Supply chain security starts with the supplier's identity.

NIS2 requires essential and important entities to secure their supply chain, including relationships with direct suppliers and service providers.

Fill Easy returns each supplier's registry record: who it is, who runs it and who owns it.

Cybersecurity duties that reach suppliers.

The NIS2 Directive (EU) 2022/2555 sets cybersecurity risk-management measures for essential and important entities in sectors such as energy, transport, banking, health and digital infrastructure. Member states applied it from 18 October 2024.

Article 21 covers supply chain security, taking account of each direct supplier's specific vulnerabilities. Management bodies approve the measures and can be held liable.

At a glance

Law
Directive (EU) 2022/2555 (NIS2), Article 21
Applied from
18 October 2024, through national law
Applies to
Essential and important entities in the sectors the directive lists
Supplier duty
Supply chain security, including relationships with direct suppliers and service providers

Data and third-party risk

What supplier assessment needs.

The part of supplier assessment that company data answers.
NIS2 supply chain security: obligations and the evidence Fill Easy returns
ObligationWhat it asksWhat Fill Easy returns
Identify the supplierKnow which legal entity you contract withRegistry extract and statutory documents from the company's home registry, across 60+ jurisdictions
Understand the supplierIts ownership, management and where it is controlled fromOwnership traced layer by layer through each registry to the natural persons at the top
Supplier riskAssess each direct supplier's specific risksAML, sanctions and PEP screening on the company and the people found; credit reports and litigation searches
Keep it currentReassess as suppliers changeMonitoring and remediation: the book re-checked at source from one Excel file

A summary, not legal advice: the official text governs, and your compliance team decides what your policies require.

Read the source

The official text.

Directive (EU) 2022/2555, EUR-Lex

The NIS2 Directive, with the risk-management measures in Article 21.

Questions about NIS2 supply chain security

Not covered here? Ask our team

Does Fill Easy make us compliant with NIS2 supply chain security?

No. The due diligence duty sits with your firm under NIS2 supply chain security, and your policies decide what is enough. Fill Easy supplies the evidence those policies rely on: records from the government or registry source, each showing where and when it was retrieved.

Does Fill Easy assess a supplier's cybersecurity?

No. Fill Easy verifies who the supplier is and who owns it. Security questionnaires, audits and certifications stay with your supplier assessment.

Move your search orders without changing how your team works.