GlossaryGlossary

Supply-chain security

Supply-chain security is the practice of managing cybersecurity risks introduced by suppliers, service providers, software, and dependencies.

August 31, 2026Updated August 2026
NIS2Supplier securityThird-party risk

Supply-chain security is the set of practices used to understand and reduce risks from the organizations, software, services, and infrastructure a business depends on.

A proportionate approach covers:

  • Supplier criticality and access
  • Data handled and service dependencies
  • Security requirements and contract terms
  • Vulnerability, incident, and change notification
  • Resilience, backup, and exit considerations
  • Ongoing reviews and evidence

NIS2 includes supply-chain security among its risk management areas, but each organization’s practical obligations depend on scope and national implementation. Even businesses outside direct scope may need supplier evidence to satisfy customers and partners.

Read NIS2 supply chain security: what SMBs need to ask their vendors.