NIS2 makes supply chain security a legal obligation. Most businesses aren’t ready. Download the free checklist and find out exactly where your gaps are.
Why this matters
NIS2 full enforcement deadline
Covered by NIS2 including healthcare, finance, transport
Of organisations do not monitor vendor risk continuously*
*Source: The Hackett Group, TPRM Performance Study
NIS2 — the EU’s Network and Information Security Directive 2 — reaches full enforcement for most organisations in October 2026. Article 21 lists supply chain security as a mandatory risk management measure, with direct obligations around vendor assessment, ongoing monitoring, and contractual protections.
Most businesses are exposed. Spreadsheets, annual questionnaires, and a reactive approach don’t satisfy what the directive now requires. The Hackett Group’s research found that only 20% of organisations monitor vendor risk continuously — and more than half take a reactive approach. That gap becomes a liability once enforcement begins.
When a regulator asks for evidence of your vendor risk programme, you need to produce it immediately. Not in two weeks. This checklist shows you exactly what they’ll ask for — and where most organisations fall short.
What’s inside
Complete, classified, current.
Cyber, ESG, sanctions, exposure.
Ongoing oversight, not point-in-time.
Security clauses, DPAs, audit rights.
Due diligence before access.
Access revocation, data return.
You within 24 hours of a vendor breach.
Named owner, board awareness.
New audit focus area.
Evidence on demand, not in two weeks.
Get the checklist
35 actionable items. Know your gaps before the auditor does.
About Vendorapp
Vendorapp was built by people who managed vendor risk at tier-one financial institutions — and got tired of the tools available not being good enough. Automated sanctions screening across five global lists, one-click risk assessments, smart contract management, and audit-ready reports — in a single platform.
We use cookies to analyze usage and enhance site navigation to give you the best experience.