NIS2 · Supplier assurance and reporting
Bring supplier-security evidence into your NIS2 programme.
See how suppliers measure up against your policies, follow up gaps and bring the evidence into your reporting. Give your team a clearer basis for supplier oversight.
Review supplier profiles and supporting evidence against your policies. Your team decides whether the information is sufficient for the relationship.
The context
Supplier security belongs in the wider risk picture.
NIS2 strengthens cyber risk management, incident reporting and management accountability across covered EU sectors. Supply-chain security is one part of that wider programme.
Platform support
Make supplier assurance easier to evidence.
Connect practical supplier-risk activities with the information your team needs. This is a capability overview, not a regulator-approved NIS2 control mapping.
| Your activity | In Risk Ledger | What it gives your team |
|---|---|---|
| Supplier security assessment | Review standardised, control-based profiles and supporting evidence against your policies. | Consistent information to inform supplier assurance and follow-up questions. |
| Remediation and follow-up | Request remediation, discuss controls with suppliers and track progress. | Records of follow-up activity to support your risk-management decisions. |
| Ongoing supplier oversight | Review supplier changes, compliance scores and remediation through dashboards and notifications. | Inputs to your review of changing supplier risk and outstanding issues. |
| Management reporting | Export supplier and risk data and use compliance, activity and performance reports. | Information to assemble for management oversight and evidence requests. |
Supplier compliance scores reflect assessment responses against your policies. They are not a determination of compliance with NIS2 or national law. Your team decides what evidence is needed.
Putting it into practice
Show what you reviewed and what happened next.
Set the scope
Identify the supplier relationships relevant to the systems and services you need to protect.
Review and challenge
Use assessment responses to guide questions. Check the relevance and quality of evidence before making a risk decision.
Report the action
Bring supplier findings and follow-up into your existing management reporting, together with the decisions and responsibilities your team records.
Questions
A clearer view of the scope.
Does Risk Ledger make us NIS2 compliant?
No. It supports supplier assurance and reporting within a wider programme. Your organisation must determine its obligations and implement the measures that apply.
Can supplier reports support our compliance evidence?
Yes. They can contribute to your evidence, alongside your own policies, decisions and other records. Your team must establish whether that evidence meets the relevant requirements.
Is this the same as reporting a significant incident?
No. Supplier-risk reporting for oversight is different from notifying the relevant authority of a significant incident. This page does not claim automatic incident classification or regulatory submission.
Are the requirements identical in every EU country?
NIS2 is implemented through national law, with additional EU-level rules for certain entities. Confirm your scope and applicable national and sector requirements.
Give supplier oversight a stronger evidence base.
See how Risk Ledger can support supplier assurance, follow-up and reporting within your NIS2 programme.
Book a demo