NIS2 · Supply-Chain Security

NIS2 and Supply-Chain Security: Is your business only as secure as its suppliers?

You may not think of your organisation as critical national infrastructure. But if you operate in a regulated sector, or supply an organisation that does, NIS2 can change how cyber risk must be managed and what customers expect you to prove.

Guide to the requirements 10 min read Updated September 2026

Legislative status

As of September 2026, Ireland had not completed the transposition of NIS2 into national law. In July 2026, the European Commission referred Ireland to the Court of Justice of the European Union for failing to notify full transposition. The final Irish legislation remains important, but organisations should not treat the delay as a reason to postpone preparation.

The EU's NIS2 Directive raises cyber security expectations across 18 critical sectors. In-scope organisations are expected to look beyond their own systems and address vulnerabilities in their supply chains, including the security-related aspects of their relationships with direct suppliers and service providers.

For Irish businesses, the practical effects can include deeper supplier assessments, more detailed security questionnaires, tighter tender requirements, new contract clauses and requests for evidence that appropriate controls are operating effectively. These expectations can reach a supplier even when it is not directly regulated under NIS2.

If your organisation provides technology, professional services, logistics, manufacturing, facilities, cloud services or other important support, this guide explains how NIS2 may affect those commercial relationships and what you can do now. For the broader regulatory picture, see IT.ie's NIS2 compliance information for Irish organisations.

Which situation applies to your organisation?

Supply-chain security creates responsibilities and commercial pressure on both sides of the customer–supplier relationship.

In scope If you are directly in scope
  • You may need to identify and assess suppliers that could affect critical services.
  • Supplier risk should be included in your wider risk-management programme.
  • Contracts, access arrangements and incident processes may need to be updated.
  • Testing should include important suppliers and outsourced services.
Supplier If you supply an in-scope organisation
  • Customers may ask you to demonstrate how you manage cyber risk.
  • New questionnaires, evidence requests and contract terms may follow.
  • Your cyber maturity may affect tenders, renewals and access to customer systems.
  • You may need to provide evidence that policies and controls work in practice.

01What supply-chain security means under NIS2

Modern organisations depend on interconnected third parties, including managed service providers, cloud platforms, software vendors, equipment manufacturers, payment providers, logistics companies, professional advisers and contractors with access to sites, systems or sensitive information.

A weakness in one of these relationships can create a route into the customer. A supplier outage can also interrupt an essential service even when no information is stolen. NIS2 therefore requires in-scope entities to consider supply-chain security as part of their cyber security risk-management measures.

This goes much further than asking whether a supplier has antivirus software. Organisations should consider the risks associated with the supplier, the security and resilience of its products or services, its vulnerability-management practices, its access to systems and data, and its ability to meet agreed security requirements.

The important distinction

NIS2 does not automatically make every supplier to an in-scope organisation a regulated entity. A supplier's direct legal status depends on factors including its sector, services, size and any specific designation under Irish legislation. However, regulated customers can introduce security and assurance requirements through procurement and contracts. This is how NIS2 can affect organisations far beyond those it directly names.

02Why suppliers outside the direct scope should still pay attention

For many SMEs, the first practical impact of NIS2 will not be a letter from a regulator. It will be a question from a customer.

An in-scope healthcare provider, public administration body, transport operator, digital services company or qualifying manufacturer may ask how you protect information, manage access, patch vulnerabilities, respond to incidents and maintain continuity. It may also introduce contract clauses covering incident notification, audits, subcontractors, evidence requirements and minimum security standards.

Cyber security can therefore influence whether you qualify for a tender, retain an important contract or are permitted to connect to a customer's systems. Readiness is becoming a commercial capability as well as a security requirement.

A practical Irish business example

Consider an Irish logistics company supporting an in-scope food manufacturer or healthcare organisation. The logistics provider may not itself be directly regulated under NIS2. However, if its systems, availability or access are important to the customer's operations, the customer may require stronger access controls, faster incident notification, evidence of staff training and tested recovery arrangements.

The requirement reaches the logistics provider through the business relationship. If that provider cannot answer the customer's questions or produce credible evidence, the consequence may be delayed procurement, additional contractual conditions or the loss of an opportunity to a better-prepared competitor.

03Which suppliers should receive the most attention?

Not every supplier presents the same level of risk. Organisations should apply proportionate due diligence, concentrating effort where a compromise or service failure could cause the greatest impact. Ask the following questions when deciding whether a supplier is critical or high risk.

  • Does the supplier access our network, cloud services, business applications or sensitive information?
  • Does it hold administrative, privileged or persistent remote access?
  • Could its failure interrupt an important product, service or business process?
  • Would replacing it quickly be difficult, expensive or operationally disruptive?
  • Does it store or process personal, confidential or commercially sensitive data?
  • Could one incident at the supplier affect several customers or locations at once?
  • Does it rely on subcontractors or cloud providers that create additional dependencies?
  • Would a supplier incident trigger legal, regulatory, contractual or reputational consequences for us?

A supplier with no systems access and little operational importance should not face the same assessment as a managed service provider with administrator privileges. The level of scrutiny should reflect access, dependency, data sensitivity, substitutability and potential impact.

04What customers may ask suppliers to demonstrate

The exact requirements should reflect the service and risk involved. Even so, suppliers should be ready for questions across the following eight areas.

1

Governance and accountability

Who owns cyber security? Are cyber risks reviewed by senior management? Are policies current, approved and followed? A policy that exists only as an unread file offers little assurance. Evidence should show ownership, review dates, decisions and practical implementation.

2

Identity and access management

Expect questions about multi-factor authentication, privileged accounts, joiner and leaver processes, password practices and access reviews. Suppliers connecting to customer environments may be required to use named accounts, least-privilege access, logging and rapid access removal.

3

Vulnerability and patch management

How are vulnerabilities identified, prioritised and remediated across systems, applications and devices? Customers may ask how quickly critical issues are addressed and how exceptions are approved, recorded and monitored.

4

Monitoring and incident response

Can suspicious activity be detected, investigated and contained? Questions may cover endpoint detection, security monitoring, log retention, escalation and response responsibilities. Supplier contracts may require rapid customer notification so the customer can assess its own NIS2 reporting duties.

5

Business continuity and recovery

A supplier can create serious operational risk even when no data is stolen. Customers may seek evidence that backups are protected, restoration is tested and important services can continue during a cyber incident, technology failure or outage. IT.ie's business continuity and disaster recovery service supports this.

6

Data protection and encryption

Suppliers should know what customer data they hold, where it is stored, who can access it and how it is protected in transit and at rest. Retention, disposal and secure-deletion practices may also be assessed.

7

Subcontractors and fourth parties

A customer's risk can extend into the suppliers used by its suppliers. Expect questions about how subcontractors are selected, what security standards apply, how their performance is monitored and whether customers will be notified of material changes.

8

Evidence and independent assurance

Customers may request policies, risk assessments, training records, penetration-test summaries, continuity-test results, audit findings or certifications. Evidence should be current, relevant and proportionate to the service provided.

Certification supports assurance, but does not replace it

ISO 27001, Cyber Essentials and the NCSC-recommended Cyber Fundamentals framework can help organisations structure and evidence their controls. However, no certification or framework automatically proves NIS2 compliance. Compliance will ultimately be determined by the relevant competent authority under the final Irish legislation.

05Seven practical steps organisations can take now

  1. Understand your exposure.Check whether your organisation may be directly in scope and identify customers operating in NIS2 sectors. Do not assume that being below a size threshold removes every legal, contractual or commercial impact.
  2. Map critical relationships.Identify the services, systems, information and access connected to important customers and suppliers. Prioritise relationships where a compromise or failure could create serious disruption.
  3. Establish a security baseline.Compare current controls with a recognised framework and the NCSC's Risk Management Measures. Record gaps, owners, priorities, dependencies and realistic completion dates.
  4. Build an assurance pack.Keep core policies, certifications, training records, test summaries, recovery evidence and key contacts in one controlled location. This makes questionnaires and tenders faster, more accurate and more consistent.
  5. Review contracts carefully.Pay particular attention to incident-notification deadlines, audit rights, liability, evidence requirements, subcontractor obligations and commitments to particular standards. Seek legal advice before accepting material new obligations.
  6. Assess your own suppliers.Identify providers whose failure could affect your customers or critical operations. Apply proportionate due diligence and make responsibilities for security, incidents, continuity and access clear.
  7. Test the arrangements.Run an incident exercise covering technical response, decision-making, supplier coordination, customer communications and recovery. A plan that has never been exercised may not work when speed matters.

Avoid the questionnaire trap

Supply-chain compliance can easily become a cycle of sending and completing spreadsheets without reducing real risk. A questionnaire is useful only when answers are accurate, supported by evidence and used to address weaknesses. Suppliers should not overstate their capabilities to win a tender, and customers should not impose identical requirements on every provider regardless of risk. A proportionate assessment considers the supplier's access, data, operational importance, substitutability, fourth-party dependencies and the likely consequences of failure.

06Using Cyber Fundamentals to organise your evidence

Ireland's National Cyber Security Centre recommends Cyber Fundamentals, also known as CyFun, as a structured and voluntary way to organise and demonstrate cyber security controls. The framework follows the familiar functions of identify, protect, detect, respond and recover, with levels that can be applied according to organisational risk and maturity.

CyFun can help an organisation turn scattered policies and security products into a more coherent body of evidence. It can also provide a common language for conversations with customers and suppliers. However, CyFun is not mandatory and does not create an automatic presumption of NIS2 compliance.

The NCSC's Risk Management Measures describe what it considers the minimum baseline for essential and important entities. Organisations can use CyFun, ISO 27001, NIST, COBIT or another suitable information-security management approach to organise how those measures are implemented and evidenced.

07Where CyberProtect can support readiness

NIS2 compliance is not achieved by purchasing a single product. It requires governance, risk management, documented processes, technical and organisational controls, staff awareness, testing and evidence that the measures work.

Managed cyber security can nevertheless help organisations implement and operate many of the controls that customers increasingly expect. IT.ie's CyberProtect bundles can support the following areas:

Customer expectationRelevant CyberProtect support
Secure devices and endpointsEndpoint protection and ransomware protection
Timely vulnerability remediationManaged patching and security configuration
Threat detection and responseSecurity monitoring, endpoint detection and managed response options
Email and cloud protectionManaged email security and Microsoft 365 security controls
RecoverabilityMicrosoft 365 backup and wider recovery planning
Staff awarenessOngoing cyber-awareness training and phishing simulations
Exposure monitoringDark-web monitoring and risk visibility

CyberProtect can form part of a wider NIS2 readiness programme following a clear assessment of scope, risk and existing gaps. Governance, legal interpretation, supplier contracts and organisational accountability must also be addressed.

Do not wait for a customer to ask

Organisations that prepare early will be better placed to answer customer questions, respond to tenders and demonstrate that cyber risk is being managed responsibly. More importantly, the same work reduces the likelihood and potential impact of a real supplier-related incident.

Start by checking whether your organisation may be directly in scope. Then identify the customers, suppliers, systems and information that matter most, assess the controls already in place and create a prioritised improvement plan.

Recommended next step

Book a NIS2 Readiness Review

Identify your most important gaps and agree practical next steps. You can also use the IT.ie NIS2 Scope Assessment for an initial indication of whether your organisation may be directly affected.

Frequently asked questions

Does NIS2 apply directly to every supplier?

No. Supplying an in-scope organisation does not automatically make a business a regulated NIS2 entity. Direct scope depends on factors including sector, service, size and any specific designation. However, customers may pass security expectations to suppliers through procurement and contracts.

Can a small Irish business be affected by NIS2?

Yes. Even when an SME is outside the direct legal scope, it may be asked to complete security assessments, provide evidence or accept new contractual obligations because it supplies an in-scope customer.

What evidence might a customer request?

Requests may include policies, risk assessments, staff-training records, incident-response procedures, access reviews, patching evidence, penetration-test summaries, backup and recovery tests, certifications and information about subcontractors.

Does ISO 27001 prove NIS2 compliance?

No. ISO 27001 can provide valuable independent assurance and a strong management framework, but no single certification automatically proves NIS2 compliance.

How should an organisation assess its suppliers?

Begin with risk. Consider the supplier's systems and data access, privileged permissions, operational importance, substitutability, subcontractors and the likely impact of compromise or unavailability. Apply deeper assessment to higher-risk relationships.

Is NIS2 currently law in Ireland?

As of September 2026, Ireland had not completed transposition of NIS2 into national law. The final Irish legislation remains pending, but the Directive's requirements and the NCSC's preparation guidance provide a clear basis for organisations to begin strengthening their controls.


Sources & further reading

This article distinguishes direct legal scope from contractual supply-chain impact. CyberProtect is positioned as supporting relevant controls, not as a guarantee of compliance. Legal interpretation and contract advice should remain with appropriately qualified advisers. Regulatory information should be checked again before publication if the article is updated after September 2026. At the time of publishing, NIS2 has not been transposed into Irish law.

Download The Social Engineering Guide

Fill in your details below and hit download.