EU Directive
NIS2
NIS2 may create direct exposure or influence the supply chain requirements of European clients, even where the supply is not a digital product.
Effect of this requirement
This rule cannot be read in isolation.
- Transfers
- Bilateral relationship
- Country sources reviewed on
Assumptions, limitations and sources of this reading
Reading point
The supplier relationship becomes the entry point
The supplier examines what its European client genuinely depends on it to protect.
- Sector and size of the entity concerned
- Applicable national transposition
- Requirements imposed by the client
- Supplier security, access and dependencies
Dependency chain
Read NIS2 from the European organisation through to the operations entrusted to the supplier.
European entity concerned
It organises the control of its risks and its supply chain.
Dependent service or component
The criticality of the supply determines the depth of expectations.
Supplier requirement
Access, incident, continuity, vulnerabilities and subcontracting become examinable.
Operational evidence
The supplier demonstrates what it can actually support within its scope.
Decision path
Link NIS2 to the client's actual dependency
The directive becomes actionable once the supply chain is translated into observable services, access, events and responsibilities.
Identify the European entity, its sector and the relevant national transposition without automatically extending its status to the supplier.
Describe what the client would no longer be able to protect or maintain if the supplier's service, component or access became unavailable.
Isolate the security, notification, continuity, vulnerability and subcontracting requirements actually passed on to the supplier.
Link each response to a practice, a configuration, dated evidence and an explicit limit within the scope provided.
Supply chain expectations
What the client is seeking to control beyond its own systems.
Questions to address
- Your risk and incident management arrangements
- Your supply chain security measures
- Your notification timelines and your crisis organisation
- If you are yourself an essential or important entity
Elements that support the response
- Dated security policy and risk analysis
- Incident process exercised, with reports
- Register of subcontractors and their commitments
- Evidence of client-imposed controls (MFA, logs, backups)
Confusions to avoid
- Treating NIS2 as a certification to be obtained
- Copying the client entity's obligations directly into your own policies
- Overlooking the national transposition applicable to the client
- Promising notification timeframes aligned with the text without the operational capacity
Demonstration
A client dependency becomes a precise question for the supplier.
The case links the European activity, the dependent service, the expectation conveyed and the operational evidence the supplier can genuinely produce.
Understanding how evidence is qualified →Apply this reading
Identify the dependency the European client is seeking to control.
The client's sector, the service provided and the consequences of a disruption make it possible to target the supply chain expectations to be examined.

