To implement NIS2 vendor monitoring, build a register of every direct supplier and what each one can access, assess them individually rather than with one uniform questionnaire, monitor their security posture continuously between assessments, and keep dated evidence of all three. NIS2 Article 21(2)(d) requires measures covering the relationship with each direct supplier, and Article 21(3) requires you to account for the vulnerabilities and cybersecurity practices specific to each — which an annual questionnaire cycle cannot satisfy on its own.
Below is how to turn that obligation into an operating process.
1. Confirm what the obligation actually says
Read Article 21(2)(d) and 21(3) directly before designing anything, because three details in the wording determine the design:
- "Each direct supplier and service provider." Per supplier, not portfolio-wide. A single generic policy applied uniformly does not meet the wording.
- "Cybersecurity practices." Practices, not just products. That is an assessment of how a supplier operates, which a certificate alone does not answer.
- "Vulnerabilities specific to each." A vulnerability is a live property. Assessing it once a year describes one day and says nothing about the other 364.
Note also that the instrument binding you is your member state's transposing law, not the directive itself — implementations differ in detail. And if you are a UK organisation supplying EU essential or important entities, this reaches you contractually through your customers rather than through a regulator. See NIS2 for scope and the wider requirements.
2. Build the direct-supplier register
Most organisations discover at this step that no authoritative list exists. Procurement has a contracts register, IT has an integrations list, finance has accounts payable, and the union of the three is larger than any of them.
Record for each supplier: what they access or process, which systems they touch, how critical they are to your service delivery, the relationship owner, and their own subcontractors where known. Start from accounts payable and integration logs rather than the contracts register — it is less tidy and more complete.
3. Tier by access and impact
Tier on what a supplier can reach and what breaks without them, never on spend. The cheapest supplier in the estate is frequently the one holding an API token into customer data.
Tiering is what makes per-supplier assessment affordable: it lets a critical supplier get a full evidenced assessment while a low-impact one gets a short screen, without pretending the two are equivalent.
4. Assess each supplier specifically
"Specifically" is the operative word, and it does not mean writing hundreds of bespoke questionnaires. It means the depth and content are driven by that supplier's inherent risk:
- Collect what already exists first — SOC 2 reports, ISO 27001 certificates and their scope statements, penetration test summaries, trust-centre content. A large share of any questionnaire is usually already answered in documents the supplier has published.
- Add an outside-in assessment of their external posture, which needs no cooperation and no waiting.
- Reconcile the two, and treat disagreement as a finding.
5. Monitor continuously between assessments
This is the step that distinguishes NIS2 vendor monitoring from the annual questionnaire cycle most programmes already run, and the wording of Article 21(3) is what requires it.
Monitor, at minimum: material change in external security posture, newly exposed services, breach and credential exposure associated with the supplier, and corporate events such as acquisition. Define what constitutes a material change in advance, and what happens when one is detected — otherwise you have a feed rather than a control.
6. Wire supplier incidents into your own 24-hour clock
NIS2 requires an early warning to your authority or CSIRT within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month.
If the incident originates at a supplier, meeting a deadline that is yours depends on them telling you in time. That makes contractual notification windows a monitoring control, not a legal formality: a contract giving a supplier 72 hours to notify you has already made your 24-hour obligation unmeetable. Rehearse the path, including how you find out.
7. Keep the evidence, dated
Supervision is evidence-based. For essential entities it is proactive rather than triggered by an incident, so the question is not whether you can describe the process but whether you can show it ran.
Retain: the tiering decision and its rationale, each assessment with its date and inputs, findings with owners and deadlines, monitoring alerts and what was done about them, and the management body's approval. NIS2 requires management bodies to approve and oversee the measures and makes them personally liable, so minute the approvals.
8. Decide how it scales before it has to
The arithmetic is what defeats most NIS2 supplier programmes. Per-supplier assessment plus continuous monitoring plus dated evidence, across several hundred relationships, is not a process a small team completes by hand — and the failure mode is not visible. The process is followed, the documents exist, and coverage quietly narrows to whichever suppliers escalate loudest.
Decide early whether you are reducing the number of suppliers in scope, increasing the team, or reducing the human effort per supplier. Those are the only three options, and choosing none of them is how a programme ends up compliant on paper and hollow in practice.
The short version
Register every direct supplier and what they can reach. Tier by access and impact. Assess each one specifically, combining what they tell you with what you can observe independently. Monitor continuously and define what counts as material change. Contract for notification fast enough to meet your own 24-hour deadline. Keep dated evidence and get management to approve it. Then check the arithmetic actually works at your supplier count — because Article 21(2)(d) says each, and it means it.
