Deciding what supply chain measures are appropriate is not left to general judgement. The entity has to take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of those parties' products and cybersecurity practices including their secure development procedures. Separately, it must take into account the results of the Union level coordinated security risk assessments of critical supply chains carried out under Article 22(1). That second limb creates an external input the entity has to watch for and respond to: when a coordinated assessment lands on a technology the entity uses, the outcome has to reach the supplier risk decisions rather than stop at a policy team. Evidence of consideration is what is being asked for, including reasoned decisions not to change anything.
NIS2 Directive Art.21.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.