Directive (EU) 2022/2555, EUR-Lex
The NIS2 Directive, with the risk-management measures in Article 21.
NIS2 requires essential and important entities to secure their supply chain, including relationships with direct suppliers and service providers.
Fill Easy returns each supplier's registry record: who it is, who runs it and who owns it.
The NIS2 Directive (EU) 2022/2555 sets cybersecurity risk-management measures for essential and important entities in sectors such as energy, transport, banking, health and digital infrastructure. Member states applied it from 18 October 2024.
Article 21 covers supply chain security, taking account of each direct supplier's specific vulnerabilities. Management bodies approve the measures and can be held liable.
Data and third-party risk
| Obligation | What it asks | What Fill Easy returns |
|---|---|---|
| Identify the supplier | Know which legal entity you contract with | Registry extract and statutory documents from the company's home registry, across 60+ jurisdictions |
| Understand the supplier | Its ownership, management and where it is controlled from | Ownership traced layer by layer through each registry to the natural persons at the top |
| Supplier risk | Assess each direct supplier's specific risks | AML, sanctions and PEP screening on the company and the people found; credit reports and litigation searches |
| Keep it current | Reassess as suppliers change | Monitoring and remediation: the book re-checked at source from one Excel file |
A summary, not legal advice: the official text governs, and your compliance team decides what your policies require.
Read the source
The NIS2 Directive, with the risk-management measures in Article 21.
The EU cybersecurity agency's NIS2 guidance.
Not covered here? Ask our team
No. The due diligence duty sits with your firm under NIS2 supply chain security, and your policies decide what is enough. Fill Easy supplies the evidence those policies rely on: records from the government or registry source, each showing where and when it was retrieved.
No. Fill Easy verifies who the supplier is and who owns it. Security questionnaires, audits and certifications stay with your supplier assessment.