Network Bridge Solutions
← All insightsThinking · 4 min read

Supplier Risk Under NIS2: Could Your Business Be Liable for Third-Party Non-Compliance?

You are not responsible for a supplier's compliance. You are responsible for having managed the risk of relying on them. Where the line actually sits.

A wireframe supply chain of connected buildings with one highlighted link feeding into a factory.

For most business leaders, cybersecurity feels challenging enough when dealing directly with their own internal processes and protections. But under the EU's NIS2 directive, your cybersecurity responsibilities extend well beyond your company's walls.

One of the most pressing concerns business leaders face is:

"Can our company really be held liable if a supplier or third party we use isn't compliant under NIS2?"

The honest answer: yes, in a specific way. NIS2 does not fine you for a supplier's failings. It holds you accountable for how you managed the risk of using that supplier, and an incident that arrives through a supplier you never assessed is treated as your risk-management failure. Let's unpack what that exposure looks like, and how to reduce it.

Understanding Your Third-Party Risk Under NIS2

Modern business operations depend heavily on suppliers, cloud providers, managed services, and various other third parties. While these partnerships fuel productivity and innovation, they also expand your cybersecurity attack surface, and regulators know it.

NIS2 explicitly makes supply-chain security part of your own compliance: regulated businesses must assess and manage the cybersecurity risk of their suppliers and subcontractors. You are not responsible for a supplier's compliance; you are responsible for having managed the risk of relying on them. Here's why this matters:

1. NIS2's Emphasis on Supply Chains

The directive explicitly acknowledges the interconnected nature of modern businesses. Cyber incidents often originate not from your internal network but from vulnerabilities in your supply chain. Regulators now hold companies directly accountable for:

  • Conducting due diligence to ensure suppliers meet baseline cybersecurity standards.
  • Continuously monitoring suppliers' cybersecurity posture.
  • Ensuring that contracts with suppliers set explicit security requirements, the mechanism through which NIS2 obligations flow down the chain.

2. Where the Liability Actually Sits

Regulators supervise the regulated entity, not its suppliers, and that is exactly why this bites. If an incident arrives through a supplier, the question regulators put to you is whether you assessed, managed and mitigated that risk. If you cannot show that you did, the failure is yours, whatever the supplier did or did not do.

Real-World Scenario: When Supplier Risk Becomes Your Risk

Imagine your business is a manufacturer in scope of NIS2, relying heavily on a cloud storage provider for customer designs and commercial data. Your own cybersecurity measures are robust and documented, yet your supplier experiences a significant data breach due to inadequate security practices. Sensitive customer information is compromised.

Under NIS2, regulators ask tough questions:

  • Did you verify your cloud provider's security practices before engagement?
  • Do your contracts clearly outline the supplier's cybersecurity obligations and compliance requirements?
  • Have you periodically audited or verified their compliance status?

If the answer is "no," or even "not clearly," regulators could determine your business failed in its compliance duties, resulting in regulatory fines, lost client trust, and significant reputational damage.

What Exactly Are Your Obligations Regarding Third Parties?

To minimise supplier-related liability under NIS2, your business must:

1. Conduct Robust Supplier Due Diligence

At minimum, your suppliers must demonstrate that they:

  • Understand and adhere to NIS2 cybersecurity standards.
  • Have clearly documented cybersecurity policies and response plans.
  • Regularly conduct internal audits or assessments to validate compliance.

2. Enforce Clear Contractual Requirements

Your contracts with third parties should explicitly outline:

  • Cybersecurity obligations aligned with NIS2 standards.
  • Rights for your company to audit and assess suppliers' compliance.
  • Consequences for failing to maintain compliance, including remediation obligations.

3. Implement Ongoing Supplier Monitoring

Periodic reviews and audits are crucial. Don't wait for a supplier breach: proactively monitor your suppliers' cybersecurity posture using:

  • Regular compliance assessments and questionnaires.
  • Security audits and technical reviews.
  • Third-party compliance reports or certifications (e.g., ISO 27001, Cyber Essentials).

Practical Steps to Mitigate Supplier Risk

Here's what effective supplier risk management looks like practically under NIS2:

  • Risk Mapping: Clearly document which suppliers handle sensitive data or critical operations.
  • Compliance Questionnaires: Regularly require suppliers to self-report their compliance posture.
  • Third-party Audits and Certifications: Request documented evidence of external audits (like ISO 27001) to demonstrate compliance.
  • Legal Clarity: Clearly define in your contracts what constitutes a breach of cybersecurity obligations, with specific, enforceable consequences.
  • Regular Reviews and Updates: Continuously monitor compliance, not just at onboarding but annually or even quarterly for high-risk suppliers.

Why Managing Supplier Risk Matters Beyond Liability

Effectively managing supplier risk isn't just regulatory compliance; it's smart business. Consider these broader benefits:

Enhanced Client Trust

Clients appreciate proactive risk management. Demonstrating rigorous third-party oversight makes your business a safer, more reliable choice, increasing client loyalty and competitive advantage.

Insurance Premium Reductions

Cyber insurers reward proactive management of third-party risks. Clearly documented due diligence and supplier oversight can significantly lower insurance premiums and improve coverage terms.

Strategic Advantage

Competitors who overlook third-party risk remain vulnerable. In contrast, your documented supplier management practices highlight your operational maturity and strategic foresight, particularly during contract negotiations, mergers, or acquisitions.

Bottom Line: You're Not Just Responsible for Yourself

Under NIS2, supplier cybersecurity isn't optional; it's a mandatory extension of your own compliance obligations. Regulators, clients, and insurers now demand comprehensive supplier oversight. Neglecting this responsibility doesn't just risk regulatory penalties; it risks your entire business's integrity and reputation.

But proactive supplier risk management doesn't have to be overwhelming:

  • Clearly document your supplier standards.
  • Conduct systematic reviews and audits.
  • Enforce compliance contractually.
  • Leverage managed service providers or cybersecurity specialists who can handle much of this monitoring efficiently and effectively.

Doing so transforms potential liabilities into strategic strengths, protecting your business while positioning it for growth and trust in a cybersecurity-conscious marketplace.

Prefer the conversation to the reading?

Thirty minutes on the alignment between your strategy and your technology. Not a sales pitch.

Book a discovery call