Montro
NIS2 & GDPR14 min read

NIS2 Supply Chain Assessment: The Obligation Mid-Market CISOs Miss

NIS2 Supply Chain Assessment: The Obligation Mid-Market CISOs Miss
AuthorNamita Razdan
Published on24 Jun 2026

Your supplier questionnaire is not a supply chain assessment. Most mid-market NIS2 compliance programmes have built something creditable around incident handling, access management, and business continuity - but Article 21(3)(d) on supply chain security tends to get lighter treatment: map the critical vendors, send a questionnaire, file the response. That approach is almost certainly insufficient, and it is precisely where national competent authorities have indicated they will focus earliest supervisory attention.


The reason the obligation gets underweighted is partly language. Article 21(3)(d) asks organisations to address "security in supply chain including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers." The phrase "security-related aspects" sounds broad and discretionary. It is neither.

 

What the Obligation Actually Requires


NIS2 does not define supply chain security as a questionnaire exercise. It requires organisations to assess the overall security practices of their suppliers - including by reviewing contractual security provisions, verifying that obligations flow down through the supply chain, and examining the degree of dependency on individual providers. ENISA's supplementary guidance makes clear that the NIS2 requirements extends to understanding sub-suppliers and indirect relationships, not only direct contractual counterparties.


Article 20 adds a dimension that CISOs should not absorb alone: the management body is personally accountable for approving NIS2 cybersecurity measures, including supply chain security. This is not a delegation right. Boards and senior leadership who cannot demonstrate that supply chain risk has been assessed, not merely acknowledged - are personally exposed. NIS2 makes cybersecurity a governance obligation in the strictest sense of the word.


The enforcement structure reinforces this. For Annex I essential entities, the maximum penalty is €10 million or 2% of global annual turnover, whichever is higher. For Annex II important entities, €7 million or 1.4% of global annual turnover. These figures apply to the legal entity, but the personal liability provisions in Article 20 extend to individual members of the management body.


The Three-Level Problem


Supply chains in practice operate across at least three tiers. Most mid-market assessments cover only the first. 

Tier 1

Contracted vendors - visible

Cloud providers, CRM platforms, security tooling, payroll providers. Formal agreements exist. DPAs are in place. Some contractual security obligations have been reviewed. This is the tier most supplier registers capture.

Tier 2

Sub-processors and indirect providers - partially visible

Your cloud provider's sub-processors. Your CRM vendor's hosting and authentication infrastructure. Disclosed in contract annexes that most organisations have not read. Visible in principle; invisible in practice.

Tier 3

Shadow tools - invisible

AI tools adopted by employees using work email addresses, corporate card subscriptions, or personal accounts. No DPAs. No security assessment. No entry in any supplier register. Processing your customer data today.

NIS2 Article 21(3)(d) requires you to assess your supply chain. That requirement is structurally impossible to satisfy when you do not know the full extent of what constitutes your supply chain. The shadow AI problem is not a housekeeping issue, it is a direct barrier to credible supply chain risk management and a compliant NIS2 compliance position.

What Montro Finds in the Supply Chain Inventory

When Montro runs a supply chain discovery exercise for a NIS2 in-scope firm, the comparison between the existing supplier register and the actual discovery output follows the same pattern every time. Tier 1 is usually accurate; all the contracted vendors are present, the DPAs are in place, and the security obligations have been reviewed at least once. Tier 2 is partial; some sub-processors are visible in contract annexes, but most organisations have not checked those annexes recently enough to know what has changed. Tier 3 is barely present in the register.


The gap between what the register shows and what is actually running in the environment is not just a handful of tools. At a typical mid-market firm in the 200 to 1,000 employee range, Montro identifies anywhere between 30 to 50 applications that are not visible on the supplier register. The majority of those were adopted in the last eighteen months, and most of them are AI tools. None of these tools have been through a supply chain security assessment.


Under NIS2 Article 21(3)(d), every one of those tools is a supplier the firm is required to have assessed. The register said that the supply chain was manageable, and the discovery identified that it was three times larger.

What Shadow AI does to the Assessment Obligation


Shadow AI tools - those adopted informally, outside procurement, create a specific problem under Article 21(3)(d) that differs from conventional shadow IT.


First, AI tools are far more likely than conventional SaaS applications to process operationally sensitive data. A messaging integration sits at the periphery of operations; an AI tool summarising client correspondence, generating customer-facing content, or scoring customers for any purpose sits at the centre. The data exposure is categorically different.


Second, informally adopted AI tools almost never contain the contractual security provisions Article 21(3)(d) requires you to assess. Consumer-tier AI products are not contracts in any relevant sense. They contain no audit rights, no sub-processor notification obligations, no security incident notification commitments, and no data return provisions on termination. There is nothing to assess, because nothing was agreed.


Third, the incident reporting obligations under NIS2 become structurally unworkable. Article 23 requires a 24-hour early warning to your national CSIRT in the event of a significant incident, followed by a full notification within 72 hours. An organisation cannot detect an incident in a system it does not know exists. Shadow AI tools create detection blind spots that make the reporting timeline impossible to honour, not because the organisation lacks NIS2 cybersecurity capability, but because visibility is structurally absent. 


Performing the Assessment Correctly


A sound supply chain assessment under NIS2 has four components that most mid-market programmes are missing at least one of.


Complete the inventory first. You cannot assess a supplier you have not identified. Discovery needs to cover SSO logs, email receipts, browser telemetry, financial data, and HR onboarding records - not just the procurement register. The inventory is the foundation; an incomplete inventory produces a compliant-looking document that does not reflect the actual risk position. For most organisations, the gap between what the procurement register shows and what is actually running in the environment is larger than the CISO expects.


Classify by criticality and apply proportionate rigour. NIS2 does not require identical assessment depth across every supplier. It requires measures that are "appropriate and proportionate to the risks posed.” Identify which suppliers support critical or important functions. Apply full assessment depth to those. Apply lighter-touch controls to commodity providers. Document the classification rationale explicitly, this is what the supervisory review will examine, and it is the foundation of defensible supply chain risk management under NIS2.


Assess the supplier's security posture, not only your contract with them. Reviewing your SLA is not a supplier security assessment. A meaningful assessment examines the supplier's own certifications, incident disclosure history, sub-processor practices, data residency, and resilience commitments. For shadow AI tools, none of this has been done, because no formal relationship was established through which to do it. Discovery and immediate risk classification is the precondition for any security compliance assessment at all.


Document residual risk explicitly. Where a supplier is retained despite a gap, because replacement would be operationally disruptive, or because no compliant alternative yet exists, document the risk and the compensating controls. National competent authorities are not expecting zero-gap programmes. They are expecting evidence that organisations know what risks they are carrying and have made considered decisions about them, the documentable judgement that separates credible NIS2 compliance from compliance theatre.


The Enforcement Posture to Expect


NIS2 transposition was required by 17 October 2024. Enforcement is now active in the jurisdictions that have completed transposition, and supervisory reviews are beginning. Germany's BSI has a well-established record of technically rigorous enforcement and has explicitly named supply chain security as a supervisory priority. The Netherlands' NCSC-NL and France's ANSSI operate with similarly proactive postures.


Mid-market organisations sometimes assume enforcement attention will concentrate on larger enterprises. The evidence from GDPR enforcement does not support that assumption. Fines have landed on organisations of all sizes, and NIS2 brings approximately 160,000 additional organisations into scope compared to its predecessor, a number that includes most mid-market entities with 50 or more employees and €10 million or more in annual turnover.


The supervisory question that will matter most is not whether you have a supply chain policy. It is whether your inventory is complete and your assessment is real, and closing that gap is what security compliance under NIS2 actually looks like in practice.


Where to Start


The most useful first step is not a gap analysis against the full ten-obligation framework. It is a complete discovery exercise against your actual application environment, covering every tool in use, not only those that passed through procurement. Until that inventory exists, the supply chain assessment rests on an incomplete foundation, and everything built on it will reflect that incompleteness back to any regulator who examines it.


The shadow AI tools your employees adopted informally over the past eighteen months are, under NIS2, your suppliers. That is the gap. And it is almost certainly larger than your current supplier register suggests. 


Frequently Asked Questions


Does NIS2 Article 21(3)(d) require a formal supplier audit or is a questionnaire sufficient?


A questionnaire alone is not sufficient. The obligation requires assessing the overall security practices of suppliers; including reviewing contractual security provisions, verifying that obligations flow down through the supply chain, and examining dependency on individual providers. ENISA's supplementary guidance increasingly frames this as extending to sub-suppliers and indirect relationships, not only direct contractual counterparties. A questionnaire that a supplier fills in is an input to an assessment, not the assessment itself, and treating it as sufficient is the most common NIS2 requirements gap in mid-market supply chain programmes.


How does NIS2 supply chain security interact with GDPR processor obligations?


They overlap significantly at the vendor level. A shadow AI tool simultaneously lacks a NIS2-compliant security assessment and a GDPR Article 28 Data Processing Agreement. The same inventory gap, not knowing the tool exists, produces two simultaneous compliance failures under two separate regulatory frameworks. Closing the inventory gap resolves both starting points at once.


Which national competent authorities are most active on NIS2 supply chain enforcement?


Germany's BSI has explicitly named supply chain security as a supervisory priority and has a technically rigorous enforcement posture. The Netherlands' NCSC-NL and France's ANSSI operate with similarly proactive postures. Organisations operating across multiple member states should model the strictest applicable jurisdiction rather than assuming a uniform standard.


What counts as a "significant incident" requiring 24-hour early warning under NIS2 Article 23?


A significant incident is one that has caused or is capable of causing severe operational disruption, financial loss, or impact on other natural or legal persons. The assessment considers the number of affected users, the duration, the geographic spread, and the criticality of the services impacted. Shadow AI tools create a specific problem here, an organisation cannot detect a significant incident in a system it does not know exists, making the 24-hour reporting obligation structurally impossible to honour without complete supply chain visibility.

Namita Razdan

Namita Razdan

Co-founder

Fifteen years of financial services compliance and technology consulting across HSBC, EY, Accenture, and NTT Data - and the person in the room when regulators ask the hard questions. At Montro, she owns regulatory accuracy and sets the firm's position on EU AI Act, DORA, NIS2, and GDPR.

Blog

Read next

Explore more from our library

View all

Stay informed on EU AI governance

Monthly updates on regulatory changes, compliance trends, and platform releases

By subscribing you agree to our Terms and Conditions and Privacy Policy

Montro AI governance dashboard showing tool risk tiers