NIS2: your suppliers, and the proof

Complete plan

An attack can come in through a provider that already has access. What to require from your suppliers, and how to show that management really oversees security: the oversight file.

  • 3 min
  • 3-question check
  • English · Français
  • Attestation

You will be able to

  • Identify critical suppliers: access, dependency, data
  • Know what to require: written commitments, controlled access, evidence, exit plan
  • Build the file that proves management oversight

The module

3 min
  1. NIS2: your suppliers, and the proof 2 min
  2. Knowledge check

    3 questions, pass mark 80 %. Explanations after each answer; you can try again.

  3. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Sources
  • Directive (UE) 2022/2555 (NIS 2), JO L 333 du 27.12.2022, art. 21(2)(d) et 21(3) (chaîne d'approvisionnement), art. 20 (supervision)
  • ENISA, NIS Investments 2025, déc. 2025 : 37 % des 481 répondants placent la chaîne d'approvisionnement parmi les exigences NIS 2 les plus difficiles (jusqu'à 3 choix)
  • Transposition en France : projet de loi « Résilience » adopté par le Sénat le 12 mars 2025, examen en séance à l'Assemblée nationale prévu les 7 et 9 octobre 2026 ; non promulgué au 3 octobre 2026 (à revérifier avant publication).

Version 1 · updated October 4, 2026