Article 54 establishes SUPPLY CHAIN CYBERSECURITY requirements for high-impact + critical-impact entities. Suppliers + service providers + software vendors providing components or services with cyber-physical-system implications must: (a) meet the Article 30 minimum + Article 32 advanced cybersecurity controls (proportionate to supplier role); (b) provide vulnerability disclosure + coordinated patching capabilities; (c) provide a software bill of materials (SBOM) for critical software components; (d) accept contractual cybersecurity audit + verification rights. Article 55 establishes the supplier risk-assessment regime + the obligation to maintain a supplier cybersecurity register. Article 56 establishes the cross-border + cross-jurisdictional supplier-management rules including treatment of third-country suppliers + alignment with the Article 22 NIS2 Cooperation Group coordinated supply-chain risk assessments (e.g. 5G + AI / ML).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.