4
Supply chain security
2026-08-10
Cbw art. 21, third paragraph, opening (d) · NIS-2 art. 21(2)(d) · Cbb art. 10
Your own security is only as strong as the weakest link in your supply chain. This family is about the security requirements you place on suppliers.
What this means in practice
You approve a supply chain security policy, record security requirements in supplier contracts, periodically test suppliers against those requirements, and keep a current overview of suppliers and outsourced services.
Why this is in the law
This is the family suppliers are usually held to: your customer, if they're in scope themselves, must be able to demonstrate this to a supervisor — so they ask it of you.
Measures in this family
- MC-16 — Supply chain security policy
- MC-17 — Recording security requirements in supplier contracts
- MC-18 — Periodically testing suppliers against your security requirements
- MC-19 — Current overview of suppliers and outsourced services
Sources
Also worth reading
Not sure yet whether this applies to you? Take the free scope check.
Take the free scope check