Skip to content
Knowledge base Updated: February 5, 2026

NIS2 Supply Chain Audit: How to Manage ICT Vendor Risk?

NIS2 mandates vendor security verification. Discover a practical approach to supply chain auditing - from inventory to scorecard.

Your cloud provider fell victim to ransomware. Your ERP vendor had a data breach. The printer company had a backdoor in their firmware. In each of these scenarios - your supplier’s problem becomes your problem. And that’s exactly why NIS2 requires organizations to formally manage supply chain security.

Quick Navigation

What does NIS2 say about supply chain?

Article 21(4) of the NIS2 Directive

The NIS2 Directive requires essential and important entities to implement cybersecurity risk management measures, including:

“Supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers.”

This is not a suggestion - it’s a legal requirement, with penalties of up to EUR 10 million or 2% of annual turnover for non-compliance.

What does this mean in practice?

You must:

  • Identify all ICT (Information and Communication Technology) suppliers
  • Assess the risk associated with each vendor
  • Have procedures for selecting and monitoring vendors
  • Require specific security standards from suppliers
  • Be able to demonstrate this to auditors/regulators

It’s not enough to:

  • Have a vendor list in Excel without risk assessment
  • Send a questionnaire once and forget about it
  • Include a clause saying “vendor ensures security” without specifics

📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać

Why is this a challenge for organizations?

The scale problem

An average company has 100-300 ICT vendors:

  • Cloud (AWS, Azure, Google Cloud)
  • SaaS (Salesforce, HubSpot, Slack, Zoom)
  • ERP/CRM (SAP, Microsoft Dynamics)
  • Infrastructure (Dell, HP, Cisco)
  • Software (Adobe, Microsoft, specialized)
  • Services (printers, telephony, internet)
  • IT subcontractors (software house, helpdesk)

Auditing each one separately takes hundreds of work hours that the IT team doesn’t have.

The competency problem

Sending a security questionnaire is one thing. But:

  • How do you verify if the answers are truthful?
  • How do you assess if a vendor’s ISO 27001 certificate is “good”?
  • How do you compare vendor A’s risk vs vendor B’s?
  • What do you do when a vendor refuses to respond?

The silo problem

  • Procurement signs contracts without consulting IT
  • IT doesn’t know about all SaaS used by the business (Shadow IT)
  • Security has no visibility into vendor contracts
  • Legal doesn’t understand the technical security aspects

How to conduct a vendor audit?

Step 1: ICT vendor inventory

Information sources:

  • Procurement department - list of contracts and invoices
  • Finance department - payments to IT vendors
  • IT - systems, licenses, integrations
  • Security - list of VPN connections, API keys
  • Network scan - what external services are being used

What we collect for each vendor:

  • Name and contact details
  • Type of service/product
  • What data they process (personal, business, critical?)
  • Do they have access to our network?
  • Who owns the relationship (business owner)
  • Contract start and expiration dates

Step 2: Categorization by risk

You can’t treat a cloud provider the same as a pen supplier. Categorization allows you to focus resources where the risk is greatest.

CategoryCriteriaExamples
CriticalAccess to critical data, single point of failure, no alternativeCloud provider, ERP, core banking
HighAccess to sensitive data, significant impact on operationsCRM, email, HR system
MediumLimited access, replaceableCollaboration tools, monitoring
LowNo data access, minimal impactPrinters, telephony, office supplies

Step 3: Assessment by category

For Critical vendors:

  • Full security questionnaire (100+ questions)
  • Interview with vendor representative
  • Certificate verification (ISO 27001, SOC 2)
  • OSINT - checking incident history
  • Review of security clauses in the contract
  • On-site audit (optional for the largest)

For High vendors:

  • Extended questionnaire (50-80 questions)
  • Certificate verification
  • OSINT

For Medium vendors:

  • Simplified questionnaire (30 questions)
  • Basic verification

For Low vendors:

  • Minimal or no verification
  • Standard contract clauses

Vendor categorization by risk

Vendor risk matrix

We use two dimensions for categorization:

Dimension 1: Impact

  • What data does the vendor process?
  • How critical is the service to operations?
  • Is there an alternative/backup?

Dimension 2: Likelihood

  • What is the vendor’s security maturity?
  • Has the vendor had incidents in the past?
  • How large is the attack surface?
                    IMPACT
              Low    Medium    High
         ┌─────────┬─────────┬─────────┐
    High │ Medium  │  High   │ Critical│
         ├─────────┼─────────┼─────────┤
LIKEL.   │  Low    │ Medium  │  High   │
Medium   ├─────────┼─────────┼─────────┤
    Low  │  Low    │  Low    │ Medium  │
         └─────────┴─────────┴─────────┘

Example categorization

VendorServiceDataImpactLikelihoodCategory
AWSCloud infrastructureAllCriticalLow (SOC 2)High
Software house XApp developmentCode + test dataHighMediumHigh
Printer companyMFP printersScanned documentsMediumHighMedium
ISPInternet connectionN/AMediumLowLow

Security questionnaires - how to do them right

Structure of a good questionnaire

Section 1: General information

  • Certificates and audits (ISO 27001, SOC 2, PCI DSS)
  • Insurance policies (cyber insurance)
  • Incident history

Section 2: Governance

  • Do they have a CISO / person responsible for security?
  • Do they have security policies?
  • How often are they updated?

Section 3: Technical security

  • MFA for system access
  • Data encryption (at rest, in transit)
  • Backup and disaster recovery
  • Patch management
  • Monitoring and logging

Section 4: Physical security

  • Data center location
  • Physical access control
  • Redundancy

Section 5: Incident management

  • Do they have an incident response plan?
  • SLA for incident notification
  • How do they handle breaches?

Section 6: Compliance

  • GDPR - are they a processor/controller?
  • Data location (EU/US)
  • Subprocessors

Verifying responses

Don’t trust - verify:

OSINT (Open Source Intelligence):

  • Search for vendor + “breach” / “hack” / “leak”
  • Check Have I Been Pwned for the domain
  • Review forums and social media

Certificate verification:

  • Request a copy of the ISO 27001 certificate (not just a statement)
  • Check the certification scope (it doesn’t always cover what you’re buying)
  • Verify in the certification body’s registry

Follow-up interview:

  • For critical/high vendors - schedule a call
  • Ask deeper questions
  • Assess maturity (do they know what they’re talking about?)

Vendor Scorecard - assessment and monitoring

Scoring model

Each vendor receives a score on a 1-5 scale (or A-E) based on:

AreaWeightQuestions
Governance20%Policies, CISO, training
Technical security30%MFA, encryption, patching
Incident management20%IR plan, SLA, communication
Compliance15%Certificates, GDPR, audits
History15%Incidents, reputation

Acceptance thresholds

ScoreRatingAction
4.0 - 5.0ExcellentAccept, review every 24 months
3.0 - 3.9GoodAccept, review every 12 months
2.0 - 2.9AcceptableConditional acceptance, improvement plan, review every 6 months
1.0 - 1.9PoorReject or exit strategy
< 1.0CriticalImmediate action (termination or escalation)

Continuous monitoring

Assessment is not a one-time project:

Ongoing:

  • Incident alerts (Google Alerts, threat intelligence)
  • Certificate change monitoring
  • Feedback from internal users

Quarterly:

  • Critical vendor review
  • Scorecard update for vendors with improvement plans

Annually:

  • Full re-assessment of all High and Critical vendors
  • Categorization update (new services, business changes)
  • Board report

Security clauses in contracts

Minimum contractual requirements

Every ICT vendor contract should include:

1. Security requirements:

  • Compliance with specific standards (ISO 27001, CIS Controls)
  • Data encryption
  • Access control and MFA
  • Backup and disaster recovery

2. Right to audit:

  • Ability to conduct security audits
  • Access to SOC 2 / ISO 27001 reports
  • Right to ask questions and request evidence

3. Incident management:

  • SLA for incident notification (e.g., 24h)
  • Cooperation in case of incident
  • Post-incident report

4. Subcontractors:

  • List of subprocessors
  • Notification of changes
  • Same requirements for subcontractors

5. Termination:

  • Data return or destruction
  • Transition period
  • Confirmation of data deletion

Example clause

“The Supplier commits to: (a) maintaining ISO 27001 certification for services covered by the Agreement throughout its duration; (b) notifying the Client of any security incident concerning Client data within 24 hours of detection; (c) allowing the Client to conduct a security audit once a year upon prior agreement of the date.”

Summary

Supply chain audit is not a one-time project - it’s a continuous process. NIS2 requires:

  1. Inventory - you know who your ICT vendors are
  2. Categorization - you know which ones are critical
  3. Assessment - you know each one’s security level
  4. Monitoring - you track changes and incidents
  5. Documentation - you can demonstrate this to auditors

Organizations that don’t have resources to run this process internally can consider outsourcing to specialized partners offering Vendor Risk Management services.


Need support with supply chain auditing? We take over the entire process - from inventory to scorecard. Contact us to discuss details.

Learn key terms related to this article in our cybersecurity glossary:


Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist