NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.3: Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

Deciding what supply chain measures are appropriate is not left to general judgement. The entity has to take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of those parties' products and cybersecurity practices including their secure development procedures. Separately, it must take into account the results of the Union level coordinated security risk assessments of critical supply chains carried out under Article 22(1). That second limb creates an external input the entity has to watch for and respond to: when a coordinated assessment lands on a technology the entity uses, the outcome has to reach the supplier risk decisions rather than stop at a policy team. Evidence of consideration is what is being asked for, including reasoned decisions not to change anything.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 51 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APRA CPS 234 · 4 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-27 Internal Audit Assessment of Third Party Control Assurance
  • CPS234-P22 Evaluation of Third Party Control Design
  • CPS234-P28 Assessment of Reliance on Third Party Control Testing

CIS Controls v8 · 4 controls

  • CIS-15.3 Classify Service Providers
  • CIS-15.5 Assess Service Providers
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components

FedRAMP High · 4 controls

  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SI-5 Security Alerts, Advisories, and Directives
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 4 controls

  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SI-5 Security Alerts, Advisories, and Directives
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)

ISO 27001:2022 · 4 controls

  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.7 Threat intelligence
  • 8.30 Outsourced development

ISO 27002:2022 · 4 controls

  • 5.21 Managing information security in the ICT supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.7 Threat intelligence
  • 8.30 Outsourced development
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

NIST SP 800-53 Rev 5 · 4 controls

C5 (Germany) · 3 controls

  • C5-DEV-02 Outsourcing of the development
  • C5-SSO-02 Risk assessment of service providers and suppliers
  • C5-SSO-04 Monitoring of compliance with requirements

NIST SP 800-171 Rev 3 · 3 controls

  • 03.14.03 Security Alerts, Advisories, and Directives
  • 03.17.02 Acquisition Strategies, Tools, and Methods
  • 03.17.03 Supply Chain Requirements and Processes

PCI DSS 4.0 · 3 controls

  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status

SOC 2 · 3 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties

DORA · 2 controls

  • DORA-Art.28 ICT third-party risk: general principles
  • DORA-Art.31 Designation of critical ICT third-party service providers

CMMC 2.0 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 51 it maps to, and the evidence behind each claim, over MCP and REST.