For the Head of Procurement (Head of Procurement), the world has been tidy so far. Key metrics were cost optimization, process transparency and contractual compliance. The IT vendor selection process was based on clear criteria: functionality, warranty terms, support (SLA) and, above all, price. The amendment to the law on the National Cyber Security System (NSC), implementing the NIS2 directive, fundamentally overturns this order.
The new regulations introduce a tough requirement for supply chain risk management (SCRM). In practice, this means that your organization becomes legally responsible for the security level of its ICT suppliers. The purchasing department, as the “gateway” to the organization through which all external partners enter, suddenly becomes one of the key control points in the company’s cyber security strategy. Your role evolves - you go from being a cost manager to a risk manager.
Shortcuts
- Why does KSC/NIS2 put the purchasing department on the front lines of cyber security?
- What exactly is supply chain risk management (SCRM) from a procurement perspective?
- What business and legal risks does a company run by ignoring ICT vendor security?
- How should the purchasing department work with the CISO and legal department in the new model?
- How to change the RFP (request for proposal) process to accommodate KSC/NIS2 requirements?
- What security clauses must become standard in any contract with an ICT provider?
- How do you evaluate a provider in terms of security, not just price and functionality?
- Does the purchasing department now need to actively audit suppliers?
- What to do with existing contracts that do not include security provisions?
- How can an external GRC partner (like nFlo) help the purchasing department vet suppliers?
- KSC/NIS2 Procurement Checklist: Changing the Procurement Process.
Why does KSC/NIS2 put the purchasing department on the front lines of cyber security?
The answer is simple: attacking the supply chain has become one of the most devastating and effective attack vectors. Cybercriminals have realized that it is easier to attack a small, poorly secured software supplier than a large, well-protected entity. By compromising the provider, they gain trusted access to the systems of all its customers. KSC/NIS2 is intended to curb this practice.
The law explicitly requires key and important players to assess the security of their technology suppliers. Since it is the purchasing department that formally selects these suppliers, negotiates contracts with them and introduces them into the company’s ecosystem, it is your decisions that have a direct impact on the level of risk.
Choosing a supplier based only on the lowest price, without verifying its security standards, is now not only bad business practice. It is a blatant failure to meet a regulatory obligation that can expose your company’s management to personal financial sanctions. Your role is no longer purely operational; it becomes part of strategic risk management.
📚 Read the complete guide: NIS2: Kompletny przewodnik po dyrektywie NIS2 - obowiązki, kary, terminy
What exactly is supply chain risk management (SCRM) from a procurement perspective?
For the CISO, SCRM is a complicated technical process. For you, as the head of procurement, SCRM is a new form of supplier qualification and verification (supplier due diligence). It’s no longer just a check to see if a supplier is financially stable and has good credentials. It’s a formalized process that you must implement into your procurement procedures.
The process consists of three main steps. The first is Risk Identification and Qualification - you need to know which suppliers to audit at all. A printer toner supplier has different risks than a cloud system provider that stores your financial data.
The second stage is Assessment - that is, how you verify in practice that a supplier is safe. This requires new tools: from self-assessment questionnaires to formal audits. The third stage is Management (Mitigation & Monitoring) - that is, what you will do with the result of the assessment. What contractual provisions will you put in place to force the supplier to maintain standards, and how will you monitor it throughout the contract lifecycle?
What business and legal risks does a company run by ignoring ICT vendor security?
The risks are twofold, and for management both are equally painful: operational and legal. Operational risk is the scenario in which your chosen (because it was the cheapest) software provider falls victim to a ransomware attack. As a result, its service stops working, blocking a critical business process in your company. Or worse, the attacker uses the provider’s service access to encrypt your own systems. The cost of downtime, reputational damage and data restoration goes into the millions.
The legal risk is new and directly related to KSC/NIS2. In the event of such an incident, the regulator will not go after just the attacker. It will come to your company and ask: “What steps did you take to verify the security of this supplier before signing the contract?”. If the only answer is “he gave the best price,” the regulator will consider it gross negligence.
The result will not only be financial penalties for the company, but potentially personal sanctions for management for lack of supply chain oversight. Your purchasing process becomes evidence in a due diligence case.
How should the purchasing department work with the CISO and legal department in the new model?
The purchasing department cannot and should not become the cyber security expert. KSC/NIS2 enforces the creation of a tripartite alliance that must act as one body in every ICT purchasing process.
-
CISO (Chief Security Officer): Defines the CO. The CISO is responsible for creating SCRM policies and minimum security requirements (e.g., “every cloud provider must have ISO 27001 and offer MFA”). Provides you with assessment questionnaires and supports you in the technical interpretation of the answers.
-
Head of Procurement (Ty): Manages the HOW. You are the owner of the procurement process. Your job is to implement CISO requirements into your procedures (RFP, evaluation), manage the commercial relationship with the supplier, and make sure the process is transparent and efficient.
-
Legal Department: Guarantees LEGAL POWER. Lawyers are responsible for translating the CISO’s security policy into hard, enforceable clauses in the contract.
Without this close cooperation, the process will fail. A CISO without you won’t block the purchase of a risky supplier, and you without a CISO won’t know what to ask.
How to change the RFP (request for proposal) process to accommodate KSC/NIS2 requirements?
Your legacy request for proposals (RFP) probably had sections: Functional Requirements, Technical Requirements (Performance), Warranty Conditions, Price Criteria. Now you need to add a new mandatory section: Safety and Regulatory Compliance Requirements.
This section cannot be optional. It should be treated as a formal criterion (Go/No-Go). If a supplier is unable to meet these requirements, its bid (even if the cheapest) should be rejected on formal grounds before it even reaches the merit evaluation.
What must this section contain? First, a security assessment questionnaire (provided by the CISO) that the supplier must complete. Second, a list of minimum requirements (e.g., “Bidder must be ISO 27001 certified,” “Solution must support MFA,” “Bidder must accept our security clauses in the contract”). In this way, you filter out risky suppliers at the earliest possible stage, saving time in analyzing bids that would not pass an audit anyway.
What security clauses must become standard in any contract with an ICT provider?
The contract is your primary instrument for enforcing KSC/NIS2 requirements. The Legal Department must develop a standard Security Annex to be attached to each ICT vendor contract. It must include, at a minimum:
-
Right to Audit: A clause giving you the right to verify supplier compliance (through questionnaires, inspections or even technical tests).
-
Incident Reporting Obligation: The provider must be contractually obligated to inform you immediately (e.g., within 24 hours) of any security incident that affects your data or services.
-
Requirement to Use Specific Controls: Commitment to adhere to your policies, use of MFA by vendor personnel, data encryption, regular vulnerability management, etc.
-
Sub-Supplier Safety: A “flow-down” clause that requires your supplier to apply the same safety standards to its sub-suppliers.
-
Liability and Contractual Penalties: Clearly define the financial responsibility of the supplier for violations of security requirements that will lead to damages on your side.
Having such provisions in your contracts is hard evidence to the regulator that you are actively managing supply chain risk.
How do you evaluate a provider in terms of security, not just price and functionality?
This is a change to your “scorecard” (scorecard) of the supplier. The previous scorecard might have looked like this, for example: 70% Price, 30% Functionality. This model is no longer valid. The new evaluation matrix must include security as the third, equivalent pillar.
An example new matrix could look like this: 40% Price, 30% Functionality, 30% Security Rating. The security assessment must be objective - based on the results of the questionnaire, the certificates held (ISO 27001, TISAX, DORA, etc.) and the results of the audit.
Most importantly, you must set a minimum threshold for acceptance. If a supplier scores below, say, 70% in the security assessment, it should be disqualified, no matter how attractive the price it offered. This gives you, as head of procurement, a firm basis for rejecting a bid that is cheap but risky.
Does the purchasing department now need to actively audit suppliers?
Yes, although the form of the audit depends on the level of risk. KSC/NIS2 requires an “assessment” of security, and you must be able to prove that this assessment was reliable. You cannot rely solely on the vendor’s marketing statements.
Your purchasing process must provide for three levels of verification:
-
Low Risk (e.g., COTS software provider): Completed self-assessment questionnaire (SAQ) and provision of evidence (e.g., ISO certification).
-
Medium Risk (e.g. software house developing an application): Completed SAQ and documentation audit (verification of their policies, BCP procedures, recent pentest reports).
-
High Risk (e.g., managed IT services provider, key cloud provider): A full audit, potentially including a technical audit or penetration test conducted by your team or (more likely) by a hired, third-party partner.
For the purchasing department, this means managing the process - sending out questionnaires, tracking responses, collecting evidence and archiving it for possible inspection.
What to do with existing contracts that do not include security provisions?
This is one of the biggest challenges. Your company is likely tied to multi-year contracts with key ICT vendors, and these contracts were signed in the “old world” - without security clauses, audit rights or incident reporting requirements. These contracts are ticking time bombs.
As head of procurement, you must immediately, in collaboration with the CISO, inventory and prioritize these contracts. Focus on the 20% of suppliers that generate 80% of the risk (critical suppliers).
Then you have to start the process of renegotiating these contracts. You cannot wait 3 years for them to expire. The entry into force of KSC/NIS2 is an excellent and very powerful legal lever. You can approach the supplier with the information: “Due to the entry into force of the new regulations (KSC/NIS2), we are legally obliged to annex our contract with the new Security Annex. This is a prerequisite for the continuation of our cooperation.”
How can an external GRC partner (like nFlo) help the purchasing department vet suppliers?
As Head of Procurement, your job is to manage the process, negotiation and formal compliance. You, nor your team, are the cyber security auditor. It is unrealistic to attempt to make a substantive, independent assessment of a supplier’s technical response to a questionnaire.
This is where the role of an external GRC partner comes in, acting as your “supply chain audit office.” A partner such as nFlo, as part of its implementation services (CORE Package), offers proactive support in SCRM.
Instead of analyzing a supplier’s complex technical documentation yourself, you outsource it to nFlo experts. They are the ones who conduct a procedural and technical audit of your supplier and come back to you with a simple, businesslike recommendation: “Supplier A is compliant, risk acceptable. Supplier B has critical gaps, we recommend rejection of the offer or a remediation plan.” This allows you to keep the process transparent and efficient, while basing your purchasing decisions on hard, expert risk analysis.
KSC/NIS2 Procurement Checklist: Changing the Procurement Process.
The following table summarizes the key changes in the ICT purchasing process necessitated by KSC/NIS2.
Process StageTraditional Approach (Focus: Price)New KSC/NIS2 Approach (Focus: Risk)1. qualification of the SupplierFinancial verification and references.Financial Verification + Cyber Risk Categorization (Critical, Important, Low).**2 Request for Proposal (RFP).**Functional requirements and price.Functional requirements + Mandatory Security section (questionnaire, formal requirements).3 Evaluation of the OfferMainly the price criterion. The cheapest supplier wins. Multi-criteria matrix: Price + Functionality + Safety Score. Risky bids are rejected. 4 Negotiation and AgreementNegotiate price, payment terms and SLAs.Price negotiation + Implementation of mandatory security clauses (Right to audit, incident reporting).5 Contract ManagementMonitor SLA implementation (e.g., service response time).SLA monitoring + Cyclical re-assessment of vendor security (e.g., annual audit, certificate verification).
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- NIS2 — NIS2 (Network and Information Security Directive 2) is an EU directive…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
- Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
- NIST Cybersecurity Framework — NIST Cybersecurity Framework (NIST CSF) is a set of standards and best…
- 0-Day Exploit — A 0-Day Exploit (zero-day exploit) is a security vulnerability in a computer…
Learn More
Explore related articles in our knowledge base:
- How to conduct a KSC NIS2 readiness audit? A practical guide for CISOs
- KSC NIS2: How should CTOs and CIOs plan for implementation? From audit to implementation
- Why are penetration tests a key proof of compliance with KSC NIS2?
- A security operations center (SOC) in every office? We demystify a key requirement of the KRI and NIS2
- Common Misconceptions About the NIS2 Directive
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
Related topics
See also:
