NIS2: your suppliers, and the proof
Complete plan
An attack can come in through a provider that already has access. What to require from your suppliers, and how to show that management really oversees security: the oversight file.
- 3 min
- 3-question check
- English · Français
- Attestation
You will be able to
- Identify critical suppliers: access, dependency, data
- Know what to require: written commitments, controlled access, evidence, exit plan
- Build the file that proves management oversight
The module
3 min-
NIS2: your suppliers, and the proof 2 min
-
Knowledge check
3 questions, pass mark 80 %. Explanations after each answer; you can try again.
-
Attestation
One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.
Sources
- Directive (UE) 2022/2555 (NIS 2), JO L 333 du 27.12.2022, art. 21(2)(d) et 21(3) (chaîne d'approvisionnement), art. 20 (supervision)
- ENISA, NIS Investments 2025, déc. 2025 : 37 % des 481 répondants placent la chaîne d'approvisionnement parmi les exigences NIS 2 les plus difficiles (jusqu'à 3 choix)
- Transposition en France : projet de loi « Résilience » adopté par le Sénat le 12 mars 2025, examen en séance à l'Assemblée nationale prévu les 7 et 9 octobre 2026 ; non promulgué au 3 octobre 2026 (à revérifier avant publication).
Version 1 · updated October 4, 2026