Why NIS2 turns your suppliers into your security problem
If you run a small or medium business in Europe, there is a good chance you have already been asked an uncomfortable question by a client: “Can you prove your systems are secure?” That question is not corporate curiosity. It is NIS2 working its way down the supply chain, one contract at a time.
The NIS2 directive (EU 2022/2555) changed the logic of cyber risk management. It no longer treats an organisation as a fortress with walls to defend. It treats it as a node in a network of suppliers, software vendors, cloud platforms and managed service providers, each one a potential entry point. Article 21 makes this explicit: essential and important entities must address security in their supply chain relationships, including the specific vulnerabilities of each direct supplier.
The practical consequence for Italian and European SMBs is significant. Even if your company is too small to fall directly under NIS2, your customers may not be. And when they are obliged to assess the security of their suppliers, you become the object of that assessment.
From one-off vetting to continuous rating
The old approach to supplier security was a questionnaire. You sent a PDF with forty questions, the supplier ticked the boxes, you filed the answer and moved on for another three years. NIS2 makes that model obsolete, because a snapshot taken in January says nothing about a compromised vendor in September.
What the directive pushes towards is a system of continuous supplier security rating: a structured, repeatable and documented way of scoring each supplier’s security posture and updating that score as conditions change. The rating is not an academic exercise. It drives decisions about contracts, access levels, monitoring intensity and, in some cases, whether the relationship continues at all.
Think of it the way a bank thinks about credit risk. No lender grants a loan based on a balance sheet from three years ago, then stops looking. They monitor, they re-score, they set limits proportional to the risk. NIS2 asks you to apply the same discipline to cyber risk in your vendor portfolio.
What NIS2 supplier obligations actually require
Article 21(2)(d) of the directive lists supply chain security among the minimum risk management measures. The wording is deliberately broad, but the Italian implementation (Legislative Decree 138/2024) and the ACN guidance that follows it give a clearer picture of what regulators expect to see.
A mapped and classified supplier register
You cannot rate what you have not listed. The first step, and the one most SMBs skip, is building a complete inventory of suppliers who touch your systems, your data or your operational continuity. That includes the obvious names (cloud provider, ERP vendor, MSP) and the less obvious ones (the accounting firm with remote access, the maintenance company with VPN credentials, the marketing agency inside your CRM).
Each supplier then needs a criticality class. A reasonable three-tier model works for most small organisations: critical suppliers whose failure stops the business, important suppliers who cause serious disruption, and standard suppliers who are replaceable within days. The depth of assessment should scale with the tier, not apply uniformly.
Contractual security clauses
NIS2 expects security requirements to move from good intentions into contracts. For critical suppliers, that means written commitments on incident notification timelines, patch management, access control, subcontractor disclosure and the right to audit or receive audit evidence.
The incident notification clause deserves particular attention. NIS2 imposes a 24-hour early warning and a 72-hour detailed notification on regulated entities. If your supplier discovers a breach and tells you five days later, your own compliance is already broken. The contract has to align supplier reporting with your regulatory clock.
Evidence, not declarations
Regulators and auditors increasingly distinguish between what a supplier claims and what a supplier can demonstrate. Certifications (ISO/IEC 27001, SOC 2), penetration test summaries, vulnerability scan reports, business continuity test results and insurance coverage all count as evidence. A self-assessment questionnaire signed by a sales manager does not.
How to assess supplier security without an enterprise budget
This is where most SMB owners stop reading, assuming the exercise requires a dedicated risk team. It does not. A proportionate approach, which is exactly what NIS2 asks for, can be run by one person with a spreadsheet and a disciplined calendar.
Build a simple scoring model
Choose five to seven dimensions and assign each a weight. A workable starting set: certifications and compliance, incident history and transparency, access management practices, business continuity and recovery capability, subcontractor management, external attack surface, and contractual maturity. Score each dimension from one to five and calculate a weighted total.
The absolute number matters less than consistency. What you need is a comparable score across suppliers, a documented method behind it, and a trail showing when each score was produced and why it changed. That documentation is what turns an informal judgement into defensible due diligence.
Set review frequencies by tier
Critical suppliers get reassessed every six months, important ones annually, standard ones every two years or at contract renewal. On top of the calendar, define trigger events that force an immediate re-rating: a publicly disclosed breach at the supplier, a change of ownership, a major change in the service delivered, or a relevant CVE affecting their technology stack.
Use external signals
You do not need to rely only on what suppliers tell you. Publicly available signals give a useful reality check: certificate expiry and TLS configuration, exposed services visible through Shodan-style scanning, domain and email authentication records (SPF, DKIM, DMARC), breach databases, and CVE feeds for the products they run. These checks cost nothing but attention, and they frequently contradict the questionnaire.
For organisations without in-house capacity, this is precisely the kind of recurring activity worth delegating. Structured supplier monitoring pairs naturally with managed cybersecurity services and with a help desk service that already tracks your technology estate and knows which vendors sit inside it.
The numbers behind the requirement
The regulatory pressure is not arbitrary. ENISA’s threat landscape reporting has consistently identified supply chain compromise as one of the prime threats facing European organisations, and the European Commission’s impact assessment for NIS2 pointed to a sharp rise in attacks entering through third parties rather than through the target’s own perimeter.
Industry research points the same way. Multiple vendor studies over recent years have found that a majority of organisations experienced at least one breach originating with a third party, and that the average cost of a third-party incident exceeds that of a directly caused one, largely because detection takes longer when the intrusion arrives through a trusted channel.
For SMBs the asymmetry is worse. A large enterprise absorbs the cost of a supplier incident. A twenty-person company that loses access to its ERP for ten days because its provider was hit by ransomware may not recover the lost contracts at all. Supplier rating is not a compliance ritual: it is operational self-defence.
Where Italian SMBs stand in practice
Italy transposed NIS2 through Legislative Decree 138/2024, with the Agenzia per la Cybersicurezza Nazionale acting as the competent authority and registration obligations already in force for entities in scope. Sanctions are material: up to 10 million euro or 2% of global turnover for essential entities, with management held personally accountable for approving and supervising risk measures.
But the wider effect is contractual rather than sanctionary. Public administrations and large regulated companies are writing NIS2-derived requirements into tenders and framework agreements. Suppliers who can produce a security rating, a supplier register and evidence of continuous monitoring win work. Those who cannot are quietly filtered out during qualification, often without being told why.
That dynamic is already visible in public sector procurement, where requirements flow directly from directive obligations into vendor qualification criteria (a shift we see constantly in projects for public administration).
A realistic starting point
If you are beginning from zero, three months of focused work gets you to a defensible position. Month one: build the supplier register and assign criticality tiers. Month two: design the scoring model and assess your critical tier. Month three: update contracts for critical suppliers and schedule the review calendar.
The result is not perfect security. It is something more useful in practice: a documented, proportionate and repeatable process that satisfies auditors, reassures clients and, crucially, tells you which of your vendors would actually hurt you. If you want the full regulatory picture before you start, our dedicated guide to NIS2 compliance covers scope, deadlines and obligations in detail.