription First the free NIS2 check

This is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.

Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.