Skip to content
Back to the knowledge base

Supply-chain partners and third parties

2026-08-10

You don't need to be in scope of the Cyberbeveiligingswet yourself to feel its effect. More and more organisations run into it through their customer.

Why supply-chain partners run into this

Measure family 4 (supply chain security, article 21, third paragraph, opening (d), Cbw) requires entities that are in scope to manage risk from their suppliers. In practice that means: asking suppliers how they've arranged their security. See also the explanation of this measure family.

What a supply-chain partner does and doesn't need to do

You don't need to comply with the full duty of care under article 21 yourself if you're not in scope — that obligation only applies to essential and important entities. It is, however, reasonable for a customer to ask about concrete measures: a security policy, access management, an incident process, working backups. For the full breakdown, see "A customer asks for NIS2 evidence — now what?".

The Keten subscription

Munitor's Keten subscription contains the relevant measure subset for exactly this situation, with AI explanation and an action plan per measure. That lets you build a shareable evidence file quickly, without working through the full article 21 duty of care.

Are you in scope after all?

Check with the free scope check. The consolidated size test also counts affiliated and partner undertakings — sometimes you're in scope even when your own figures wouldn't suggest it.

Sources

Also worth reading

Not sure yet whether this applies to you? Take the free scope check.

Take the free scope check